[SC-L] Software Security and Business

2009-06-18 Thread Gary McGraw
hi sc-l,

We all know that justifying our activities from a business perspective is 
essential to a healthy and successful software security initiative.  Real data 
helps.  In the Boardroom, numbers are king.

Jim Routh (CSO of KPMG and ex CSO of DTCC) and I wrote this month's informIT 
article about demonstrating software security business value at DTCC.  This is 
a case study of one very successful software security initiative.

How DTCC Builds Better Software and at a Lower Cost
http://www.informit.com/articles/article.aspx?p=1357183

For more about DTCC's software security initiative, also listen to Reality 
Check episode 2:
http://www.cigital.com/realitycheck/show-002/

As always, we welcome your feedback.

gem

company www.cigital.com
podcast www.cigital.com/silverbullet
podcast www.cigital.com/realitycheck
blog www.cigital.com/justiceleague
book www.swsec.com

___
Secure Coding mailing list (SC-L) SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
___


[SC-L] Silver Bullet: Matt Blaze

2009-06-18 Thread Gary McGraw
hi sc-l,

When it rains it pours...especially in Virginia these days.

Silver Bullet number 39 is an interview with Matt Blaze, security and privacy 
luminary.  Matt and I spent lots of time digging into Matt's public policy 
work.  Matt is an important voice of sanity whose opinions I greatly admire.  
And he coined the term trust management.

http://www.cigital.com/silverbullet/show-039/

Some of Matt's work has been published by IEEE Security  Privacy magazine in 
highly popular articles.  There are a couple of pointers on the Silver Bullet 
page for the episode.  IEEE SP is the co-sponsor of Silver Bullet.

As always, your feedback is welcome.

gem

company www.cigital.com
podcast www.cigital.com/silverbullet
podcast www.cigital.com/realitycheck
blog www.cigital.com/justiceleague
book www.swsec.com

___
Secure Coding mailing list (SC-L) SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
___