New Study Provides Real-World Data on Leading Software Security Initiatives
Posted on: Thursday, 5 March 2009, 05:00 CST
First-ever Maturity Model Details Success of Microsoft, Google and others
Based on in-depth interviews with leading enterprises such as Adobe, EMC, Google, Microsoft, QUALCOMM, Wells Fargo, and Depository Trust & Clearing Corporation (DTCC), the BSIMM pulls together a set of activities practiced by nine of the most successful software security initiatives in the world. Unlike some industry standards, BSIMM is a structured set of practices based on real-world data rather than philosophy and ideas. BSIMM provides insight on what successful organizations actually do to build security into their software and mitigate the business risk associated with insecure applications.
"Microsoft's Security Development Lifecycle (SDL) was one of the first real enterprise software security methodologies, and we are always eager to share our ideas and best practices with the industry," said
"Software security has turned the corner from a good idea to a business necessity. The industry has finally reached a point where enough real experience has been accumulated to compare notes and talk about what works," said Dr.
"Virtually every organization today relies on software to operate, and at the same time the threat to that software is at an all-time high," said Dr.
Chess, McGraw and coauthor
- The necessity of a Software Security Group: Each of the nine enterprises has a designated group of software security personnel -- the SSG -- tasked with carrying out and facilitating software security. Average SSG size is just over one percent of the size of the software development organization.
- Advocacy over audit: Successful SSGs, even in regulated industries, always emphasize security education, technical resources, and mentoring rather than policing for security errors and handing out punishments.
- Use of automated technologies: Each organization performs automated code review and deploys black box testing tools, but use of these technologies requires considerable SSG know-how.
- Training for development: All organizations have an institutionalized security training curriculum for programmers, QA engineers, and project managers.
"I was surprised by the amount of common ground discovered between the financial services organizations, ISVs, and technology companies in the BSIMM study," said
"Comprehensive software security involves a combination of people, processes, and technologies, and it almost always requires some change to the way the organization operates," said analyst
Over the next several months, Cigital and Fortify will gather data from other leading software security initiatives to enhance the study and provide additional insight on trends and activities particular to certain vertical industries and company sizes, among other factors.
The BSIMM is available under creative commons license here: http://bsi-mm.com.
About Fortify Software, Inc.
Fortify(R)'s Software Security Assurance products and services protect companies from the threats posed by security flaws in business-critical software applications. Its software security suite -- Fortify 360 -- drives down costs and security risks by automating key processes of developing and deploying secure applications. Fortify Software's customers include government agencies and FORTUNE 500 companies in a wide variety of industries, such as financial services, healthcare, e-commerce, telecommunications, publishing, insurance, systems integration and information management. The company is backed by world-class teams of software security experts and partners. More information is available at www.fortify.com or visit our blog at blog.fortify.com.
About Cigital
Cigital, Inc. is the leading software security and quality consulting firm. Established in 1992, Cigital plans and implements initiatives that help organizations ensure their applications are secure and reliable while also improving how they build and deploy software. Our recognized experts apply a combination of proven methodologies, tools, and best practices to meet each client's unique requirements. Cigital is headquartered near
SOURCE Fortify Software, Inc.
Source: PR Newswire
Related Articles
- Fortify Software Delivers Governance to Software Security and Brings Security Assurance to Third Party Software
- Software Security Solutions Introduces CyberPatrol Web Site Filtering Products and Services
- Leading Consumer Magazine Ranks BitDefender First Among Software Security Suites
- Cloakware Delivers Next Generation Software Security Toolkit for Apple Developers
- Cenzic Recognized As the Industry Leader in Software Security By SD Times
- MFS Investment Management Chooses Ounce Labs for Software Security Assurance
- Cigital CTO Gary McGraw Authors Definitive Software Security Book
- Research and Markets: Consumers Putting Pressure on ISVs and Equipment Manufacturers to Improve Software Security
- St. Paul, Minn.-Area Software Security, Consulting Firm Sees Patchwork Profits
User Comments (0)

RSS Feeds