<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Justice League &#187; gem</title>
	<atom:link href="http://www.cigital.com/justiceleague/author/gem/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cigital.com/justiceleague</link>
	<description>The Cigital Software Security and Quality Blog</description>
	<lastBuildDate>Thu, 02 Sep 2010 14:50:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Software Security Crosses the Threshold in 2009</title>
		<link>http://www.cigital.com/justiceleague/2010/08/16/software-security-crosses-the-threshold-in-2009/</link>
		<comments>http://www.cigital.com/justiceleague/2010/08/16/software-security-crosses-the-threshold-in-2009/#comments</comments>
		<pubDate>Mon, 16 Aug 2010 20:46:39 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=413</guid>
		<description><![CDATA[I have been tracking the software security market and publishing numbers since 2006.  This year’s article is now available on InformIT: Software Security Crosses the Threshold.
See these past (mysteriously named) articles for data from previous years:

InformIT (2008): Software Security Comes of Age: Space Approaches $500M threshold
InformIT (2007): Software Security Demand Rising
Darkreading (2006): Want Turns [...]]]></description>
			<content:encoded><![CDATA[<p>I have been tracking the software security market and publishing numbers since 2006.  This year’s article is now available on InformIT: <a href="http://www.informit.com/articles/article.aspx?p=1623792"><strong>Software Security Crosses the Threshold</strong></a>.</p>
<p>See these past (mysteriously named) articles for data from previous years:</p>
<ul>
<li>InformIT (2008): <a href="http://www.informit.com/articles/article.aspx?p=1338343">Software Security Comes of Age: Space Approaches $500M threshold</a></li>
<li>InformIT (2007): <a href="http://www.informit.com/articles/article.aspx?p=1237978">Software Security Demand Rising</a></li>
<li>Darkreading (2006): <a href="http://www.darkreading.com/security/management/showArticle.jhtml?articleID=208803627">Want Turns to Need</a></li>
</ul>
<p align="center"><img src="http://www.cigital.com/justiceleague/wp-content/uploads/2010/08/softsecspace-rev1.gif" alt="" title="Software Security Space Revenue" width="449" height="449" class="aligncenter size-full wp-image-419" /></p>
<p>The Figure above shows in millions of US dollars how the four major segments of the space have grown since 2006, from a total of $293.9 million (2006) to a total of $554.4 million in 2009. Note that even stronger growth is evident midway through 2010.  </p>
<p>Analysis and details are available in the <a href="http://www.informit.com/articles/article.aspx?p=1623792">informIT article</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2010/08/16/software-security-crosses-the-threshold-in-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cigital Participates in White House Discussion on the Progress of the President’s Cybersecurity Efforts</title>
		<link>http://www.cigital.com/justiceleague/2010/07/16/cigital-participates-in-white-house-discussion-on-the-progress-of-the-president%e2%80%99s-cybersecurity-efforts/</link>
		<comments>http://www.cigital.com/justiceleague/2010/07/16/cigital-participates-in-white-house-discussion-on-the-progress-of-the-president%e2%80%99s-cybersecurity-efforts/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 06:00:22 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Governance and Regulation]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=393</guid>
		<description><![CDATA[On Wednesday July 14, 2010, US Cyber Security Coordinator Howard Schmidt convened a hastily called meeting of around 100 public and private sector security experts at the White House to explain the progress he has made in the six months since he joined the administration.  I was there.  In an unexpected and exciting [...]]]></description>
			<content:encoded><![CDATA[<p>On Wednesday July 14, 2010, US Cyber Security Coordinator Howard Schmidt convened a hastily called meeting of around 100 public and private sector security experts at the White House to explain the progress he has made in the six months since he joined the administration.  I was there.  In an unexpected and exciting surprise, President Obama stopped by the meeting and spoke for 15-20 minutes.  </p>
<p style="clear: both;" align="center"><a href="http://www.cigital.com/justiceleague/wp-content/uploads/2010/07/obama.jpg"><img src="http://www.cigital.com/justiceleague/wp-content/uploads/2010/07/obama.jpg" alt="" title="obama" width="480" height="360" class="aligncenter size-full wp-image-397" /></a></p>
<p>Here is a picture I took of President Obama addressing the meeting.  Howard Schmidt is to the far left. Beside him is Department of Homeland Security (DHS) Deputy Undersecretary Phil Reitinger.  The moment President Obama entered the meeting was electric.  Attendees immediately stood and gave him an ovation.  The room was energized, and the President’s charisma was palpable.  I, for one, was proud to be there.</p>
