The Brave New World of InfoSec

About this Blog:

A seasoned security pro's take on events around the world.

Jeff Bardin

Let's Get it Right - It is Writing Proper Code, not Secure Code!

to Data Protection |
As a CISO, I grow weary hearing that developers need to be trained in how to write secure code. 

 

A whole industry around ‘writing secure code’ has sprung up. From academia (U of Illinois at Springfield, UVA, Purdue, GMU, Princeton, Penn State, U of Wash, U Cal Berkley, Vanderbilt, to name a few), to information security training and product companies. Books are being written on the subject. Millions are being made on writing secure code. Unless you are in the DoD, NSA, CIA or protecting ring zero, you are not writing secure code.

 

Everyone wants to teach you how to write secure code. Well, I refuse to allow anyone thru doors unless they want to teach developers how to write proper code. 

 

Other CISO’s are quoted:

 

“We train all our programmers in secure coding, and we follow the basic tenets of secure programming design and management…”

 

When a developer does not validate input, it is not a security bug. It is a developer’s defect. When programmers do not enforce restrictions on authenticated users, it is not a security bug. When error conditions are not handled properly, it is not a security bug.    When developers do not learn how to properly code cryptographic functions within their code, it is not a security bug. When devices are not configured properly, it is not a security bug. When applications fail open it is not because of a security bug. It is because of poor architecture, design and development.

 

What it comes down to is improper coding techniques and immature infrastructure environments that can be properly configured. Let’s start focusing on where the problems really reside and get CIO’s and others to recognize that it is all about writing proper code and configuring their environments the right way. The fire drill is getting old.


Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
WHITE PAPER
Reduce Email Archives up to 60%

Clearwell Are you considering implementing a proactive archiving and eDiscovery solutions? This paper summarizes 15 separate soft cost savings when implementing Symantec Enterprise Vault and the Clearwell eDiscovery Platform.

» Learn More

WHITE PAPER
Aberdeen Report: To Patch, or Not to Patch? (Not If, But How)

Secunia The report explores the correlation between the current use of patch management and the level of endpoint-related risk that companies are effectively accepting.

» Learn More

Browse CSO Blogs

See all CSO Blogs »

Recent Comments

RESOURCE CENTER