Recent articles

Software@Risk

Secure coding for C/C++ training

Klocwork (who sell source code analysis tools) has a ‘Klocwork University‘ portal on their developers web site. They have announced an online Secure Coding for C/C++ course developed with Security Innovation. You have to register (free) to take the course.

(Note: this is provided for information, and is not an endorsement)

 

[...]

More Papers on Software

Cigital has a nice list of papers and other software risk publications located at www.cigital.com/papers.

 

Software Risk References

Here are a set of references for topics discussed in the webinar:

NIST:  http://csrc.nist.gov/publications/PubsSPs.html –SP 800-39 Mar. 2011 Managing Information Security Risk: Organization, Mission, and Information System View SP800-39-final.pdf –SP 800-27 Rev. A Jun 2004 Engineering Principles for Information Technology Security (A Baseline for Achieving Security) SP800-27-RevA.pdf –SP 800-12 Oct 1995 An Introduction to Computer [...]

Sotware@Risk Webinar Dec. 14

The final webinar in the IEEE-USA series on Risk Management will be Wednesday, December 14. The topic is “Software Risk Management”. This is the online companion site for discussion of the webinar.

Also see the companion article in IEEE-USA’s Todays Engineer: “Software Risk Management”.

Here are some references requested in the webinar:

SOFTWARE QUALITY & [...]