Re: [SC-L] Functional Correctness

2009-08-25 Thread Pravir Chandra
ls (both BSIMM and OSAMM) help to provide a framework > and a direction to those that have no real security practices at all. Or > allow a measurement of existing process and see where their weaknesses are. > That and th

Re: [SC-L] Where Does Secure Coding Belong In the Curriculum?

2009-08-26 Thread Pravir Chandra
_ > Secure Coding mailing list (SC-L) SC-L@securecoding.org > List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l > List charter available at - http://www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associate

Re: [SC-L] top 10 software security surprises

2008-12-16 Thread Pravir Chandra
http://krvw.com/mailman/listinfo/sc-l > List charter available at - http://www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) > as a free, non-commercial service to the software security community. &

Re: [SC-L] SANS Institute - CWE/SANS TOP 25 Most Dangerous Programming Errors

2009-01-15 Thread Pravir Chandra
looking positive so far. I encourage anyone with data, ideas, or motivation to ping me and get involved. p. -- ~ ~ ~~~~ ~~~~~ ~~~ ~~ ~ Pravir Chandra chandralistorg PGP:CE60 0E10 9207 7290 06EB

[SC-L] Relationship between BSIMM and SAMM

2009-03-06 Thread Pravir Chandra
hort answer: they're different), so I blogged about it here: http://www.opensamm.org/2009/03/whats-up-with-the-other-model/ Thanks! p. ~ ~ ~~~~ ~ ~~~ ~~ ~ Pravir Chandra chandralistorg PGP:CE60 0E10 9207 7290 06EB

Re: [SC-L] Positive impact of an SSG

2009-03-10 Thread Pravir Chandra
/www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) > as a free, non-commercial service to the software security community. > ___ > -- ~ ~ ~ ~~~ ~~ ~ Pravir Chandra

Re: [SC-L] Positive impact of an SSG

2009-03-11 Thread Pravir Chandra
ge of orgs for which a dedicated SSG isn't cost effective, I'm sure we can agree that affording 'someone in charge of success' doesn't equate to a dedicated SSG. There's a myriad of ways that can be accomplished in any organizational structure. Thanks! p. ~

Re: [SC-L] Positive impact of an SSG

2009-03-11 Thread Pravir Chandra
nd run with it without serious outside help. p. ~ ~ ~~~~ ~ ~~~ ~~ ~ Pravir Chandra chandralistorg PGP:CE60 0E10 9207 7290 06EB 5107 4032 63FC 338E 16E4 ~ ~~ ~~~ ~ ~ ~ -Origin

Re: [SC-L] Positive impact of an SSG

2009-03-11 Thread Pravir Chandra
to, say, looking at it and >> thinking "Here's what nine companies have spent dozens of >> person-decades and millions of dollars learning about what works; >> let's see what we can glean from that." Uh, okay. >> >> Yes, previous models exist. Although it may ha

Re: [SC-L] BSIMM: Confessions of a Software SecurityAlchemist(informIT)

2009-03-20 Thread Pravir Chandra
ct, I'd be willing to be that for just about every software security problem we've dealt, I could give you a design/spec level solution that would prevent it in general (and make auditing and so forth incredibly streamlined). p. ~ ~~~~

Re: [SC-L] SAMM 1.0 Released! | OpenSAMM

2009-03-25 Thread Pravir Chandra
gt; List charter available at - http://www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) > as a free, non-commercial service to the software security community. > ___ > >

[SC-L] SAMM helps with real software development

2009-04-30 Thread Pravir Chandra
The Real Software blog by Jim Bird has a good post about how his software security assurance program has evolved over time, and now, SAMM is helping out. http://swreflections.blogspot.com/2009/04/opensamm-shows-way.html p. -- ~ ~ ~ ~~~ ~~ ~ Pravir

Re: [SC-L] Static Vs. Binary

2009-07-30 Thread Pravir Chandra
liability, or usability, etc.). p. ~ ~~~~~~~~~ ~~~~ ~ ~~~ ~~ ~ Pravir Chandra chandralistorg PGP:CE60 0E10 9207 7290 06EB 5107 4032 63FC 338E 16E4 ~ ~~ ~~~ ~ ~ ~ -Original Message- From: John Steven Date: Thu, 30 Jul 2009 17:20:52 To: Secu