Software Security: Building Security In

3,66 valoración promedio
( 56 valoraciones por Goodreads )
 
9780321356703: Software Security: Building Security In

 "When it comes to software security, the devil is in the details. This book tackles the details."
--Bruce Schneier, CTO and founder, Counterpane, and author of Beyond Fear and Secrets and Lies

 

"McGraw's book shows you how to make the 'culture of security' part of your development lifecycle."
--Howard A. Schmidt, Former White House Cyber Security Advisor

 

"McGraw is leading the charge in software security. His advice is as straightforward as it is actionable. If your business relies on software (and whose doesn't), buy this book and post it up on the lunchroom wall."
--Avi Rubin, Director of the NSF ACCURATE Center; Professor, Johns Hopkins University; and coauthor of Firewalls and Internet Security

 

Beginning where the best-selling book Building Secure Software left off, Software Security teaches you how to put software security into practice.The software security best practices, or touchpoints, described in this book have their basis in good software engineering and involve explicitly pondering security throughout the software development lifecycle. This means knowing and understanding common risks (including implementation bugsand architectural flaws), designing for security, and subjecting all software artifacts to thorough, objective risk analyses and testing.

 

Software Security is about putting the touchpoints to work for you. Because you can apply these touchpoints to the software artifacts you already produce as you develop software, you can adopt this book's methods without radically changing the way you work. Inside you'll find detailed explanations of

  • Risk management frameworks and processes
  • Code review using static analysis tools
  • Architectural risk analysis
  • Penetration testing
  • Security testing
  • Abuse case development

In addition to the touchpoints, Software Security covers knowledge management, training and awareness, and enterprise-level software security programs. Now that the world agrees that software security is central to computer security, it is time to put philosophy into practice. Create your own secure development lifecycle by enhancing your existing software development lifecycle with the touchpoints described in this book. Let this expert author show you how to build more secure software by building security in.

"Sinopsis" puede pertenecer a otra edición de este libro.

From the Back Cover:

This is the Mobipocket version of the print book. ""When it comes to software security, the devil is in the details. This book tackles the details." "
--Bruce Schneier, CTO and founder, Counterpane, and author of "Beyond Fear" and "Secrets and Lies" ""McGraw's book shows you how to make the 'culture of security' part of your development lifecycle.""
--Howard A. Schmidt, Former White House Cyber Security Advisor ""McGraw is leading the charge in software security. His advice is as straightforward as it is actionable. If your business relies on software (and whose doesn't), buy this book and post it up on the lunchroom wall.""
--Avi Rubin, Director of the NSF ACCURATE Center; Professor, Johns Hopkins University; and coauthor of "Firewalls and Internet Security" Beginning where the best-selling book "Building Secure Software" left off, "Software Security" teaches you how to put software security into practice.The software security best practices, or touchpoints, described in this book have their basis in good software engineering and involve explicitly pondering security throughout the software development lifecycle. This means knowing and understanding common risks (including implementation bugsand architectural flaws), designing for security, and subjecting all software artifacts to thorough, objective risk analyses and testing. "Software Security" is about putting the touchpoints to work for you. Because you can apply these touchpoints to the software artifacts you already produce as you develop software, you can adopt this book's methods without radically changing the way you work. Inside you'll find detailed explanations of

  • Risk management frameworks and processes
  • Code review using static analysis tools
  • Architectural risk analysis
  • Penetration testing
  • Security testing
  • Abuse case development
In addition to the touchpoints, "Software Security" covers knowledge management, training and awareness, and enterprise-level software security programs. Now that the world agrees that software security is central to computer security, it is time to put philosophy into practice. Create your own secure development lifecycle by enhancing your existing software development lifecycle with the touchpoints described in this book. Let this expert author show you how to build more secure software by building security in.

About the Author:

Gary McGraw, Cigital, Inc.'s CTO, is a world authority on software security. Dr. McGraw is coauthor of five best selling books: Exploiting Software (Addison-Wesley, 2004), Building Secure Software (Addison-Wesley, 2001), Software Fault Injection (Wiley 1998), Securing Java (Wiley, 1999), and Java Security (Wiley, 1996). His new book, Software Security: Building Security In (Addison-Wesley 2006) was released in February 2006. As a consultant, Dr. McGraw provides strategic advice to major software producers and consumers. Dr. McGraw has written over ninety peer-reviewed technical publications and functions as principal investigator on grants from DARPA, National Science Foundation, and NIST's Advanced Technology Program. He serves on Advisory Boards of Authentica, Counterpane, and Fortify Software, as well as advising the CS Department at UC Davis, the CS Department at UVa, and the School of Informatics at Indiana University. Dr. McGraw holds a dual PhD in Cognitive Science and Computer Science from Indiana University and a BA in Philosophy from UVa. He is a member of the IEEE Security and Privacy Task Force, and was recently elected to the IEEE Computer Society Board of Governors. He is the producer of the Silver Bullet Security Podcast for IEEE Security & Privacy magazine, writes a monthly column for darkreading.com, and is often quoted in the press.

