Archive for July, 2009

Episode 37 – Securing Web Applications: Improving the Application Development Life Cycle

Tuesday, July 28th, 2009

BigFix CTO Amrit Williams and White Hat Security CTO Jeremiah Grossman conclude their discussion on web application security by looking at ways organizations can build in security features and resistance to attack over the life cycles of in-house developed web applications. While design-for-security should start in the initial spec and coding processes, security mindedness needs to continue throughout an application’s life cycle as the application evolves to meet changing technical and business requirements.

Podcast

  • Share/Bookmark

Episode 36 – Securing Web Applications: Instituting Operational Controls

Friday, July 24th, 2009

BigFix CTO Amrit Williams and White Hat Security CTO Jeremiah Grossman continue their discussion on web application security by looking at what kinds of operational controls organizations can institute to enable more effective management and protection of web applications over their life cycles. As many web applications are in-house efforts, this often requires organizations to make decisions and enforce policies that would otherwise be the domain of third-party application vendors.

Podcast

  • Share/Bookmark

Episode 35 – Securing Web Applications: Surveying the Threat Landscape

Tuesday, July 21st, 2009

Amrit Williams, BigFix CTO begins a three-part discussion with Jeremiah Grossman, CTO of White Hat Security on web application security. In the first part, Amrit and Jeremiah review the nature, severity, and spread of threats to the security and integrity of web applications. Web applications differ from commercial applications and system software as the majority of them are developed in-house. Not only are there no external resources to provide patches, updates and vulnerability fixes, web applications may not be fully documented or designed for easy updating.

Podcast

  • Share/Bookmark

Episode 34 – Cybsersecurity, Cyberdefense and Cyberwarfare: Part III

Tuesday, July 14th, 2009

Part III of the conversation with Amrit Williams, Michael Smith and Dan Philpott moves on to look at private sector adoption of government-developed IT security standards and policies, a field guide to current NIST FISMA documents, and which private organizations—mostly government contractors–must comply with government security standards. The discussion concludes on increasing government IT security spending and how the government will spend it. In particular, will the new spending emphasize tools and capital goods and relatively neglect developing human expertise in the field.

Podcast

  • Share/Bookmark

Episode 33 – Cybsersecurity, Cyberdefense and Cyberwarfare: Part II

Friday, July 10th, 2009

Part II of this discussion involving Amrit Williams, Michael Smith and Dan Philpott focuses on recent policy developments in the US, in particular legislation currently in the US Congress to modify or replace the Federal Information Security Management Act with new laws, whether the establishment of a US Military Cyber Command is a military necessity or a maneuver to attract funding, and whether the intense effort to legislate and regulate represents an effort to compensate for a shortage of human cybersecurity expertise.

Podcast

  • Share/Bookmark

Episode 32 – Cybsersecurity, Cyberdefense and Cyberwarfare: Part I

Tuesday, July 7th, 2009

Begins a three part discussion with Michael Smith, self-described Guerilla CISO and Dan Philpott, the instigator of the www.fismapedia.org wiki site on latest thinking on the rapidly developing fields of cyberdefense and cyberwarefare. Planners, policy makers and practitioners face multi-faceted dilemmas in this field. Key topics include the relationship of government and civilian organizations, the blurred line between warlike and criminal attacks on cyber assets, the questions whether cyberwarfare includes “kinetic” attacks on enemy cyber assets, the collateral necessity of using neutral nation IT infrastructure as a channel for cyberwarfare actions among many other issues.

Podcast

  • Share/Bookmark