InfoQ

InfoQ

Topic/Tag specific view

Security Assessment Content on InfoQ


Latest featured content about Security Assessment

Cloud Security or: How I Learned to Stop Worrying and Love the Cloud

Topics
GOTO 2011,
Encryption,
Public Cloud,
Private Cloud,
Cloud Adoption,
SaaS,
Cloud Security,
Security Assessment,
IaaS,
Cryptography ,
Deployment,
GOTO Conference,
PaaS,
Security,
Cloud Computing,
Conferences

While Cloud Computing offers increased business agility and reduced cost, many are worried about security: loss of control and lack of confidentiality. Presented by Alon Hazy and Jakob Illeborg Pagter, this talk looks at the threat landscape, then examines how to secure cloud solutions today and in the future.

Resilient Security Architecture

Topics
Security Assessment,
Vulnerabilities,
Security,
Threat Modeling

In this IEEE article, author John Diamant talks about how to improve security quality of software applications using a proactive approach with techniques like Security requirements gap analysis and Architectural threat analysis in the early phases of software development life cycle.

Brian Chess on Static Code Analysis

Topics
Security Assessment,
Static Analysis,
Architecture,
Security

Building security into software applications from the initial phases of development process is critical. Static code analysis gives developers the ability to review their code without actually executing it to uncover potential security vulnerabilities. InfoQ spoke with Brian Chess about static analysis and how it compares with other security assessment techniques like penetration testing.

News about Security Assessment

IEEE’s Hans Karlsson Standards Award 2012 for Paul R. Croll

Topics
Communication,
Distributed Teams,
Security Assessment,
Teamwork,
Agile,
Enterprise Architecture,
Security,
Security Vulnerabilities,
Internet,
Standardization

IEEE announced that the Hans Karlsson Standard Award 2012 has been given to Paul R. Croll for dedicated leadership of the IEEE Systems and Software Engineering Standards Committee, and for his diplomacy and collaboration in facilitating the development of a collection of high-quality standards.

Security Assessment Techniques: Code Review v Pen Testing

Topics
Code Analysis,
Debugging,
Operations,
Security Assessment,
Profilers,
Infrastructure,
Security Code Reviews,
Architecture,
Security,
Penetration Testing,
Programming

Web application security testing and assessment should include both security code review and penetration testing techniques. Dave Wichers, an OWASP Board Member, spoke at the recent AppSec DC 2010 Conference about the pros and cons of code reviews and penetration testing approaches in finding security vulnerabilities in web applications.