<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Show 026 - An Interview with Adam Shostack</title>
	<atom:link href="http://www.cigital.com/silverbullet/show-026/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cigital.com/silverbullet/show-026/</link>
	<description>In-depth conversations with leading security gurus, hosted by Gary McGraw, sponsored by IEEE Security &#38; Privacy Magazine.</description>
	<pubDate>Wed, 03 Dec 2008 07:10:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: Stephen Craig Evans</title>
		<link>http://www.cigital.com/silverbullet/show-026/#comment-29299</link>
		<dc:creator>Stephen Craig Evans</dc:creator>
		<pubDate>Fri, 23 May 2008 04:32:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.cigital.com/silverbullet/show-026/#comment-29299</guid>
		<description>Another home run, Gary, but it could have been twice as long! I'm looking forward to getting the book.

In general, I think we are getting to the same point in time (and maturity) similar to some of the BSVs (Big Security Vendors) who still put out white papers that profoundly point out that software security is important. Meaning, we know that we need metrics to measure effectiveness and to be able to decide where to spend the money (also brought up by Mary Ann Davidson in your podcast with her).

I guess I should go check out what the Metrics Guys are doing (revisit Jaquith's book, check out Metricon, etc). They're probably a couple of years ahead of me.

I wonder why as a community that we aren't talking more about application classification. I have seen only this paper:
The Importance of Application Classification in Secure Application Development
http://www.webappsec.org/projects/articles/041607.shtml

It seems that that would be a first step in putting price tags on software security efforts. And software security pros would have that knowledge, especially consultants that do different types of engagements.

Keep'em coming,
Stephen</description>
		<content:encoded><![CDATA[<p>Another home run, Gary, but it could have been twice as long! I&#8217;m looking forward to getting the book.</p>
<p>In general, I think we are getting to the same point in time (and maturity) similar to some of the BSVs (Big Security Vendors) who still put out white papers that profoundly point out that software security is important. Meaning, we know that we need metrics to measure effectiveness and to be able to decide where to spend the money (also brought up by Mary Ann Davidson in your podcast with her).</p>
<p>I guess I should go check out what the Metrics Guys are doing (revisit Jaquith&#8217;s book, check out Metricon, etc). They&#8217;re probably a couple of years ahead of me.</p>
<p>I wonder why as a community that we aren&#8217;t talking more about application classification. I have seen only this paper:<br />
The Importance of Application Classification in Secure Application Development<br />
<a href="http://www.webappsec.org/projects/articles/041607.shtml" rel="nofollow">http://www.webappsec.org/projects/articles/041607.shtml</a></p>
<p>It seems that that would be a first step in putting price tags on software security efforts. And software security pros would have that knowledge, especially consultants that do different types of engagements.</p>
<p>Keep&#8217;em coming,<br />
Stephen</p>
]]></content:encoded>
	</item>
</channel>
</rss>