"Sobre este título" puede pertenecer a otra edición de este libro.

Los mejores resultados en AbeBooks

1.

McGraw, Gary
Editorial: Addison-Wesley Professional (2006)
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Paperback Cantidad: 1
Librería
TEXTBOOKNOOK
(Knoxville, TN, Estados Unidos de America)
Valoración
[?]

Descripción Addison-Wesley Professional, 2006. Paperback. Estado de conservación: New. Brand New Text!!! Never Been Used!!! This text is totally clean with no writing at all!!! Includes Unopened Cd!!!. Nº de ref. de la librería 106519

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 34,77
Convertir moneda

Añadir al carrito

Gastos de envío: EUR 2,57
A Estados Unidos de America
Destinos, gastos y plazos de envío

2.

Gary McGraw
Editorial: Addison-Wesley Professional (2006)
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Paperback Cantidad: 1
Librería
Ergodebooks
(RICHMOND, TX, Estados Unidos de America)
Valoración
[?]

Descripción Addison-Wesley Professional, 2006. Paperback. Estado de conservación: New. Nº de ref. de la librería SONG0321356705

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 36,09
Convertir moneda

Añadir al carrito

Gastos de envío: EUR 3,42
A Estados Unidos de America
Destinos, gastos y plazos de envío

3.

McGraw, Gary
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Paperback Cantidad: 2
Librería
BargainBookStores
(Grand Rapids, MI, Estados Unidos de America)
Valoración
[?]

Descripción Paperback. Estado de conservación: New. Nº de ref. de la librería 1487300

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 37,64
Convertir moneda

Añadir al carrito

Gastos de envío: EUR 3,42
A Estados Unidos de America
Destinos, gastos y plazos de envío

4.

McGraw, Gary
Editorial: Prentice Hall
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Cantidad: > 20
Librería
INDOO
(Avenel, NJ, Estados Unidos de America)
Valoración
[?]

Descripción Prentice Hall. Estado de conservación: New. Brand New. Nº de ref. de la librería 0321356705

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 41,17
Convertir moneda

Añadir al carrito

Gastos de envío: EUR 3,00
A Estados Unidos de America
Destinos, gastos y plazos de envío

5.

Gary R. McGraw
Editorial: Pearson Education (US), United States (2006)
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Cantidad: 10
Librería
The Book Depository US
(London, Reino Unido)
Valoración
[?]

Descripción Pearson Education (US), United States, 2006. Mixed media product. Estado de conservación: New. Language: English . Brand New Book. When it comes to software security, the devil is in the details. This book tackles the details. --Bruce Schneier, CTO and founder, Counterpane, and author of Beyond Fear and Secrets and Lies McGraw s book shows you how to make the culture of security part of your development lifecycle. --Howard A. Schmidt, Former White House Cyber Security Advisor McGraw is leading the charge in software security. His advice is as straightforward as it is actionable. If your business relies on software (and whose doesn t), buy this book and post it up on the lunchroom wall. --Avi Rubin, Director of the NSF ACCURATE Center; Professor, Johns Hopkins University; and coauthor of Firewalls and Internet Security Beginning where the best-selling book Building Secure Software left off, Software Security teaches you how to put software security into practice.The software security best practices, or touchpoints, described in this book have their basis in good software engineering and involve explicitly pondering security throughout the software development lifecycle.This means knowing and understanding common risks (including implementation bugsand architectural flaws), designing for security, and subjecting all software artifacts to thorough, objective risk analyses and testing. Software Security is about putting the touchpoints to work for you. Because you can apply these touchpoints to the software artifacts you already produce as you develop software, you can adopt this book s methods without radically changing the way you work. Inside you ll find detailed explanations of * Risk management frameworks and processes * Code review using static analysis tools * Architectural risk analysis * Penetration testing * Security testing * Abuse case development In addition to the touchpoints, Software Security covers knowledge management, training and awareness, and enterprise-level software security programs. Now that the world agrees that software security is central to computer security, it is time to put philosophy into practice. Create your own secure development lifecycle by enhancing your existing software development lifecycle with the touchpoints described in this book.Let this expert author show you how to build more secure software by building security in. Nº de ref. de la librería AAK9780321356703

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 45,25
Convertir moneda

Añadir al carrito

Gastos de envío: GRATIS
De Reino Unido a Estados Unidos de America
Destinos, gastos y plazos de envío

6.

