<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Software Security Framework</title>
	<atom:link href="http://www.cigital.com/justice-league-blog/2008/10/15/software-security-framework/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cigital.com/justice-league-blog/2008/10/15/software-security-framework/</link>
	<description></description>
	<lastBuildDate>Sun, 13 May 2012 16:44:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: gem</title>
		<link>http://www.cigital.com/justice-league-blog/2008/10/15/software-security-framework/#comment-112</link>
		<dc:creator>gem</dc:creator>
		<pubDate>Fri, 16 Apr 2010 20:46:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/justiceleague/2008/10/15/software-security-framework/#comment-112</guid>
		<description>Hi Tilly,

The Framework is very much like a grid in Archeology.  Think of it as conceptual stakes and string defining &quot;squares&quot; where we discover (or observe) activities.  You can read about the Framework and why we built it here: http://www.informit.com/articles/article.aspx?p=1271382

The Model is the actual observed data.  You should read the BSIMM itself for that which you can find here: http://bsi-mm.com/

The BSIMM itself is infinitely more important than the Framework.

Hope that helps.

gem</description>
		<content:encoded><![CDATA[<p>Hi Tilly,</p>
<p>The Framework is very much like a grid in Archeology.  Think of it as conceptual stakes and string defining &#8220;squares&#8221; where we discover (or observe) activities.  You can read about the Framework and why we built it here: <a href="http://www.informit.com/articles/article.aspx?p=1271382" rel="nofollow">http://www.informit.com/articles/article.aspx?p=1271382</a></p>
<p>The Model is the actual observed data.  You should read the BSIMM itself for that which you can find here: <a href="http://bsi-mm.com/" rel="nofollow">http://bsi-mm.com/</a></p>
<p>The BSIMM itself is infinitely more important than the Framework.</p>
<p>Hope that helps.</p>
<p>gem</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tilly</title>
		<link>http://www.cigital.com/justice-league-blog/2008/10/15/software-security-framework/#comment-111</link>
		<dc:creator>Tilly</dc:creator>
		<pubDate>Fri, 16 Apr 2010 19:12:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/justiceleague/2008/10/15/software-security-framework/#comment-111</guid>
		<description>Can you explain the difference between framework and model</description>
		<content:encoded><![CDATA[<p>Can you explain the difference between framework and model</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Van Vleck</title>
		<link>http://www.cigital.com/justice-league-blog/2008/10/15/software-security-framework/#comment-110</link>
		<dc:creator>Tom Van Vleck</dc:creator>
		<pubDate>Mon, 19 Jan 2009 20:06:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/justiceleague/2008/10/15/software-security-framework/#comment-110</guid>
		<description>This is good and useful.  I would trya different set of rows to see what happens:
MODEL, POLICY, PROCEDURE, TOOL.  See http://www.multicians.org/thvv/vvcomb.html

The security MODEL is the identification of actors, interests, and relationships: the &quot;piping digram&quot; if you will.

Security POLICY states the goal.  That is, what flows we want in the pipes.

There may be many PROCEDUREs but each should be justified by pointing to the policies it supports.

Then we can talk about how the procedures are mechanized by TOOLs.</description>
		<content:encoded><![CDATA[<p>This is good and useful.  I would trya different set of rows to see what happens:<br />
MODEL, POLICY, PROCEDURE, TOOL.  See <a href="http://www.multicians.org/thvv/vvcomb.html" rel="nofollow">http://www.multicians.org/thvv/vvcomb.html</a></p>
<p>The security MODEL is the identification of actors, interests, and relationships: the &#8220;piping digram&#8221; if you will.</p>
<p>Security POLICY states the goal.  That is, what flows we want in the pipes.</p>
<p>There may be many PROCEDUREs but each should be justified by pointing to the policies it supports.</p>
<p>Then we can talk about how the procedures are mechanized by TOOLs.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

