<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebProNews &#187; NIST</title>
	<atom:link href="http://www.webpronews.com/tag/nist/feed" rel="self" type="application/rss+xml" />
	<link>http://www.webpronews.com</link>
	<description>Breaking News in Tech, Search, Social, &#38; Business</description>
	<lastBuildDate>Sun, 12 Feb 2012 22:29:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Government Agencies Ban Windows Vista</title>
		<link>http://www.webpronews.com/government-agencies-ban-windows-vista-2007-03</link>
		<comments>http://www.webpronews.com/government-agencies-ban-windows-vista-2007-03#comments</comments>
		<pubDate>Wed, 14 Mar 2007 22:09:14 +0000</pubDate>
		<dc:creator>Joe Lewis</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Administration]]></category>
		<category><![CDATA[ban]]></category>
		<category><![CDATA[DOT]]></category>
		<category><![CDATA[FAA]]></category>
		<category><![CDATA[Federal]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[ONE]]></category>
		<category><![CDATA[Vista]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=36139</guid>
		<description><![CDATA[<p>In the past, large organizations have been reluctant to switch over to a new Microsoft operating system due to factors of cost, new training, and the possibility unknown bugs still lurking about in the software. In this case, however, reluctance has given way to outright refusal.<br />
]]></description>
			<content:encoded><![CDATA[<p>In the past, large organizations have been reluctant to switch over to a new Microsoft operating system due to factors of cost, new training, and the possibility unknown bugs still lurking about in the software. In this case, however, reluctance has given way to outright refusal.</p>
<p>It&rsquo;s not exactly been a banner year for the Windows brand. Microsoft released Vista in early 2007 only to be met with a lukewarm reception from both the enterprise and personal computing markets. Dell is also ramping up efforts to offer a Linux alternative to Windows for customers purchasing new computers from the store.</p>
<p>It&rsquo;s not just the private sector, however, that is displaying hesitancy to upgrade to Windows Vista. Government agencies such as the <a href="http://www.faa.gov">Federal Aviation Administration</a> have publicly acknowledged the fact that finding alternatives to Microsoft products, such as Linux-based operating systems and Google&rsquo;s Premier Apps office suite, is becoming a higher <a href="http://www.webpronews.com/topnews/2007/03/09/faa-ponders-switch-to-linux-premier-apps">priority</a>.</p>
<p>The FAAs efforts in this regard seemed to have worked their way up the pipeline, as now the Department of Transportation, the entity under which the FAA is affiliated, has officially prohibiting upgrades to Windows Vista, as is the National Institute of Standards and Technology.</p>
<p>Here&rsquo;s an excerpt from a January <a href="http://www.dot.gov/ost/m60/morat001.pdf">DOT memo</a> documenting the rational behind such a decision:
</p>
<blockquote><p><em>Based on our initial analysis (from internal recommendations and analysis provided by Gartner Group), there appears to be no compelling technical or business case for upgrading to these new Microsoft products. Furthermore, there appears to be specific reasons not to upgrade including:</em></p>
<p><em>&middot;&nbsp;&nbsp;&nbsp; The cost of performing the upgrade (hardware/software upgrades, application upgrades, labor for planning and implementation, etc.)</em></p>
<p><em>&middot;&nbsp;&nbsp;&nbsp; Previous version compatibility concerns regarding Office 2007 suite components (primarily Word)</em></p>
<p><em>&middot;&nbsp;&nbsp;&nbsp; The protracted FY07 Continuing Resolution (CR) which limits available funding</em></p>
<p><em>&middot;&nbsp;&nbsp;&nbsp; The more to the new Headquarters DOT building that would be competing with the same IT expertise required to support the migration to any of these products</em></p></blockquote>
<p>
So, not only are these government agencies effectively banning the implementation of Windows Vista, but they are also preventing users from upgrading to the latest versions of Microsoft Office and Internet Explorer, a move that the top brass in Redmond can&rsquo;t be too thrilled about.</p>
<p>&nbsp;</p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/government-agencies-ban-windows-vista-2007-03/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The Software Development Life Cycle:  When to Secure Your Process</title>
		<link>http://www.webpronews.com/the-software-development-life-cycle-when-to-secure-your-process-2006-05</link>
		<comments>http://www.webpronews.com/the-software-development-life-cycle-when-to-secure-your-process-2006-05#comments</comments>
		<pubDate>Thu, 04 May 2006 15:41:56 +0000</pubDate>
		<dc:creator>Caleb Sima and Kevin Beaver</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=28991</guid>
		<description><![CDATA[When it comes to software security, the general perception is that including technologies such as firewalls, intrusion prevention systems, and malware protection throughout the software development life cycle is all that's needed to keep information secure in the end product.
