Secure and Resilient Software Development

  • 5h 6m
  • Lakshmikanth Raghavan, Mark S. Merkow
  • CRC Press
  • 2010

Although many software books highlight open problems in secure software development, few provide easily actionable, ground-level solutions. Breaking the mold, Secure and Resilient Software Development teaches you how to apply best practices and standards for consistent and secure software development. It details specific quality software development strategies and practices that stress resilience requirements with precise, actionable, and ground-level inputs.

Providing comprehensive coverage, the book illustrates all phases of the secure software development life cycle. It shows developers how to master non-functional requirements including reliability, security, and resilience. The authors provide expert-level guidance through all phases of the process and supply many best practices, principles, testing practices, and design methodologies.

About the Authors

Mark S. Merkow, CISSP, CISM, CSSLP, works at PayPal Inc. (an eBay company) in Scottsdale, Arizona, as Manager of Security Consulting and IT Security Strategy in the Information Risk Management area. Mark has over 35 years of experience in information technology in a variety of roles, including applications development, systems analysis and design, security engineer, and security manager. Mark holds a Masters in Decision and Info Systems from Arizona State University (ASU), a Masters of Education in Distance Learning from ASU, and a BS in Computer Info Systems from ASU. In addition to his day job, Mark engages in a number of extracurricular activities, including consulting, course development, online course delivery, writing e-business columns, and writing books on information technology and information security.

Mark has authored or co-authored nine books on IT and has been a contributing editor to four others.

Mark remains very active in the information security community, working in a variety of roles for the Financial Services Information Sharing and Analysis Center (FS-ISAC), the Financial Services Technology Consortium (FSTC), and the Financial Services Sector Coordinating Council (FSCCC) on Homeland Security and Critical Infrastructure Protection.

Lakshmikanth Raghavan (Laksh) works at PayPal Inc. (an eBay company) as Staff Information Security Engineer in the Information Risk Management area. He has over eight years of experience in the areas of information security and information risk management and has been providing consulting services to Fortune 500 companies and financial services companies around the world in his previous stints. He is a Certified Ethical Hacker (CEH) and also maintains the Certified Information Security Manager (CISM) certificate from ISACA (previously known as the Information Systems Audit and Control Association). Laksh holds a Bachelor's degree in Electronics & Telecommunication Engineering from the University of Madras, India. Laksh enjoys writing security-related articles and has spoken on the various dimensions of software security at industry forums and security conferences.

In this Book

  • How Does Software Fail Thee? Let Us Count the Ways
  • Characteristics of Secure and Resilient Software
  • Security and Resilience in the Software Development Life Cycle
  • Proven Best Practices for Resilient Applications
  • Designing Applications for Security and Resilience
  • Programming Best Practices
  • Special Considerations for Embedded Systems, Cloud Computing, and Mobile Computing Devices
  • Security Testing of Custom Software Applications
  • Testing Commercial off-the-Shelf Systems
  • Implementing Security and Resilience Using CLASP
  • Metrics and Models for Security and Resilience Maturity
  • Taking It to the Streets
SHOW MORE
FREE ACCESS

YOU MIGHT ALSO LIKE

Rating 4.4 of 59 users Rating 4.4 of 59 users (59)
Rating 4.7 of 266 users Rating 4.7 of 266 users (266)
Rating 4.6 of 125 users Rating 4.6 of 125 users (125)