<p>In addition to remarks from President Obama and Howard Schmidt, the meeting was addressed by two cabinet Secretaries—Janet Napolitano, Secretary of DHS, and Gary Locke, Secretary of Commerce.  The invitation-only event included members of the Administration, state and local government officials, law enforcement officers, select industry executives, academics and representatives from privacy and civil liberties groups.  Attendees who I know included <a href="http://www.cigital.com/silverbullet/show-039/">Matt Blaze</a>, Carl Landwehr, <a href="http://www.cigital.com/silverbullet/show-022/">Ed Amoroso</a>, Marc Rotenberg, <a href="http://www.cigital.com/silverbullet/show-018/">Eugene Spafford</a>, Mischel Kwon, and John Savage.</p>
<p>I wrote up my thoughts on the meeting in an informIT article “<a href="http://www.informit.com/articles/article.aspx?p=1617137"><strong>Obama Highlights Cyber Security Progress: Private Sector Security Experts Convene at the White House to Discuss the National Cyber Securiy Agenda</strong></a>.”</p>
<p>Howard <a href="http://www.whitehouse.gov/blog/2010/07/14/progress-report-cybersecurity">described his impressions of the meeting</a> and its purpose on the White House blog.  An <a href="http://www.whitehouse.gov/administration/eop/nsc/cybersecurity/progressreports/july2010">official progress report</a> is also available there.</p>
<p align="center"><a href="http://www.cigital.com/justiceleague/wp-content/uploads/2010/07/obama2.jpg"><img src="http://www.cigital.com/justiceleague/wp-content/uploads/2010/07/obama2.jpg" alt="" title="obama2" width="480" height="392" class="aligncenter size-full wp-image-398" /></a></p>
<p align="center"><a href="http://www.cigital.com/justiceleague/wp-content/uploads/2010/07/obama3.jpg"><img src="http://www.cigital.com/justiceleague/wp-content/uploads/2010/07/obama3.jpg" alt="" title="obama3" width="480" height="265" class="aligncenter size-full wp-image-399" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2010/07/16/cigital-participates-in-white-house-discussion-on-the-progress-of-the-president%e2%80%99s-cybersecurity-efforts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Silver Bullet Turns 50</title>
		<link>http://www.cigital.com/justiceleague/2010/06/02/silver-bullet-turns-50/</link>
		<comments>http://www.cigital.com/justiceleague/2010/06/02/silver-bullet-turns-50/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 19:58:38 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=377</guid>
		<description><![CDATA[It’s hard to believe that the Silver Bullet Security Podcast has been running for 50 consecutive months!  Silver Bullet has thousands of listeners, and it’s always fun to produce.  Writing the script usually takes an hour or two, and requires some advance research from Brandi Ortega of IEEE S&#038;P fame.  Then we [...]]]></description>
			<content:encoded><![CDATA[<p>It’s hard to believe that the Silver Bullet Security Podcast has been running for 50 consecutive months!  Silver Bullet has thousands of listeners, and it’s always fun to produce.  Writing the script usually takes an hour or two, and requires some advance research from Brandi Ortega of IEEE S&#038;P fame.  Then we do recording (almost always over the phone) and post production mixing to add in the music.</p>
<p>For our 50th episode, we decided to shoot some HD video or our interview with Richard Clarke.  Ryan and I bought some cheap digital cameras, (really importantly) some lights, and a “clapper” which we drove out to Arlington for the shoot.  We recorded audio separately with boom mics and a USB mixer.  Then came the video editing&#8230;</p>
<p>And the result?  Check it out yourself here:</p>
<div align="center">
<img src="http://www.cigital.com/justiceleague/wp-content/plugins/flash-video-player/default_video_player.gif" />
</div>
<p>It amazes me what you can do for less than $1000 bucks with video these days.  Shouts to Marcus Ranum for the photography advice.  Thanks Ryan for the extra effort on this episode!  And also thanks to <em>IEEE Security &#038; Privacy</em> magazine for co-sponsoring the podcast.</p>
<p>We hope you like Silver Bullet, and we welcome your feedback on the <a href="http://www.cigital.com/silverbullet/">Silver Bullet website</a>.  <a href="http://www.cigital.com/silverbullet/feed/">Subscribe today</a> via RSS or on <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=154782182">iTunes</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2010/06/02/silver-bullet-turns-50/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://www.cigital.com/silverbullet/videos/silverbullet-050.flv" length="92792089" type="video/x-flv" />