]]></description>
			<content:encoded><![CDATA[<p>When it comes to software security, the general perception is that including technologies such as firewalls, intrusion prevention systems, and malware protection throughout the software development life cycle is all that&#8217;s needed to keep information secure in the end product.</p>
<p>However, these technologies are mostly reactive in nature and don&#8217;t prevent the vulnerabilities in the first place. Also, at the development level, there&#8217;s a lot of talk about testing for buffer overruns, validating user input, using the principle of least privilege, and so on. These are certainly solid practices, but there&#8217;s still a considerable gap when it comes to getting to the root of software flaws &#8211; the development process itself. </p>
<p>Web application security is extremely complex and constantly changing and there&#8217;s more to it than just technical controls. Whether it&#8217;s commercial or in-house, any type of code from firmware to client-server programs to Web applications can benefit from a solid and proven development process. A solid development process throughout the software development life cycle will not only ensure proper expectations are set within the team, help reduce development time, and improve quality, but it can also help make major software security improvements along the way. This all may seem too idealistic, but it can be done. As a result, both in the short term and the long run, software security flaws can be drastically reduced and organizations can lower their dependence on technical safeguards working reactively to cover up the true problem.</p>
<p>There are six common weaknesses in the software development life cycle that lead to vulnerable code, and inevitably, security exploits.</p>
<p><b>1.  Not understanding the long-term consequences of a weak security process </b></p>
<p>Certain software security flaws may not be quite so obvious. It may take several software revisions before they&#8217;re discovered. Other software security flaws may not show up for years. Regardless, they&#8217;re still being baked in which create long-term problems. Much of this can be traced back to weak security processes throughout the software development life cycle, such as not performing threat modeling, not establishing and following software security standards, and using the proper testing tools to uncover software security weaknesses.</p>
<p><b>2. Business goals conflict with security during each phase </b></p>
<p>Regardless of what anyone in development, product management, or marketing says, there&#8217;s still less focus on software security and more focus on delivering feature-rich applications that can deliver as close to everything-to-everyone as possible. Throughout the software development life cycle &#8211; from planning to ongoing maintenance &#8211; time is of the essence in each phase. Time to market drives the majority of projects, and quite often during time crunches, security oversight occurs, sloppiness ensues, and otherwise solid code is placed on the &#8220;back burner&#8221; to be fixed later.</p>
<p><b>3. Viewing security requirements in the wrong context </b></p>
<p>Product managers, developers, and customers alike are not always aware of the actual and potential software security issues during the software development life cycle. This often leads to the &#8220;we have/require a layered defense &#8211; a firewall, user authentication, and file access controls &#8211; what more do we need&#8221; mentality. Software security goes way beyond these reactive controls. Like the architectural and environmental intricacies associated with a land developer planning a new neighborhood, security vulnerabilities must be understood and controls must be made part of the software during the initial requirements phase of the software development life cycle. Likewise, similar to the foundation and framing of a house, if software security is not integrated up front in the design &#8220;blueprints&#8221; of the software, it can be very difficult and expensive to go back and make changes once the building begins.</p>
<p><b>4.  Not developing with security in mind </b></p>
<p>Once requirements are established and projects are in full swing, it&#8217;s common for developers to get back to what they know and do best (writing code) and not focusing on software security throughout the software development life cycle. Quite often, the only focus is on the bare minimum security controls and not integrating security with the big picture goals of the project. This can be due to a lack of security education on the part of developers but can also be attributed to lack of security buy-in, unclear security requirements, or a general lack of project leadership during the software development life cycle.</p>
<p><b>5.  Glazing over security during testing </b></p>
<p>Many software security controls operate independently as individual components and should be tested as such. Furthermore, flaws may only be obvious during the early unit testing stages. However, software security testing is often &#8220;saved&#8221; for later in the software development life cycle &#8211; during integration testing or post-implementation reviews &#8211; thus allowing flaws or inadequate controls to be overlooked. Likewise, integration testing can highlight flaws in interrelated components that might not readily show up during unit testing. It&#8217;s therefore important to ensure that security testing using the proper static analysis and penetration tools be performed during each testing phase of the software development life cycle, as well as once the software is implemented.</p>
