Software Security

Resources

Build Security In Web Site

The Addison-Wesley Software Security Series, Gary McGraw contributing editor

Software Security by Gary McGraw

Specific Articles from the Building Security In Website mentioned in the book

Deployment & Operations content area

Attack Patterns content area

Assurance Cases content area

Coding Practices content area

Coding Rules content area

Guidelines content area

Code Analysis content area

Runtime Protection

Risk Management content area

Requirements Elicitation Case Studies

Requirements Prioritization Case Study Using AHP

Introduction to the CLASP Process

The Common Criteria

Using Integer Programming to Optimize Investments in Security Countermeasures

Architectural Risk Analysis content area

Architectural Risk Analysis

Principles content area

Business Case

Code Analysis

Coding Practices

Risk-Based and Functional Security Testing

White Box Testing

Black Box Security Testing Tools

Adapting Penetration Testing for Software Development Purposes

Penetration Testing Tools

Building Security In IEEE Security & Privacy Series

Identity in Assembly and Integration

Application Firewalls and Proxies—Introduction and Concept of Operations

Correctness by Construction

Assessing Security Risk in Legacy Systems

Security Considerations in Managing COTS Software

Security Is Not Just a Technical Issue

Risk Management Framework

Risk-Centered Practices

Security and Project Management

The Influence of System Properties on Software Assurance and Project Management

Prioritizing IT Controls for Effective, Measurable Security

Measures and Measurement for Secure Software Development

Plan, Do, Check, Act

Maturity of Practice and Exemplars

Adopting a Software Security Improvement Program

Bridging the Gap Between Software Development and Information Security

Misuse and Abuse Cases: Getting Past the Positive

Adopting an Enterprise Software Security Framework

Making the Business Case for Software Assurance

Secure Software Development Life Cycle Processes

Additional Resources—DHS SwA WG Output

Risk Management Framework Glossary