		</item>
		<item>
		<title>BSIMM2</title>
		<link>http://www.cigital.com/justiceleague/2010/05/12/bsimm2/</link>
		<comments>http://www.cigital.com/justiceleague/2010/05/12/bsimm2/#comments</comments>
		<pubDate>Wed, 12 May 2010 05:10:51 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[BSIMM]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=371</guid>
		<description><![CDATA[In March 2009 we announced the publication of the BSIMM&#8212;a measuring stick for software security.  We&#8217;re pleased today to announce the publication of BSIMM2.  We have tripled the size of the data set to thirty firms, including: Adobe, Aon, Bank of America, Capital One, The Depository Trust &#038; Clearing Corporation (DTCC), EMC, Google, [...]]]></description>
			<content:encoded><![CDATA[<p>In March 2009 we announced the publication of the BSIMM&#8212;a measuring stick for software security.  We&#8217;re pleased today to announce the publication of BSIMM2.  We have tripled the size of the data set to thirty firms, including: Adobe, Aon, Bank of America, Capital One, The Depository Trust &#038; Clearing Corporation (DTCC), EMC, Google, Intel, Intuit, Microsoft, Nokia, QUALCOMM, Sallie Mae, Standard Life, SWIFT, Symantec, Telecom Italia, Thomson Reuters, VMware, and Wells Fargo.</p>
<p>BSIMM2 is available for free under the creative commons license from <a href="http://bsimm2.com/">bsimm2.com</a>.  Download your copy today.  </p>
<p>The BSIMM2 document itself is 53 pages.  A concise treatment of the results can be found in this month&#8217;s informIT column in an article titled &#8220;<a href="http://www.informit.com/articles/article.aspx?p=1592389">BSIMM2: Measuring the Emergence of a Software Security Community</a>.&#8221;</p>
<p>Our study represents the work of 635 people who are members of the 30 firms’ SSGs.  Together, the firms have a collective 130 years of experience planning and executing 30 software security initiatives.  Among other results, we have identified 15 core BSIMM activities.</p>
<p>We think the descriptive nature of the BSIMM study is an important characteristic of the work.  We describe not what you should do for software security, but what successful software security initiatives are actually doing.  Use BSIMM2 to measure your own software security initiative and compare it to others.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2010/05/12/bsimm2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Is Cyber War Inevitable?</title>
		<link>http://www.cigital.com/justiceleague/2010/05/06/is-cyber-war-inevitable/</link>
		<comments>http://www.cigital.com/justiceleague/2010/05/06/is-cyber-war-inevitable/#comments</comments>
		<pubDate>Thu, 06 May 2010 15:24:37 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=362</guid>
		<description><![CDATA[Turns out that Richard Clarke is a national security policy wonk.  I guess that fact is not that surprising if you knew that Mr. Clarke was once an Assistant Secretary of State working on nuclear arms control issues during the Reagan years.  The general public knows Dick best as a key figure in [...]]]></description>
			<content:encoded><![CDATA[<p>Turns out that Richard Clarke is a national security policy wonk.  I guess that fact is not that surprising if you knew that Mr. Clarke was once an Assistant Secretary of State working on nuclear arms control issues during the Reagan years.  The general public knows Dick best as a key figure in counter-terrorism who famously testified before the 9-11 commission and then became enmeshed in partisan battles.  Those of us on the front lines cyber security know Dick best as one of the first political types to focus real attention on computer security.  For that, we owe Dick a major thank you.</p>
<p><img src="/images/cyberwar.gif" width="132" height="200" alt="Cyberwar cover" align="right" style="padding-left: 10px; padding-bottom: 5px; clear: both;"> In his new book <a href="http://www.amazon.com/Cyber-War-Threat-National-Security/dp/0061962236"><em>Cyber War</em></a>, co-authored by foreign policy expert Robert Knake, Mr. Clarke confronts an important topic too often swept under the rug with the burgeoning pile of security FUD—the notion of cyber war.  US citizens have every right to worry about cyber war given our risk exposure.  The risks of cyber war and some of the potential consequences are impressively covered in the book and even include doomsday scenarios that are getting Dick into <a href="http://www.wired.com/threatlevel/2010/04/cyberwar-richard-clarke/">hot water with the hipsters at Wired</a>.  Consider how little North Korea depends on the Internet (ok, they are only barely scraping by as a society), then consider the same dependency in the US.  See the problem?</p>
