<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: cigitals]]></title>
    <link>http://securityratty.com/tag/cigitals</link>
    <description></description>
    <pubDate>Fri, 21 Dec 2007 17:40:32 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Show 026 - An Interview with Adam Shostack]]></title>
      <link>http://securityratty.com/article/c33fabcf5dc8851811ed58bff76a27ea</link>
      <guid>http://securityratty.com/article/c33fabcf5dc8851811ed58bff76a27ea</guid>
      <description><![CDATA[The 26th episode of The Silver Bullet Security Podcast features Adam Shostack, a security expert on Microsofts Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective....]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Adam Shostack" title="Adam Shostack" src="http://www.cigital.com/silverbullet/ashostack-125.gif" style="padding-left: 7px;" /></p>
<p>The 26th episode of <em>The Silver Bullet Security Podcast</em> features Adam Shostack, a security expert on Microsoft&#8217;s Secure Development Lifecycle team who has also worked for Zero Knowledge and Reflective.  Gary and Adam discuss how Adam got started in computer security, how art/literature informs Adam’s current work, and the main ideas behind Adam’s new book <em>The New School of Information Security</em>.  They go on to chat about Adam&#8217;s aversion to the term &#8220;best practices,&#8221; the role IEEE Security &#038; Privacy magazine plays in bringing the science of security to a practical level, and whether the biggest problem of the CardSystems breach was the following the letter, rather than the spirit, of PCI.  Also on the agenda, duck-billed platypuses, Kandinski, and books by Pynchon.</p>
<p>(Beginning with this episode, Silver Bullet will be available as a 192k MP3.)</p>
<ul>
<li><a href="http://www.emergentchaos.com/">Emergent Chaos blog</a></li>
<li><a href="http://www.amazon.com/New-School-Information-Security/dp/0321502787/"><em>The New School of Information Security</em></a></li>
<li><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx">Microsoft&#8217;s SDL</a></li>
<li><a href="http://www.cigital.com/justiceleague/category/software-security-touchpoints/">Cigital’s Touchpoints</a></li>
<li><a href="http://www.computer.org/portal/site/security"><em>IEEE Security &#038; Privacy magazine</em></a></li>
<li><a href="http://en.wikipedia.org/wiki/Wassily_Kandinsky">Wassily Kandinsky</a></li>
<li><a href="http://money.cnn.com/2005/06/17/news/master_card/index.htm">The CardSystems breach</a> (2005)</li>
<li><a href="http://en.wikipedia.org/wiki/Thomas_Pynchon">Thomas Pynchon</a>
</ul>
]]></content:encoded>
      <pubDate>Thu, 15 May 2008 15:17:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/role ieee security">role ieee security</category>
      <category domain="http://securityratty.com/tag/ieee security">ieee security</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/adam">adam</category>
      <category domain="http://securityratty.com/tag/privacy magazine">privacy magazine</category>
      <category domain="http://securityratty.com/tag/privacy magazine plays">privacy magazine plays</category>
      <source url="http://www.cigital.com/silverbullet/show-026/">Show 026 - An Interview with Adam Shostack</source>
    </item>
    <item>
      <title><![CDATA[Show 021 - A Panel Discussion with Cigitals Principals]]></title>
      <link>http://securityratty.com/article/39c02aba5b4d96ce317267dc5d12bb81</link>
      <guid>http://securityratty.com/article/39c02aba5b4d96ce317267dc5d12bb81</guid>
      <description><![CDATA[For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigitals principals. Participants include Sammy Migues (Director of Training and Knowledge Management),...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Cigital Logo" title="Cigital Logo" src="http://www.cigital.com/silverbullet/cigital-125.gif" /></p>
<p style="margin-top: 5px">For the 21st episode of The Silver Bullet Security Podcast, Gary hosts a panel discussion with Cigital&#8217;s principals.  Participants include Sammy Migues (Director of Training and Knowledge Management), John Steven (Principal Consultant) and Pravir Chandra (Principal Consultant).  The group discusses the best ways for large companies to get started with software security and the similarities between CLASP, Microsoft&#8217;s SDL, and the Security Touchpoints.  They also ponder how much the security testing burden should fall on QA and whether developing expertise in architectural risk analysis or threat modeling is more helpful.  John Steven also discusses the hole in his dining room, which threat modeling would not have helped to prevent.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-021-cigital.pdf">Transcript of this episode</a> [PDF]</li>
<li><a href="http://www.cigital.com/justiceleague/">Justice League blog</a></li>
<li><a href="http://www.cigital.com/justiceleague/2007/11/13/threat-modeling/">Threat Modeling</a> - a blog entry by John Steven</li>
<li><a href="http://www.owasp.org/index.php/Top_10_2007">OWASP Top 10 for 2007</a></li>
<li><a href="http://www.owasp.org/">OWASP</a></li>
<li><a href="http://www.shmoo.com/">The Shmoo Group</a></li>
</ul>
]]></content:encoded>
      <pubDate>Fri, 21 Dec 2007 17:40:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/principal consultant">principal consultant</category>
      <category domain="http://securityratty.com/tag/cigitals principals">cigitals principals</category>
      <category domain="http://securityratty.com/tag/panel discussion">panel discussion</category>
      <category domain="http://securityratty.com/tag/security touchpoints">security touchpoints</category>
      <category domain="http://securityratty.com/tag/owasp top">owasp top</category>
      <category domain="http://securityratty.com/tag/owasp">owasp</category>
      <category domain="http://securityratty.com/tag/justice league blog">justice league blog</category>
      <source url="http://www.cigital.com/silverbullet/show-021/">Show 021 - A Panel Discussion with Cigitals Principals</source>
    </item>
  </channel>
</rss>
