Bridging the Gap between Software Development and Information Security

  • Authors:
  • Kenneth R. van Wyk;Gary McGraw

  • Affiliations:
  • Cigital and KRVW Associates;Cigital

  • Venue:
  • IEEE Security and Privacy
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Traditionally, software development efforts in large corporations have been about as far removed from information security as they were from human resources or any other business function. The disconnect between security and development has ultimately produced software development efforts that lack any sort of contemporary understanding of technical security risks. Today's complex and highly connected computing environments trigger myriad security concerns, so by blowing off the idea of security entirely, software builders virtually guarantee that their creations will have way too many security weaknesses that could--and should--have been avoided. This article presents some recommendations for solving this problem.