<p>One of the challenges of discussing computer security rationally in the Internet Age is that devastating consequences always seem hyperbolic, even when they’re not.  Turns out that taking down the power grid with a cyber attack is <a href="http://www.cigital.com/justiceleague/2010/03/22/smart-grid-equals-dumb-security/">not outside the realm of possibility</a>.  I’ve been told by people who actually engineer and run the grid for a living that inflicting permanent damage taking years to fix is more than possible given current design.  Nor is the notion of an Information Warfare attack preceding “kinetic” involvement with explosive chunks of metal some kind of idea from Mars.  One of the coolest stories in the book involves the Israeli destruction of the ill-fated Syrian nuclear facility.  Scary?  Yes.  Hyperbolic?  Not so much.</p>
<p>There are a few technical nits to pick, of course.  Calling out the Estonian dDOS attack (most likely perpetrated by the Russians) as some kind of major cyber attack is a bit over the top.  dDOS attacks are the stuff of script kiddies and solutions that thwart them are over a decade old.   Most problematic of all is the overemphasis on network security mechanisms and ISPs as proposed technical solutions to the problem.  I know Ed Amoroso (CSO of AT&#038;T) believes that security defenses and monitors need to be put in place in the tier1 ISPs, and it’s very clear that he has convinced Dick of that.  But as a computer security expert, I am skeptical of that solution.  In my view, the only way we can properly address the cyber war problem is by attacking software security head on.  Fortunately Dick says the right things about software vulnerability, demonstrating a nuanced understanding all too rare among politicals.</p>
<p>From a policy perspective, the ideas in Cyber War are fresh, new, and important.  Dick’s mastery of arms control strategy comes to the fore when he discusses various ideas about cyber war non-proliferation.  I must confess that my knowledge of such things is rudimentary at best.  I wonder, probably naïvely, how we can think of controlling something as invisible as cyber attack capability (not to mention Trojan Horses and logic bombs) when we can’t even stop Iran from refining uranium like the complete nut-jobs that they are.  But SALT II and START came from somewhere, and they have been a very good thing for the world.</p>
<p>Some of my foreign colleagues in computer security (but not all, see <a href="http://blog.flameeyes.eu/2010/04/28/book-review-cyber-war">this posting from Italy for example</a>) wonder why we are so obsessed with cyber war in the States.  They are not sure why we are the only society openly discussing these things.  Perhaps they hear the drums of war beating again as they did in the impressively-orchestrated and utterly-delusional run up to the Iraq war.  More likely I think the answer to that question lies in understanding just how vulnerable we are in the States.  We may not be the most wired country in the world from a consumer perspective, but we’re the most wired country in the world from a critical infrastructure perspective.  Cyber war is a serious problem that calls out for serious solutions.  </p>
<p>In final analysis, I think it behooves every computer security person to read this book and think through its points carefully.  Even if you disagree with some parts of the book (as I do), we must do what we can as technically adept citizens to involve ourselves in the political discourse around cyber war.  Dick does an excellent job getting the conversation started.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2010/05/06/is-cyber-war-inevitable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Grid equals Dumb Security?</title>
		<link>http://www.cigital.com/justiceleague/2010/03/22/smart-grid-equals-dumb-security/</link>
		<comments>http://www.cigital.com/justiceleague/2010/03/22/smart-grid-equals-dumb-security/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 18:43:55 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=337</guid>
		<description><![CDATA[I recently had the pleasure of giving a keynote at the NRECA annual conference in Atlanta.  The conference brings together senior management and Board members from rural electric cooperatives throughout the country.  Some coops are large in terms of the number of subscribers, and some are large in terms of geographic area covered [...]]]></description>
			<content:encoded><![CDATA[<p>I recently had the pleasure of giving a keynote at the <a href="http://www.nreca.org/">NRECA</a> annual conference in Atlanta.  The conference brings together senior management and Board members from rural electric cooperatives throughout the country.  Some coops are large in terms of the number of subscribers, and some are large in terms of geographic area covered (those numbers often run opposite to each other).  My job as keynoter was to introduce some thinking about computer security to business people who operate power grids for a living.  This is a big challenge for a geek like me.</p>
