{"product_id":"software-security-building-security-in-paperback","title":"Software Security: Building Security in - Paperback","description":"\u003cdiv\u003e\u003cp style=\"text-align: right;\"\u003e\u003ca href=\"https:\/\/reportcopyrightinfringement.com\/\" target=\"_blank\" rel=\"nofollow\"\u003e\u003cb\u003eReport copyright infringement\u003c\/b\u003e\u003c\/a\u003e\u003c\/p\u003e\u003c\/div\u003e\u003cp\u003eby \u003cb\u003eGary McGraw\u003c\/b\u003e (Author)\u003c\/p\u003e\u003cp\u003e\u003ci\u003e\"When it comes to software security, the devil is in the details. This book tackles the details.\" \u003c\/i\u003e\u003cbr\u003e--Bruce Schneier, CTO and founder, Counterpane, and author of \u003ci\u003eBeyond Fear\u003c\/i\u003e and \u003ci\u003eSecrets and Lies\u003c\/i\u003e\u003c\/p\u003e  \u003ci\u003e\"McGraw's book shows you how to make the 'culture of security' part of your development lifecycle.\"\u003c\/i\u003e\u003cbr\u003e--Howard A. Schmidt, Former White House Cyber Security Advisor  \u003ci\u003e\"McGraw is leading the charge in software security. His advice is as straightforward as it is actionable. If your business relies on software (and whose doesn't), buy this book and post it up on the lunchroom wall.\"\u003c\/i\u003e\u003cbr\u003e--Avi Rubin, Director of the NSF ACCURATE Center; Professor, Johns Hopkins University; and coauthor of \u003ci\u003eFirewalls and Internet Security\u003c\/i\u003e  Beginning where the best-selling book \u003ci\u003eBuilding Secure Software\u003c\/i\u003e left off, \u003ci\u003e\u003cb\u003eSoftware Security\u003c\/b\u003e\u003c\/i\u003e teaches you how to put software security into practice.The software security best practices, or touchpoints, described in this book have their basis in good software engineering and involve explicitly pondering security throughout the software development lifecycle. This means knowing and understanding common risks (including implementation bugsand architectural flaws), designing for security, and subjecting all software artifacts to thorough, objective risk analyses and testing.  \u003ci\u003e\u003cb\u003eSoftware Security\u003c\/b\u003e\u003c\/i\u003e is about putting the touchpoints to work for you. Because you can apply these touchpoints to the software artifacts you already produce as you develop software, you can adopt this book's methods without radically changing the way you work. Inside you'll find detailed explanations of \u003cul\u003e \u003cli\u003eRisk management frameworks and processes \u003c\/li\u003e \u003cli\u003eCode review using static analysis tools \u003c\/li\u003e \u003cli\u003eArchitectural risk analysis \u003c\/li\u003e \u003cli\u003ePenetration testing \u003c\/li\u003e \u003cli\u003eSecurity testing \u003c\/li\u003e \u003cli\u003eAbuse case development\u003c\/li\u003e \u003c\/ul\u003e In addition to the touchpoints, \u003ci\u003e\u003cb\u003eSoftware Security\u003c\/b\u003e\u003c\/i\u003e covers knowledge management, training and awareness, and enterprise-level software security programs. Now that the world agrees that software security is central to computer security, it is time to put philosophy into practice. Create your own secure development lifecycle by enhancing your existing software development lifecycle with the touchpoints described in this book. Let this expert author show you how to build more secure software by building security in.\u003ch3\u003eBack Jacket\u003c\/h3\u003e\u003cp\u003e\u003c\/p\u003e\u003cp\u003eThis is the Mobipocket version of the print book.\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003e\u003ci\u003e\"When it comes to software security, the devil is in the details. This book tackles the details.\" \u003c\/i\u003e\u003cbr\u003e--Bruce Schneier, CTO and founder, Counterpane, and author of \u003ci\u003eBeyond Fear\u003c\/i\u003e and \u003ci\u003eSecrets and Lies\u003c\/i\u003e\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003e\u003ci\u003e\"McGraw's book shows you how to make the 'culture of security' part of your development lifecycle.\"\u003c\/i\u003e\u003cbr\u003e--Howard A. Schmidt, Former White House Cyber Security Advisor\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003e\u003ci\u003e\"McGraw is leading the charge in software security. His advice is as straightforward as it is actionable. If your business relies on software (and whose doesn't), buy this book and post it up on the lunchroom wall.