The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
.
google unix.com



More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Securing DNS Servers iBot IT Security RSS 0 08-27-2008 01:40 PM
Symark Software Named to Software Magazine’s Software 500 for ... - Business Wire (pr iBot UNIX and Linux RSS News 0 10-29-2007 09:40 AM
securing a shell jhansrod AIX 1 05-17-2005 12:11 PM
Securing arguments SolidSnake Shell Programming and Scripting 0 05-21-2004 11:44 AM
securing a remote box sphiengollie Security 8 05-09-2002 10:59 AM

 
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 10-20-2008
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 22,197
Securing Software Through Professionalism

The challenge of software vulnerabilities has been discussed by many in the information security industry for several years now. Not only have there been several major breaches due to unsecured software, the costs continue to rise for those of us who have to maintain systems and constantly patch the vulnerabilities that are found.







As we know, the problem is not isolated to any particular piece of software – it’s across the board, whether it’s operating systems, word processing, new media or any other application that can make enterprises open to attack.






After hearing from our members and those who write and develop software about this problem, (ISC)² formed several expert working groups to discuss possible solutions. The consensus was that while the software industry has made some progress in improving the secure coding and development of software, it hasn’t moved quickly enough.






These experts agreed that there are security issues found at all different steps in the software lifecycle and that we need to look at software security holistically, from the very beginning of design, to implementation, maintenance and disposal.






The end result of these conclusions is the Certified Secure Software Lifecycle Professional (CSSLPcm), a new certification announced this past month by (ISC)² to validate an individual’s understanding of security best practices throughout the software lifecycle.






Code-language neutral, the CSSLP is applicable to anyone involved in the software development lifecycle, from analysts, developers, software engineers and software architects to project managers, software quality assurance testers and programmers. It is complementary to the CISSP but there is no other certification required to obtain it.






CSSLP candidates must demonstrate four years of professional experience in the software development lifecycle process or three years experience and a bachelor’s degree (or regional equivalent) in an IT discipline.






The seven domains of the CSSLP CBK are:



  • Secure Software Concepts
  • Secure Software Requirements
  • Secure Software Design
  • Secure Software Implementation/Coding
  • Secure Software Testing
  • Software Acceptance
  • Software Deployment, Operations, Maintenance and Disposal



We are very proud to note that a wide range of respected organizations have expressed their support for the CSSLP, including Microsoft, Symantec, DSCI (NASSCOM), SANS, SRS International, Software Assurance Forum for Excellence in Code (SAFECode), Cisco, Xerox, SAIC, ISSA, and Frost & Sullivan.






The first CSSLP exam is scheduled for the end of June in 2009. Currently, (ISC)² is seeking qualified professionals who meet experience and other requirements to participate in the exam assessment. They will become the first CSSLP holders and be asked to contribute to the exam development process and assist in other program development tasks. Applications for the CSSLP experience assessment will be accepted from Sept. 25, 2008 through March 31, 2009, with the first education seminars slated for Q1 2009. For more information and to register for the experience assessment, please visit www.isc2.org/CSSLP.






I hope you will support this endeavor to make our software and our enterprises more secure in the years to come. I welcome your suggestions and comments on this exciting new initiative from (ISC)².




More...
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 05:54 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0