<p>Of course I ended up touching on software security, especially the fact that power meters for the “smart grid” are little IP-enabled computers hung on the outside of your house.  Given known attacks against this new breed of meters, the question is how many rooted smart grid meters in a botnet could cause a really serious problem?</p>
<p>Here is my talk in its entirety.  Your feedback is welcome.</p>
<p align="center">
            <object id="csSWF" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="415" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version==8"><param name="src" value="/presentations/Cyber Security/Cyber Security_controller.swf#"/><param name="bgcolor" value="FFFFFF"/><param name="quality" value="best"/><param name="allowScriptAccess" value="always"/><param name="flashVars" value="csConfigFile=/presentations/Cyber Security/Cyber Security_config.xml&#038;csColor=FFFFFF"/><embed name="csSWF" src="/presentations/Cyber Security/Cyber Security_controller.swf" width="480" height="415" bgcolor="FFFFFF" quality="best" allowScriptAccess="always" flashVars="csConfigFile=/presentations/Cyber Security/Cyber Security_config.xml&#038;csColor=FFFFFF" pluginspage="http://www.adobe.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed></object>
        </p>
<p align="center"><a href="/presentations/Cyber%20Security/Cyber%20Security.mp3"><strong>Download audio</strong></a> [mp3]<br />
<a href="/presentations/Cyber%20Security/NRECA-cyber-grid.pdf"><strong>Download presentation</strong></a> [pdf]</p>
<p>I’m pleased that Cigital is directly involved in working to make smart grid security a reality.  We’re working directly with <a href="http://www.nreca.org/">NRECA</a> to bring electric cooperatives up to speed with cyber risk management.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2010/03/22/smart-grid-equals-dumb-security/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>BSIMM2: The Magic Number 30</title>
		<link>http://www.cigital.com/justiceleague/2010/03/03/bsimm2-the-magic-number-30/</link>
		<comments>http://www.cigital.com/justiceleague/2010/03/03/bsimm2-the-magic-number-30/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 14:56:06 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[BSIMM]]></category>
		<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=330</guid>
		<description><![CDATA[BSIMM2 is the 30 firm version of BSIMM.  I wrote up an article with Brian Chess and Sammy Migues (my BSIMM co-creators) called “Software [In]security: What Works in Software Security &#8212; Fifteen Common Activities from BSIMM2.”  In addition to highlighting the fifteen most common BSIMM activities, the article also provides the 30 firm [...]]]></description>
			<content:encoded><![CDATA[<p>BSIMM2 is the 30 firm version of BSIMM.  I wrote up an article with Brian Chess and Sammy Migues (my BSIMM co-creators) called “<a href="http://www.informit.com/articles/article.aspx?p=1569495">Software [In]security: What Works in Software Security &#8212; Fifteen Common Activities from BSIMM2</a>.”  In addition to highlighting the fifteen most common BSIMM activities, the article also provides the 30 firm data for all 110 activities in public for the first time.</p>
<p>We’re unveiling some statistical results at RSA this week that will enhance and expand the dataset published in the article.  We’ll do an official BSIMM2 launch within the next couple of months.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2010/03/03/bsimm2-the-magic-number-30/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I Repeat Myself When Under Stress, I Repeat Myself When Under Stress</title>
		<link>http://www.cigital.com/justiceleague/2010/02/17/i-repeat-myself-when-under-stress-i-repeat-myself-when-under-stress/</link>
		<comments>http://www.cigital.com/justiceleague/2010/02/17/i-repeat-myself-when-under-stress-i-repeat-myself-when-under-stress/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 14:48:02 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[BSIMM]]></category>
		<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=320</guid>
		<description><![CDATA[Apparently the time has come to re-release the SANS/CWE 25 &#8212; something that we can expect annually.  The good news is that exercises like this do plenty to hype up software security and its importance.  In fact, in many ways the target of these lists is “the reporters who cover software security.”  [...]]]></description>
			<content:encoded><![CDATA[<p>Apparently the time has come to re-release the <a href="http://cwe.mitre.org/top25/">SANS/CWE 25</a> &#8212; something that we can expect annually.  The good news is that exercises like this do plenty to hype up software security and its importance.  In fact, in many ways the target of these lists is “the reporters who cover software security.”  So hype = good.</p>
