<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Show 001 &#8211; An Interview with Steve Lipner</title>
	<atom:link href="http://www.cigital.com/realitycheck/show-001/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cigital.com/realitycheck/show-001/</link>
	<description>The Reality Check Podcast with Gary McGraw focuses directly on software security practitioners and practical software security.   Reality Check’s sister podcast, the Silver Bullet Security Podcast with Gary McGraw, follows a free form interview style tailored highlight the ideas and experience of security gurus.  By contrast, Reality Check is concerned with practical questions centered on running large-scale software security initiatives in the real world.

Reality Check targets experienced leaders working to solve software security problems in large organizations every day.  We use a standard script to guide each conversation with questions about history, methodology, best practice, and measurement.  We plan to interview leaders of mature software security programs and leaders of programs just getting started.</description>
	<lastBuildDate>Wed, 11 Nov 2009 05:41:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: gem</title>
		<link>http://www.cigital.com/realitycheck/show-001/comment-page-1/#comment-4</link>
		<dc:creator>gem</dc:creator>
		<pubDate>Tue, 20 Jan 2009 14:42:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/realitycheck/?p=5#comment-4</guid>
		<description>Hi Stephen,

Thanks for the suggestion.  I love the idea of a roundtable on the SDL and will try to make that happen.

Security testing has come up a few times in various silver bullet episodes.  I agree that it deserves more airplay.

gem</description>
		<content:encoded><![CDATA[<p>Hi Stephen,</p>
<p>Thanks for the suggestion.  I love the idea of a roundtable on the SDL and will try to make that happen.</p>
<p>Security testing has come up a few times in various silver bullet episodes.  I agree that it deserves more airplay.</p>
<p>gem</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Craig Evans</title>
		<link>http://www.cigital.com/realitycheck/show-001/comment-page-1/#comment-3</link>
		<dc:creator>Stephen Craig Evans</dc:creator>
		<pubDate>Tue, 20 Jan 2009 03:48:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/realitycheck/?p=5#comment-3</guid>
		<description>Hi Gary,

Great stuff, especially when you inject your own experience and compare notes with the guest; I&#039;ve listened to it 3 times already. Yes, you started at the top!

From listening to pretty much all of your podcasts, I see some questions that you are consistently asking like &quot;what are the top 2 software security practices that you recommend?&quot; and &quot;what difference do you see between web app security and general software security?&quot; (I&#039;m broadly paraphrasing this one because I think that it&#039;s the point you are getting at)... I would like to see a couple of more like: &quot;is security testing being done by a separate security group, by QA testers, or how? And, if not by a separate security group, how are they trained and chosen?&quot; and some details about their SDL and how it applies to their types of applications (something along the lines of the Silverbullet Cigital roundtable discussing different SDLs; and Mary Ann Davidson of Oracle completely evaded your question to her on this topic in her Silverbullet podcast).

Cheers,
Stephen</description>
		<content:encoded><![CDATA[<p>Hi Gary,</p>
<p>Great stuff, especially when you inject your own experience and compare notes with the guest; I&#8217;ve listened to it 3 times already. Yes, you started at the top!</p>
<p>From listening to pretty much all of your podcasts, I see some questions that you are consistently asking like &#8220;what are the top 2 software security practices that you recommend?&#8221; and &#8220;what difference do you see between web app security and general software security?&#8221; (I&#8217;m broadly paraphrasing this one because I think that it&#8217;s the point you are getting at)&#8230; I would like to see a couple of more like: &#8220;is security testing being done by a separate security group, by QA testers, or how? And, if not by a separate security group, how are they trained and chosen?&#8221; and some details about their SDL and how it applies to their types of applications (something along the lines of the Silverbullet Cigital roundtable discussing different SDLs; and Mary Ann Davidson of Oracle completely evaded your question to her on this topic in her Silverbullet podcast).</p>
<p>Cheers,<br />
Stephen</p>
]]></content:encoded>
	</item>
</channel>
</rss>
