Category · SD Elements

Applications are the Crash Test Dummies of Security

posted on Aug 10, 2011 by Rohit Sethi Comments:0

Once upon a time driving a car was substantially more dangerous than it is now. Manufacturers were not held liable for accidents caused by their processes. Then everything changed. Now car manufacturers build safety into their car design right from the start. Software developers have also begun to try and build more secure applications. The…

5 Key Design Decisions That Affect Security in Web Applications

posted on Feb 10, 2011 by Rohit Sethi Comments:0

Senior developers and architects often make decisions related to application performance or other areas that have significant ramifications on the security of the application for years to come. Some decisions are obvious: How do we authenticate users? How do we restrict page access to authorized users? Others, however, are not so obvious. The following list…

SDLC Security Audit Framework

posted on Mar 30, 2010 by Rohit Sethi Comments:0

We’ve put together a framework based on the OWASP Security Assurance Maturity Model and some of its user-contributed checklists to perform a security assessment on an organization’s SDLC. The intent here is not to find specific flaws in an application, but rather to measure the level of security baked into the process. Today, this kind of assessment…