<p>So why am I not a big fan of these lists?  Well, I wrote that down a year ago and what I said then still applies.  Sure would be nice to see a reasoned response to my criticisms instead of repetition of the same tired ideas.  If you haven’t had a chance yet, go read my January 2009 informIT column &#8220;<a href="http://www.informit.com/articles/article.aspx?p=1322398">Top 11 Reasons Why Top 10 (or Top 25) Lists Don&#8217;t Work</a>.&#8221;</p>
<p>There are some important improvements in this year’s top25 list that have been discussed on sc-l.  But there is also a problem that really bothers me.  The SANS guys are trying to tie the top25 list to software liability (?!) and apparently think they can hold developers accountable for their bugs..well, 25 of them at least.  I think this is a wrongheaded approach to software security.  I would much rather talk about the real progress the field has made than to hype up yet another list and make the list a critical aspect of software contracts?!  Can you imagine what such a move (if it succeeded) would do to the price of software and to the hourly rates of developers?  Developers would be compensated like lawyers!</p>
<p>Top-n lists do have their place.  In the <a href="http://bsi-mm.com">BSIMM</a> we note 10 firms (of 30) who follow activity [<a href="http://www.bsi-mm.com/ssf/ssdl/cr/?s=cr1.1#cr1.1">CR1.1</a>].  Here is the activity cut from the BSIMM:</p>
<blockquote><p><strong>Create a top N bugs list (real data preferred).</strong> The SSG maintains a list of the most important kinds of bugs that need to be eliminated from the organization’s code. The list helps focus the organization’s attention on the bugs that matter most. A generic list could be culled from public sources, but a list is much more valuable if it is specific to the organization and built from real data gathered from code review, testing, and actual incidents. The SSG can periodically update the list and publish a “most wanted” report. (For another way to use the list, see [<a href="http://www.bsi-mm.com/ssf/governance/t/?s=t2.2#t2.2">T2.2</a>] <em>Create/ use material specific to company history.</em>)</p></blockquote>
<p>In my view, a tailored top-n bugs list is way more useful than a generic “world list” like the SANS/CWE25.  To think about why this is, consider the differences between code bases from Intel, Microsoft, Symantec, and Nokia (not to mention Wells Fargo)&#8230;all BSIMM participants.  Whose bugs do you want to eradicate?  Yours?  Or your neighbors?</p>
<p>Press coverage of the “controversy”:</p>
<ul>
<li><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1387131,00.html">SANS Institute, MITRE release new top 25 dangerous coding errors list</a>, TechTarget.</li>
<li><a href="http://www.bankinfosecurity.com/articles.php?art_id=2204">Top 25 Programming Errors: Should Software Developers be Liable?</a>, Bank Info Security.</li>
<li><a href="http://www.computerworld.com/s/article/9157218/Hold_vendors_liable_for_buggy_software_group_says?taxonomyId=63&#038;pageNumber=2">Hold vendors liable for buggy software, group says</a>, ComputerWorld.</li>
<li><a href="http://www.scientificamerican.com/blog/post.cfm?id=25-ways-to-better-secure-software-f-2010-02-16">25 ways to better secure software from cyber attacks</a>, <em>Scientific American</em> Observations.</li>
<li><a href="http://washingtontechnology.com/articles/2010/02/16/top-25-programming-errors.aspx">Security agencies release Top 25 programming errors</a>, Washington Technology.</li>
<li><a href="http://www.darkreading.com/vulnerability_management/security/app-security/showArticle.jhtml?articleID=222900574">Proposal Would Hold Software Developers Accountable For Security Bugs</a>, Dark Reading.</li>
<li><a href="http://www.govinfosecurity.com/articles.php?art_id=2205">Group Proposes Suits Over Faulty Code</a>, Gov Info Security.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2010/02/17/i-repeat-myself-when-under-stress-i-repeat-myself-when-under-stress/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>BSIMM update</title>
		<link>http://www.cigital.com/justiceleague/2010/01/28/bsimm-update/</link>
		<comments>http://www.cigital.com/justiceleague/2010/01/28/bsimm-update/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 14:56:11 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[BSIMM]]></category>
		<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=293</guid>
		<description><![CDATA[The BSIMM study data set has more than tripled in size and now includes data from 30 firms.  We are busy working with Betsy Nichols to crunch the numbers now that we have a statistically significant data set.  The plan is to announce our results at RSA.