<p><b>6.  Not using the right security testing tools</b></p>
<p>It&#8217;s one thing to develop with security in mind but quite another to use professional tools discover flaws during the software development life cycle that may otherwise be difficult or impossible for humans to find. Proper security testing tools used during threat modeling, coding, QA, and subsequent penetration testing processes are essential for looking at the big picture context as well as drilling down at a granular level to root out security-related problems at every possible phase of the software development life cycle. </p>
<p>Fortunately, there are software products available that can help you solve these problems without slowing aggressive project schedules. The application assessment software available today targets both developers and testers. Many developer products are integrated with popular IDEs, such as Microsoft&#8217;s Visual Studio .NET, and many security testing products are integrated with popular testing platforms like Mercury. </p>
<p>There is some work to do, however, in setting management goals. It is management&#8217;s responsibility to mandate secure applications. Vulnerabilities in software security must be treated like any other software defect. Smart development organizations know that it makes financial and organizational sense to do it right the first time, at the beginning of the software development life cycle.</p>
<p> Various resources are available to help you enhance your software development life cycle, and in turn, produce higher-quality, more secure applications long term. The following papers and standards cover both information security and secure coding and offer insight, principles, and processes that you can integrate immediately to improve software security:
<ul>
<li> <a href="http://csrc.nist.gov/publications/nistpubs/800-64/NIST-SP800-64.pdf" class="bluelink">NIST Special Publication 800-64-Security Considerations in the Information System Development Life Cycle</a> </li>
<li><a href="http://csrc.nist.gov/publications/nistpubs/800-27/sp800-27.pdf" class="bluelink">NIST Special Publication 800-27-Engineering Principles for Information Technology Security</a></li>
<li><a href="http://csrc.nist.gov/publications/nistpubs/800-55/sp800-55.pdf" class="bluelink">NIST Special Publication 800-55-Security Metrics Guide for Information Technology Systems </a></li>
<li><a href="http://www.iso.org/iso/en/ISOOnline.frontpage" class="bluelink">ISO/IEC 12207:1995-Information technology-Software life cycle processes</a> </li>
<li><a href="http://www.iso.org/iso/en/ISOOnline.frontpage" class="bluelink">ISO/IEC 17799:2005-Information technology-Security techniques-Code of practice for information security management </a></li>
<li><a href="http://msdn.microsoft.com/security/default.aspx?pull=/library/en-us/dnsecure/html/sdl.asp" class="bluelink">Microsoft&#8217;s Trustworthy Computing Security Development Lifecycle paper</a> </li>
</ul>
<p>Resolving problems in the development process and integrating security every step of the software development life cycle is much easier said than done and the business risks and costs must be balanced with rewards. However, it&#8217;s clear that strengthening the software development life cycle, possessing the right security testing tools, and placing software security higher in the priority list is an excellent and invaluable long-term business investment. Integrate such improvements and make small changes over time. This will lay the groundwork for a streamlined development process long term. You&#8217;ll be there before you know it.</p>
<p>Caleb Sima is the co-founder of SPI Dynamics, a <a href="http://www.spidynamics.com/">Web application security</a> products company.  He currently serves as the CTO and director of SPI Labs, SPI Dynamics R&#038;D security team. Prior to co-founding SPI Dynamics, Caleb was a member of the elite X-Force R&#038;D team at Internet Security Systems, and worked as a security engineer for S1 Corporation. Caleb is a regular speaker and press resource on <a href="http://www.spidynamics.com/products/qainspect/index.html">Web application security testing methods</a> and has contributed to (IN)Secure Magazine, Baseline Magazine and been featured in the Associated Press. </p>
<p>Kevin Beaver  founder of Atlanta-based <a href="http://www.principlelogic.com/">Principle Logic</a>, LLC  is an independent information security consultant, author, and speaker. He has over 18 years of experience in IT and specializes in performing information security assessments. Before starting his own information security services business five years ago, Kevin served in various information technology and security companies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/the-software-development-life-cycle-when-to-secure-your-process-2006-05/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 1/17 queries in 0.007 seconds using memcached
Object Caching 255/298 objects using memcached

Served from: webpronews.com @ 2012-02-12 17:43:48 -->
