Re: [SC-L] BSIMM4 Released Today

2012-09-27 Thread Gary McGraw
hi sc-l, Once every blue moon, software security makes it into the major press. BSIMM4 did it today. http://blogs.wsj.com/cio/2012/09/26/bank-cyberattacks-underscore-need-for-security-processes/ I think it's great when the major players get past the train wreck mentality that seems to

[SC-L] BSIMM4 Released Today

2012-09-18 Thread Gary McGraw
hi sc-l, Today we released BSIMM4, the fourth edition of the BSIMM model built directly from data observed in 51 firms. If you ever wonder what software assurance looks like in commercial practice (and how to measure it), the BSIMM sheds plenty of light on current practice. Download a copy