Building Security into Software with Security Policies & Static Analysis
Building Security into Software with Security Policies & Static Analysis
The common approach to securing applications is to try to identify and remove all of the application's security vulnerabilities at the end of the development process. However, this bug-finding approach is not only resource-intensive, it's largely ineffective. To have any chance of exposing all of the security vulnerabilities that may be nested throughout the application, the team would have to identify every single path through the application then rigorously test each and every one. And any error found would be difficult to fix, considering that the effort, cost, and time required to fix each one increases exponentially as the development process progresses. Most importantly, the bug-finding approach to security fails to address the root cause of the problem - the fact that security, like quality, must be built into the application.
For the complete article:
Building Security into Software with Security Policies & Static ...
For more information on SOA Security Appliances:
Check out the "official" SOA Appliance web site: www.soaappliances.com
_________________________________________________________________________________________
_________________________________________________________________________________________
Back to Main Page
Gary E. Smith
SOA Security Architect - Securing SOA in a Connected World
THE SOA NETWORK SOA Verticals
SOA Governance | SOA Management | SOA Networking | SOA Security | SOA Identity | SOA Test
SOA Finance | SOA Government | SOA Healthcare | SOA Insurance | SOA Manufacturing | SOA Retail | SOA Telecom | SOA Utilities







Comments