Enterprise Software Security
Software Security Now: 2006 Shows Impressive Growth
In my April darkreading column, “Want Turns to Need,??? I describe the state of the market for software security. I am very much optimistic about the software security space. In a few short years, we have created a space with a small ($250-275 million) but growing market niche. Last year, the tools market doubled in [...]
To Bolster Software Security Development Capability: Look at How R&D Has Changed in the last 50 years?
While reading last week’s Economist, I stumbled on an article on Innovation (available without a subscription online). The article discussed how commercial entities have changed the way they fund R&D. They’ve fundamentally changed the structure of research and development groups–as well as their interaction. I began my Cigital career in the company’s research division and [...]
Cigital’s Touchpoints versus Microsoft’s SDL
Recently, someone at Cigital asked me to characterize the difference between our approach to software security and Microsoft’s. Before I get to comparing things I want to note that we’re big fans of Microsoft when it comes to software security. Under the leadership of Michael Howard and Steve Lipner, Microsoft has made great progress in [...]
Darn the SOX, We Need More Security Ahead
The PCAOB is introducing new guidance to help lower the overall cost and, presumably, increase the effectiveness of SOX 404 audits. It needs to use this opportunity to help fix some root causes, not just tell us how to find more symptoms. This past December, the PCAOB announced that it would propose for public comment [...]
Keeping up with the Jones’ Security Initiatives
Frequently, those directing software security initiatives ask what others in their space are doing. I believed this was a perfectly reasonable question and answered, dutifully protecting each side’s confidentiality as best as humanly possible. Indeed, this kind of perspective represents one key value Cigital provides to our clients. Over time my relationship with clients deepened, [...]