All,

Both WASC and the MITRE CWE team have begun exploring the feasibility of enumerating or classifying the types of mitigations that are used to fix software defects/weaknesses. Does anybody know of such work in this area? (We can draw from sources such as McGraw/Viega "Building Secure Software," and 'indirect' sources such as ESAPI, but I was wondering if there was something that was a little more focused on mitigations.)

CWE status:

http://www.webappsec.org/lists/websecurity/archive/2010-10/msg00065.html

WASC status:

http://www.webappsec.org/lists/websecurity/archive/2010-10/msg00066.html



Thanks,
Steve
_______________________________________________
Secure Coding mailing list (SC-L) SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates
_______________________________________________

Reply via email to