Security Assessment Content on InfoQ
Latest featured content about Security Assessment

- Topics
- GOTO 2011,
- Encryption,
- Public Cloud,
- Private Cloud,
- Cloud Adoption,
- SaaS,
- Cloud Security,
- Security Assessment,
- IaaS,
- Cryptography ,
- Deployment,
- GOTO Conference,
- PaaS,
- Security,
- Cloud Computing,
- Conferences
While Cloud Computing offers increased business agility and reduced cost, many are worried about security: loss of control and lack of confidentiality. Presented by Alon Hazy and Jakob Illeborg Pagter, this talk looks at the threat landscape, then examines how to secure cloud solutions today and in the future.

- Topics
- Security Assessment,
- Vulnerabilities,
- Security,
- Threat Modeling
In this IEEE article, author John Diamant talks about how to improve security quality of software applications using a proactive approach with techniques like Security requirements gap analysis and Architectural threat analysis in the early phases of software development life cycle.

- Topics
- Security Assessment,
- Static Analysis,
- Architecture,
- Security
Building security into software applications from the initial phases of development process is critical. Static code analysis gives developers the ability to review their code without actually executing it to uncover potential security vulnerabilities. InfoQ spoke with Brian Chess about static analysis and how it compares with other security assessment techniques like penetration testing.
News about Security Assessment
- Topics
- Communication,
- Distributed Teams,
- Security Assessment,
- Teamwork,
- Agile,
- Enterprise Architecture,
- Security,
- Security Vulnerabilities,
- Internet,
- Standardization
IEEE announced that the Hans Karlsson Standard Award 2012 has been given to Paul R. Croll for dedicated leadership of the IEEE Systems and Software Engineering Standards Committee, and for his diplomacy and collaboration in facilitating the development of a collection of high-quality standards.
- Topics
- Code Analysis,
- Debugging,
- Operations,
- Security Assessment,
- Profilers,
- Infrastructure,
- Security Code Reviews,
- Architecture,
- Security,
- Penetration Testing,
- Programming
Web application security testing and assessment should include both security code review and penetration testing techniques. Dave Wichers, an OWASP Board Member, spoke at the recent AppSec DC 2010 Conference about the pros and cons of code reviews and penetration testing approaches in finding security vulnerabilities in web applications.