1 / 396
文档名称:

Software Security- building security in.pdf

格式:pdf   页数:396
下载后只包含 1 个 PDF 格式的文档,没有任何的图纸或源代码,查看文件列表

如果您已付费下载过本站文档,您可以点这里二次下载

Software Security- building security in.pdf

上传人:bolee65 2014/7/18 文件大小:0 KB

下载得到文件列表

Software Security- building security in.pdf

文档介绍

文档介绍:1
Dedication
To my grandmother Ruth McGraw, who lives life to the fullest.

















2
Advance Praise for Software Security
"I have been involved with trying to solve security problems for over twenty years—
starting with individual desktop systems and transitioning work security as that
became the prevalent issue. I have been an entrepreneur, executive in the industry, and
am now an investor pany builder, all focused on trying to solve these important
issues. What I have learned over these twenty years is that we have done an okay job at
slowing down the problem, but we are no closer to solving the problem than we were
when we started.
"Our twenty years of investment has been spent being reactive—trying to 'keep the bad
guys out.' The idea has been to build a wall around panies so high and so thick
that no one with nefarious intentions could get in. In today's world this just does not
work. We live in a wall-less economy panies need to allow freedom of
communication in and out of their enterprises. Freedom of information access and
freedom of application usage are central drivers for petitive. In other words,
the battlefield has changed. Thus the weapons and tactics we use to secure our assets
must change as well.
"The only way I see the security conundrum getting solved is by confronting the problem
and not the symptoms of the problem. We need to design and build security in from the
beginning. No application, no operating system, no piece of middleware should ever be
released that has not already been designed for security and reviewed for security
vulnerabilities. Only then will we start to fight these new battles with the correct weapons
and tactics that afford us the chance to win.
"I believe so fervently in these concepts that I founded pany called Fortify Software
to develop, market, and sell solutions to attack and solve these issues directly. W