One question that comes up in the [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://bsi-mm.com">BSIMM study</a> data set has more than tripled in size and now includes data from 30 firms.  We are busy working with Betsy Nichols to crunch the numbers now that we have a statistically significant data set.  The plan is to announce our results at RSA.</p>
<p>One question that comes up in the BSIMM work fairly consistency is the difference between BSIMM and other maturity models for software security.   To answer that question, I wrote an article for informIT entitled “<a href="http://www.informit.com/articles/article.aspx?p=1562220">Cargo Cult Computer Security: Why we need more description and less prescription</a>.&#8221;</p>
<p align="center">
            <object id="csSWF" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="525" height="450" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version==8"><param name="src" value="sans_controller.swf#"/><param name="bgcolor" value="FFFFFF"/><param name="quality" value="best"/><param name="allowScriptAccess" value="always"/><param name="flashVars" value="csConfigFile=/presentations/sans-webcast/sans_config.xml&#038;csColor=FFFFFF"/><embed name="csSWF" src="/presentations/sans-webcast/sans_controller.swf" width="525" height="450" bgcolor="FFFFFF" quality="best" allowScriptAccess="always" flashVars="csConfigFile=/presentations/sans-webcast/sans_config.xml&#038;csColor=FFFFFF" pluginspage="http://www.adobe.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed></object>
        </p>
<p align="center"><a href="/presentations/sans-webcast/sans.mp3"><strong>Download audio</strong></a> [mp3]</p>
<p>David Rice, the author of Geekonomics (as well as the <a href="/silverbullet/show-046/">46th Silver Bullet Security podcast victim</a>), and I discuss the BSIMM in a webcast about the upcoming SANS software security event in San Francisco.</p>
<p>The time for science is upon us.  And the first step in any scientific approach is measurement.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2010/01/28/bsimm-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Howard Schmidt Cybersecurity Czar</title>
		<link>http://www.cigital.com/justiceleague/2009/12/22/howard-schmidt-cybersecurity-czar/</link>
		<comments>http://www.cigital.com/justiceleague/2009/12/22/howard-schmidt-cybersecurity-czar/#comments</comments>
		<pubDate>Tue, 22 Dec 2009 18:05:43 +0000</pubDate>
		<dc:creator>gem</dc:creator>
				<category><![CDATA[Governance and Regulation]]></category>
		<category><![CDATA[Software Security]]></category>

		<guid isPermaLink="false">http://www.cigital.com/justiceleague/?p=279</guid>
		<description><![CDATA[Our sincere congratulations to Howard Schmidt for taking on one of the most important jobs in computer security&#8212;US Cybersecurity Coordinator for the White House.  Howard knows what he’s getting into, because he already did it once.  (You’re crazy Howard!)
Here’s what the White House has to say.
Back in July I talked about what I [...]]]></description>
			<content:encoded><![CDATA[<p>Our sincere congratulations to Howard Schmidt for taking on one of the most important jobs in computer security&#8212;US Cybersecurity Coordinator for the White House.  Howard knows what he’s getting into, because he already did it once.  (You’re crazy Howard!)</p>
<p><a href="http://www.whitehouse.gov/blog/2009/12/22/introducing-new-cybersecurity-coordinator">Here’s what the White House has to say</a>.</p>
<p>Back in July I talked about what I would like to see in the position in a <a href="http://www.cigital.com/justiceleague/2009/07/14/moving-cybersecurity-past-cyberplatitudes/">Justice League post</a>  and a video for Gartner.  I stand by my statements from July.  However, I am psyched that Howard is taking the job.  He understands the importance of building security in and will be a powerful advocate for software security.</p>
<p>What a great way to start 2010!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cigital.com/justiceleague/2009/12/22/howard-schmidt-cybersecurity-czar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
