Home > Software Quality Topics > Software Requirements > Building security into the SDLC (Software development life cycle) > Expert Technical Advice
Software Quality Topics:
EMAIL THIS
 TOPICS HOME   BROWSE ALL SOFTWARE QUALITY TOPICS   SOFTWARE QUALITY INFO CENTERS   RESOURCE CENTERS     RSS FEEDS 

Building security into the SDLC (Software development life cycle)

IN THIS TOPIC:  NEWS (71) , EXPERT TECHNICAL ADVICE (119) , REFERENCE & LEARNING (24) , DOWNLOADS (2) , BEST WEB LINKS (112)

Display in sets of:

  1 - 10 of 119 in Expert Technical Advice << Previous   page 1 2 3 ... 10 11 12   Next >>

BUILDING SECURITY INTO THE SDLC (SOFTWARE DEVELOPMENT LIFE CYCLE) EXPERTS
Ramesh Nagappan
Java Technology Architect, Sun Microsystems
ASK A QUESTION
Chris Wysopal
co-founder and chief technology officer
ASK A QUESTION
PCI DSS compliance: WAF, code review or both?
02 Jul 2008
EXPERT ANSWER - Complying with PCI DSS requirement 6.6 means installing a Web application firewall or conducting a code review. Application security expert Caleb Sima explains which option is best and how to get the most out of your app sec ...
Application security careers have bright future
09 Jun 2008
EXPERT ANSWER - Application security expert Dan Cornell explains why companies are taking a greater interest in incorporating security into the SDLC, and how this trend affects those breaking into the software security field.
Software Security Engineering: A Guide for Project Managers -- Chapter 3, Requirements Engineering for Secure Software
Submitted By: SearchSoftwareQuality.com | 20 May 2008
TIP - Security requirements engineering is a critical part of the software development lifecycle. This chapter explains how to approach requirements engineering for a secure SDLC.
Writing software requirements that address security issues
Submitted By: SearchSoftwareQuality.com | 20 May 2008
TIP - Experts always say you need to bake security into the development lifecycle. To do that, you need to take a hard look at the security requirements written for the software.
How to prevent XPath injection
Submitted By: SearchSoftwareQuality.com | 11 Feb 2008
TIP - Parameterization and input validation are invaluable to application security. Which method is best for preventing XPath injection attacks? Expert Chris Eng explains.
InfoSecurity 2008 Threat Analysis, Chapter 4: XSS Theory
Submitted By: SearchSoftwareQuality.com | 07 Jan 2008
TIP - Application security threats are becoming more complex than ever before. This free chapter explains how cross-site scripting (XSS) works.
How to prevent anti-DNS pinning attacks
19 Dec 2007
EXPERT ANSWER - Application security measures can prevent anti-DNS pinning, aka DNS rebinding. Expert Chris Wysopal explains how to protect end users from this attack.
Java application security features and measures
03 Dec 2007
EXPERT ANSWER - Application security features are built in to the Java language. Expert Ramesh Nagappan explains how to take advantage of these features and several other simple measures to ensure Java application security.
How to get developers to buy into software security
Submitted By: SearchSoftwareQuality.com | 19 Nov 2007
TIP - Getting developers' buy-in on security and secure coding practices can be like pulling teeth. But Kevin Beaver has some ideas to get them to follow security practices.
Password recovery with .NET 2.O using C#
29 Oct 2007
EXPERT ANSWER - ASP.NET developers can use built-in Membership controls to enhance application authentication and authorization. Expert Dan Cornell explains how to use these controls to create a password recovery mechanism.


  1 - 10 of 119 in Expert Technical Advice << Previous   page 1 2 3 ... 10 11 12   Next >>

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts