SECCOM Labs logo
Resources for Secure
Software Engineering
from Security Compass

Case Study: The Skeptic

By Sahba Kazerooni on April 30, 2010, about: security scenarios

James Smith* was the manager of information security at a large healthcare company. After several years of primarily running penetration testing, and a few limited source code reviews, James successfully made the case to internal IT leadership that security needed to come earlier in the software development life cycle (SDLC).

James had heard many people talk about the concept of secure SDLC at a high-level, but was having trouble planning concrete steps. What specifically should they change about requirements, design, development and testing?

Read More…


Security Compass Youtube Channel

From our various training courses, we have quite a few videos that demonstrate web application attacks. Some are basic, and some are advanced attacks that are otherwise difficult to explain on paper. You can now access some of these videos through our Youtube channel. We’ll continue to update this channel as we create more demo videos. Enjoy!