Download Free Computer Ebooks - NET BOOKS
Free information, Free your knowledge!
11th
MAY
Software Security Engineering: A Guide for Project Managers
Posted by bandr under Software Development
Product Description
“This book’s broad overview can help an organization choose a set of processes, policies, and techniques that are appropriate for its security maturity, risk tolerance, and development style. This book will help you understand how to incorporate practical security techniques into all phases of the development lifecycle.”
–Steve Riley, senior security strategist, Microsoft Corporation
“There are books written on some of the topics addressed in this book, and there are other books on secure systems engineering. Few address the entire life cycle with a comprehensive overview and discussion of emerging trends and topics as well as this one.”
–Ronda Henning, senior scientist-software/security queen, Harris Corporation
Software that is developed from the beginning with security in mind will resist, tolerate, and recover from attacks more effectively than would otherwise be possible. While there may be no silver bullet for security, there are practices that project managers will find beneficial. With this management guide, you can select from a number of sound practices likely to increase the security and dependability of your software, both during its development and subsequently in its operation.
Software Security Engineering draws extensively on the systematic approach developed for the Build Security In (BSI) Web site. Sponsored by the Department of Homeland Security Software Assurance Program, the BSI site offers a host of tools, guidelines, rules, principles, and other resources to help project managers address security issues in every phase of the software development life cycle (SDLC). The book’s expert authors, themselves frequent contributors to the BSI site, represent two well-known resources in the security world: the CERT Program at the Software Engineering Institute (SEI) and Cigital, Inc., a consulting firm specializing in software security.
This book will help you understand why
-
Software security is about more than just eliminating vulnerabilities and conducting penetration tests
-
Network security mechanisms and IT infrastructure security services do not sufficiently protect application software from security risks
-
Software security initiatives should follow a risk-management approach to identify priorities and to define what is “good enough”–understanding that software security risks will change throughout the SDLC
-
Project managers and software engineers need to learn to think like an attacker in order to address the range of functions that software should not do, and how software can better resist, tolerate, and recover when under attack
About the Author
Julia H. Allen is a senior member of the technical staff within the CERT Program at the Software Engineering Institute (SEI), a unit of Carnegie Mellon University in Pittsburgh, PA. In addition to her work in software security and assurance, Allen is engaged in developing and transitioning executive outreach programs in enterprise security and governance. She is the author of The CERT Guide to System and Network Security Practices (Addison-Wesley, 2001), Governing for Enterprise Security (CMU/SEI, 2005), and the CERT Podcast Series: Security for Business Leaders (2006/2007).
Sean Barnum is a Principal Consultant at Cigital and is technical lead for their federal services practice. He has more than twenty years of experience in the software industry in the areas of development, software quality assurance, quality management, process architecture and improvement, knowledge management, and security. He is a frequent contributor and speaker for regional and national software security and software quality publications, conferences, and events. He is very active in the software assurance community and is involved in numerous knowledge standards-defining efforts, including the Common Weakness Enumeration (CWE), the Common Attack Pattern Enumeration and Classification (CAPEC), and other elements of the Software Assurance Programs of the Department of Homeland Security and the Department of Defense. He is also the lead technical subject matter expert for the Air Force Application Software Assurance Center of Excellence.
Robert J. Ellison, Ph.D., is a member of the Survivable Systems Engineering Team within the CERT Program at the Software Engineering Institute and, in that capacity, has served in a number of technical and management roles. He was a project leader for the evaluation of software engineering development environments and associated software development tools. He was also a member of the Carnegie Mellon University team that wrote the proposal for the SEI; he joined the new FFRDC in 1985 as a founding member. Ellison regularly participates in the evaluation of software architectures and contributes from the perspective of security and reliability measures.
Gary McGraw, Ph.D., is the CTO of Cigital, Inc., a software security and quality consulting firm with headquarters in the Washington, D.C., area. He is a globally recognized authority on software security and the author of six best selling books on this topic. The latest is Exploiting Online Games (Addison-Wesley, 2008). His other titles include Java Security, Building Secure Software, Exploiting Software, and Software Security; and he is editor of the Addison-Wesley Software Security series. McGraw has also written more than ninety peer-reviewed scientific publications, authors a monthly security column for darkreading.com, and is frequently quoted in the press. Besides serving as a strategic counselor for top business and IT executives, Gary is on the Advisory Boards of Fortify Software and Raven White. He serves on the Dean’s Advisory Council for the School of Informatics at Indiana University. Gary is an IEEE Computer Society Board of Governors member and produces the monthly Silver Bullet Security Podcast for IEEE Security & Privacy magazine.
Nancy R. Mead, Ph.D., is a senior member of the technical staff in the Survivable Systems Engineering Group, which is part of the CERT Program at the Software Engineering Institute. Mead is also a faculty member in the Master of Software Engineering and Master of Information Systems Management programs at Carnegie Mellon University. She has more than one hundred publications and invited presentations. She is a fellow of the Institute of Electrical and Electronic Engineers, Inc. (IEEE) and the IEEE Computer Society and is also a member of the Association for Computing Machinery (ACM).
Password default: netbks.com
Report Dead Link
Please leave a comment to report dead links, so that someone else may update new links.
Related Ebooks
- Engineering Wireless-Based Software Systems And Applications
- Integrating Security And Software Engineering: Advances And Future Vision
- Designing Software-Intensive Systems: Methods and Principles
- Software Engineering for Modern Web Applications: Methodologies and Technologies
- Role Engineering for Enterprise Security Management
- Model-Driven Software Development: Integrating Quality Assurance
- Verification, Validation and Testing in Software Engineering
- Handbook of Research on Web Information Systems Quality
- Trustworthy Computing: Analytical and Quantitative Engineering Evaluation
- Space-Time Codes and MIMO Systems
Leave a Reply
Post Meta
-
May 11, 2008 -
Software Development -
No Comments
-
Comments Feed
Subscribe
Featured Links
Categories
- Game Mini
- Comics
- Architecture
- Business & Investing
- Medical & Health
- Science & Engineering
- Scripts & Web Templates
- Ajax
- Algorithms
- C & C++
- Certification Stuff
- Database
- Delphi
- Development for Web
- Dot NET
- General Programming
- Graphics & Design
- Java
- JavaScript
- Magazines
- Networks
- Operating System
- Perl
- PHP
- Python
- Software Development
- UML
- Video Training
- XML
Recent Comments
- GaQuay: An Introduction to Computer Graphics and Creative 3-D Environments
- GaQuay: Scripting in Java: Languages, Frameworks, and Patterns
- dead link: Scripting in Java: Languages, Frameworks, and Patterns
- dead link: Java Web Services in a Nutshell
- dead link: An Introduction to Computer Graphics and Creative 3-D Environments
- I need This complete book: Programming Microsoft ASP.NET 3.5
- Eduardo: VTC Maya Fundamentals [ video ]
- Eduardo: VTC Maya Fundamentals [ video ]
- Deka: SQL Server 2005 Integration Services
- GaQuay: Building Parsers With Java
Links Exchange
- Daily Internet Guide
- Free Full Downloads
- Download Free PC Games
- DownArchive
- Download Free Software
- Full and Free
- Free IT ebooks and Videos
- RapidShare Links Downloads
- Softlinkers
- Solaris 10 online tutorials
- warezLook
- free download
- Free ebooks download
- mobilevodoo.com
- Area51WareZ
- GiGAWarez
- FunkyType.com
- DASofts.Com
- DLisland
- SoftNull Group Team
- Allulook4.com
- BoyGJ.COM
- Down61

Rss Feed