McGraw, Gary
Editorial: Addison-Wesley Professional
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Cantidad: 1
Librería
Ohmsoft LLC
(Lake Forest, IL, Estados Unidos de America)
Valoración
[?]

Descripción Addison-Wesley Professional. Estado de conservación: Brand New. Ships from USA. FREE domestic shipping. Nº de ref. de la librería 0321356705

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 48,75
Convertir moneda

Añadir al carrito

Gastos de envío: GRATIS
A Estados Unidos de America
Destinos, gastos y plazos de envío

7.

Gary R. McGraw
Editorial: Pearson Education (US), United States (2006)
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Cantidad: 10
Librería
The Book Depository
(London, Reino Unido)
Valoración
[?]

Descripción Pearson Education (US), United States, 2006. Mixed media product. Estado de conservación: New. Language: English . Brand New Book. When it comes to software security, the devil is in the details. This book tackles the details. --Bruce Schneier, CTO and founder, Counterpane, and author of Beyond Fear and Secrets and Lies McGraw s book shows you how to make the culture of security part of your development lifecycle. --Howard A. Schmidt, Former White House Cyber Security Advisor McGraw is leading the charge in software security. His advice is as straightforward as it is actionable. If your business relies on software (and whose doesn t), buy this book and post it up on the lunchroom wall. --Avi Rubin, Director of the NSF ACCURATE Center; Professor, Johns Hopkins University; and coauthor of Firewalls and Internet Security Beginning where the best-selling book Building Secure Software left off, Software Security teaches you how to put software security into practice.The software security best practices, or touchpoints, described in this book have their basis in good software engineering and involve explicitly pondering security throughout the software development lifecycle.This means knowing and understanding common risks (including implementation bugsand architectural flaws), designing for security, and subjecting all software artifacts to thorough, objective risk analyses and testing. Software Security is about putting the touchpoints to work for you. Because you can apply these touchpoints to the software artifacts you already produce as you develop software, you can adopt this book s methods without radically changing the way you work. Inside you ll find detailed explanations of * Risk management frameworks and processes * Code review using static analysis tools * Architectural risk analysis * Penetration testing * Security testing * Abuse case development In addition to the touchpoints, Software Security covers knowledge management, training and awareness, and enterprise-level software security programs. Now that the world agrees that software security is central to computer security, it is time to put philosophy into practice. Create your own secure development lifecycle by enhancing your existing software development lifecycle with the touchpoints described in this book.Let this expert author show you how to build more secure software by building security in. Nº de ref. de la librería AAK9780321356703

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 49,38
Convertir moneda

Añadir al carrito

Gastos de envío: GRATIS
De Reino Unido a Estados Unidos de America
Destinos, gastos y plazos de envío

8.

McGraw, Gary
Editorial: Addison-Wesley Professional (2006)
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Paperback Cantidad: 2
Librería
Murray Media
(North Miami Beach, FL, Estados Unidos de America)
Valoración
[?]

Descripción Addison-Wesley Professional, 2006. Paperback. Estado de conservación: New. Nº de ref. de la librería P110321356705

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 50,84
Convertir moneda

Añadir al carrito

Gastos de envío: EUR 2,56
A Estados Unidos de America
Destinos, gastos y plazos de envío

9.

Gary McGraw
Editorial: Addison-Wesley Professional (2006)
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Paperback Cantidad: 1
Librería
Ergodebooks
(RICHMOND, TX, Estados Unidos de America)
Valoración
[?]

Descripción Addison-Wesley Professional, 2006. Paperback. Estado de conservación: New. PAP/CDR. Nº de ref. de la librería DADAX0321356705

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 51,04
Convertir moneda

Añadir al carrito

Gastos de envío: EUR 3,42
A Estados Unidos de America
Destinos, gastos y plazos de envío

10.

Gary McGraw
ISBN 10: 0321356705 ISBN 13: 9780321356703
Nuevos Paperback Cantidad: 1
Librería
Grand Eagle Retail
(Wilmington, DE, Estados Unidos de America)
Valoración
[?]

Descripción Paperback. Estado de conservación: New. 1. Paperback. When it comes to software security, the devil is in the details. This book tackles the details. --Bruce Schneier, CTO and founder, Counterpane, and author of Beyond Fear and Secrets and L.Shipping may be from multiple locations in the US or from the UK, depending on stock availability. 448 pages. 0.871. Nº de ref. de la librería 9780321356703

Más información sobre esta librería | Hacer una pregunta a la librería

Comprar nuevo
EUR 54,58
Convertir moneda

Añadir al carrito

Gastos de envío: GRATIS
A Estados Unidos de America
Destinos, gastos y plazos de envío

Existen otras copia(s) de este libro

Ver todos los resultados de su búsqueda