\"\u003c\/i\u003e\u003cbr\u003e--Avi Rubin, Director of the NSF ACCURATE Center; Professor, Johns Hopkins University; and coauthor of \u003ci\u003eFirewalls and Internet Security\u003c\/i\u003e\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003eBeginning where the best-selling book \u003ci\u003eBuilding Secure Software\u003c\/i\u003e left off, \u003ci\u003e\u003cb\u003eSoftware Security\u003c\/b\u003e\u003c\/i\u003e teaches you how to put software security into practice.The software security best practices, or touchpoints, described in this book have their basis in good software engineering and involve explicitly pondering security throughout the software development lifecycle. This means knowing and understanding common risks (including implementation bugsand architectural flaws), designing for security, and subjecting all software artifacts to thorough, objective risk analyses and testing.\u003c\/p\u003e \u003cp\u003e \u003c\/p\u003e \u003cp\u003e\u003ci\u003e\u003cb\u003eSoftware Security\u003c\/b\u003e\u003c\/i\u003e is about putting the touchpoints to work for you. Because you can apply these touchpoints to the software artifacts you already produce as you develop software, you can adopt this book's methods without radically changing the way you work. Inside you'll find detailed explanations of\u003c\/p\u003e \u003cul\u003e \u003cli\u003eRisk management frameworks and processes \u003c\/li\u003e \u003cli\u003eCode review using static analysis tools \u003c\/li\u003e \u003cli\u003eArchitectural risk analysis \u003c\/li\u003e \u003cli\u003ePenetration testing \u003c\/li\u003e \u003cli\u003eSecurity testing \u003c\/li\u003e \u003cli\u003eAbuse case development\u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003eIn addition to the touchpoints, \u003ci\u003e\u003cb\u003eSoftware Security\u003c\/b\u003e\u003c\/i\u003e covers knowledge management, training and awareness, and enterprise-level software security programs.\u003c\/p\u003e \u003cp\u003eNow that the world agrees that software security is central to computer security, it is time to put philosophy into practice. Create your own secure development lifecycle by enhancing your existing software development lifecycle with the touchpoints described in this book. Let this expert author show you how to build more secure software by building security in.\u003c\/p\u003e\u003ch3\u003eAuthor Biography\u003c\/h3\u003e\u003cp\u003e\u003c\/p\u003e\u003cp\u003e\u003cb\u003eGary McGraw, \u003c\/b\u003e Cigital, Inc.'s CTO, is a world authority on software security. Dr. McGraw is coauthor of five best selling books: \u003ci\u003eExploiting Software \u003c\/i\u003e(Addison-Wesley, 2004), \u003ci\u003eBuilding Secure Software\u003c\/i\u003e (Addison-Wesley, 2001), \u003ci\u003eSoftware Fault Injection\u003c\/i\u003e (Wiley 1998), \u003ci\u003eSecuring Java\u003c\/i\u003e (Wiley, 1999), and \u003ci\u003eJava Security\u003c\/i\u003e (Wiley, 1996). His new book, \u003ci\u003eSoftware Security: Building Security In\u003c\/i\u003e (Addison-Wesley 2006) was released in February 2006. As a consultant, Dr. McGraw provides strategic advice to major software producers and consumers. Dr. McGraw has written over ninety peer-reviewed technical publications and functions as principal investigator on grants from DARPA, National Science Foundation, and NIST's Advanced Technology Program. He serves on Advisory Boards of Authentica, Counterpane, and Fortify Software, as well as advising the CS Department at UC Davis, the CS Department at UVa, and the School of Informatics at Indiana University. Dr. McGraw holds a dual PhD in Cognitive Science and Computer Science from Indiana University and a BA in Philosophy from UVa. He is a member of the IEEE Security and Privacy Task Force, and was recently elected to the IEEE Computer Society Board of Governors. He is the producer of the Silver Bullet Security Podcast for \u003ci\u003eIEEE Security \u0026amp; Privacy\u003c\/i\u003e magazine, writes a monthly column for darkreading.com, and is often quoted in the press.\u003c\/p\u003e\n            \u003cdiv\u003e\n\u003cstrong\u003eNumber of Pages:\u003c\/strong\u003e 448\u003c\/div\u003e\n            \u003cdiv\u003e\n\u003cstrong\u003eDimensions:\u003c\/strong\u003e 1.17 x 9.22 x 7.06 IN\u003c\/div\u003e\n            \u003cdiv\u003e\n\u003cstrong\u003ePublication Date:\u003c\/strong\u003e January 23, 2006\u003c\/div\u003e\n            ","brand":"BooksCloud","offers":[{"title":"Default Title","offer_id":48532532822237,"sku":"9780321356703","price":89.99,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0811\/9867\/8237\/files\/U8jFO3gBwa9780321356703.webp?v=1788975742","url":"https:\/\/handfulofbooks.com\/products\/software-security-building-security-in-paperback","provider":"Handful of Books","version":"1.0","type":"link"}