Home
International Software Testing Conference
Home
About The Conference
Organizers
2007 Security Speakers
2007 Security Testing Talks
2007 Quality Testing
2007 Keynote Speeches
2007 Sponsors
2007 Half-Day Workshops
VERIFY 2007 Conference
Mailing List

Enter your email to receive occasional news about VERIFY 2008.

ST14: Having a Defined Target for Software Security Testing PDF Print E-mail

Bob Martin — Mitre

Most organizations want assurance that their software has been tested for known security issues. Government, in conjunction with industry and academia are working together to make this economical and effective. The acquisition groups in large government and private organizations are moving to require that this types of testing be part of future contracts. The tools and services that can be used for evaluating source code, design, and architecture are maturing, however, there are no standards defining these types of capabilities. This lack of defined standards leaves open the question of which tool/service is appropriate/better for a particular job and how effective they are. Government, industry, and academia are working together to develop a dictionary of software weakness types and an assessment approach to help mature this new code-based security assessment industry, and dramatically accelerate the use and utility of these capabilities in testing the software systems they acquire, develop, and use.





Digg!Reddit!Del.icio.us!Google!Netscape!Technorati!StumbleUpon!Newsvine!Yahoo!
Last Updated ( Friday, 13 July 2007 )