03/29/2012 |
Application Security
The Application Security track at the IANS 2012 Mid-Atlantic Information Security Forum was designed to walk delegates through a growing problem: Poor application development leads to security threats. More mature security organizations are starting to realize that they need to work with development teams to ensure that security is baked into the process, not added as an
02/10/2012 |
Application Security
IANS Faculty Diana Kelley and Ed Moyle share a preview of what delegates can expect to experience during the application security track at IANS' upcoming Information Security Forums.
02/06/2012 |
Application Security
Businesses spend a generous portion of their budgets on applications, in general. Tools like financial applications and CRM applications get installed into and used in the business environment every day. These applications are central to running a business, yet historically application security hasn’t been at the top of the stack for IT security funding. A vulnerability in any one
07/13/2011 |
Application & Code Testing
"It’s a national security imperative in a global economy that we have confidence in the supply chains of integrated systems and the integrity of the people, processes, and technology that comprise them." - Hart Rossman
“In the digital age, sovereignty is demarcated not by territorial frontiers but by supply chains.” – Dan Geer, CISO In-Q-Tel
Highlighting leading research from a
05/02/2011 |
Application Security
IANS’ research is generated through a unique interactionbased approach. Our belief is that the best knowledge about industry trends, best practices, and critical issues resides with the true experts: practicing information security professionals.
04/21/2011 |
Security Development Life-Cycle
Whether through SaaS, PaaS or IaaS, the Cloud is probably paying your enterprise a visit. This is both a challenge and an opportunity for Information Security teams. How should Information Security
position its architecture and processes to deal with the Cloud?
In this talk we will explore four concrete patterns that you can use to embrace the challenge of leveraging the Cloud'
11/01/2010 |
Application Security
IANS Faculty member Ron Ritchey shared IANS’ perspective on application security and threat modeling. He led participants in an interactive discussion of how they are developing secure code, securing applications, and getting management support for application security.
10/01/2010 |
Application Security
Organizations are rushing to move business applications to the cloud based on perceived costs savings, flexibility, scalability, and other advantages. Some people see the situation as analogous to any other outsourcing situation. But, the cloud has some important differences versus other traditional outsourcing situations in regard to compliance, the outsourcing model, and the
09/01/2010 |
Application Security
IANS Faculty member Ron Ritchey shared IANS’ perspective on identifying high risk applications and led an interactive discussion of this topic. Ed Adams, the CEO of Security Innovation, provided a brief overview of the company’s application security solutions.
05/20/2010 |
Security Development Life-Cycle
Developing secure software, particularly web applications, is a formidable task. Historically developers have been focused on features and speed—not security. Incorporating security into the development lifecycle requires a change in behaviors and skills, and requires a new set of tools.
Organizations such as Fleishman-Hillard show that it is possible to orchestrate changes in
