Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Application Security resources

Status
Not open for further replies.

hilfy

Active member
Oct 31, 2003
2,564
US
I'm looking at the possibility of moving into a new job with my current employer - probably sometime next year. Currently I'm a software engineer/project manager for a financial services and insurance company. The job that I want to move into will involve working with all branches of the company to ensure that software we create meets the security requirements our clients expect.

Does anyone have and good resources about sofware security? I'm not talking about language specifics, but more about the overall process of securing software and data. I know that as a service provider to banks that we fall under Sarbanes-Oxley. We also have to have SAS 70 audits (so far just Level I, but we've got a Level II scheduled for next year). Where can I find good "plain English" information about these requirements as well and other industry standards type of info?

Thanks!
-Dell

A computer only does what you actually told it to do - not what you thought you told it to do.
 
Good application security typically isn't something that you can ensure by following a checklist or list of requirements. It requires people who are able to think like an attacker and break the rules in order to expose weaknesses in a system.

Usually, those people don't get along too well in a structured environment, so they're often employed as consultants or contractors. I would try and find a consultant who can mentor you.

Chip H.


____________________________________________________________________
If you want to get the best response to a question, please read FAQ222-2244 first
 
May I point you at thread1393-1040784 in my own forum (Forum1393)?

Discussion therein about security and penetration testing.

Cheers,
Dave

Probably the only Test Analyst Manager on Tek-Tips...therefore whatever it was that went wrong, I'm to blame...

animadverto vos in Abyssus!

Take a look at Forum1393!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top