Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.

Tag Archives: application security

Insider Threat – Not Knowing That You Don’t Know What You Don’t Know

– In my column “All the Way from RSA,” posted on April 5, 2010, I refer to the article “France Got Stolen HSBC Data” by Deborah Ball and David Gauthier-Villars in the Money and Investing section of The Wall Street Journal published on March 12, 2010. Not only does this appear to be a case…

Application Security – Where It’s At

– Some time ago, I was planning to write about my participation last year in a conference and a workshop on application security and software assurance respectively. One was the annual OWASP (Open Web Application Security Project) Conference in New York and the other was a workshop on the business…

Bill Gates, Facebook and Privacy Controls

– While in India this week, Bill Gates made the following comment: He admitted that he once had a Facebook page, but every day “ten thousand people tried to be my friend.” He said he spent too much time trying to decide “Do I know them? Don’t I know them?” Ultimately, he said, “I had to…

BSIMM – Top Ten Surprises

– In a prior column, I described the results of a survey conducted by Gary McGraw, Sammy Migues and Brian Chess published in the BSIMM (Build Security In Maturity Model) report available at http://bsi-mm.com/   Most of the results are intuitively obvious … after the fact, that is. But some…

BSIMM – A Giant Step for Application Security

– There’s a new acronym in town – BSIMM. It’s not BSIMM the rapper out of Louisville, Kentucky. But it is BSI-MM, which is how it is depicted in the website from which you can download the 50-page report, namely http://bsi-mm.com/ The BSIMM in question stands for “Building…