New software certification to stem vulnerabilities
By Asavin Wattanajantra,
Non-profit information security group ISC2 has announced a new certification programme validating secure software development to prevent security vulnerabilities, supported by vendors such as Microsoft, Symantec and Cisco.
ISC2 hoping the Certified Secure Software Lifecycle Professional (CSSLP) will cut the number of security vulnerabilities springing up due to software not being developed properly.
To do this, the certification aims to ensure best practices and also make sure that the individuals working on the software are capable of addressing any security issues that they encounter.
The group said that this will apply to anybody involved in working through the software lifecycle. This would include developers, software engineers, project managers, testers and programmers.
ISC2 quoted Gartner research which said 70 per cent of security vulnerabilities occurred at the application layer, claiming that it was a significant and immediate threat.
It was claimed that new applications lacking basic security controls were developed every day, with thousands of vulnerabilities ignored because developers did not have to deal with them.
“Unsecured software is not only a danger to the enterprise, it can cause higher production costs and delays for the software developer, and require additional staff for the end-user as well,” said John Colley, ISC2 managing director for EMEA.
He claimed that the new certification would be key in offering better critical infrastructure protection, the reduced risk of software malpractice suits and the stricter following of industry and government regulations.
Companies such as Cisco, Microsoft, SANS, Symantec and Xerox expressed their support for the scheme.
“Microsoft strongly supports industry efforts industry efforts to train and certify developers in security, especially those in organisations with limited resources,” said Steven B. Lipner, senior director of security engineering strategy at Microsoft.
“Along with executive commitment, tooling and state-of-the-art processes, certification and training are critical parts of secure development.”
Sponsored results
Gem GSP Internet Security Suite
Internet Security Suite includes everything you need to protect your small office or home...
dell business
Gem Who Do you Think You Are Deluxe
Getting started is easy. Just enter the information you already know and watch your tree take...
dell (uk)
Microsoft 66I-02393
Microsoft Windows Vista Home Premium SP1
ecost software
Related Tags
advertisement
Latest Security Features
How to be a successful online fraudster
Ever wanted to know how easy it is to be an identity thief and earn a fortune? IT PRO reveals all…
- What you need to know about ID cards
- Lessons to learn from a year of data breaches
- Q&A: DNS inventor Paul Mockapetris
- Is the password ill-equipped for the modern world?
- Why is backing up given short shrift?
- Defending Europe against cyber attack
- The present and future of IT security
- I’m an IT manager, get me out of here!
- IT around the world: Russia
Latest Security Reviews
Fortinet FortiGate-3810A
Rating: ![]()
- Clearswift MIMEsweeper Web Appliance ENW
- NetASQ U6000 UTM appliance
- AVG Internet Security SBS Edition 8.0
- Finjan Vital Security Web Appliance NG-6000S
- LogLogic MX2010
- Exclusive: WatchGuard Firebox Core X750e
- Sophos ES4000 Security Appliance
- Microsoft Forefront Security for Exchange and SharePoint
- EXCLUSIVE: Juniper Networks SSG 550 UTM appliance
advertisement
Latest News Videos in Security
Video: Eugene Kaspersky outlines security threats
IT PRO speaks to Eugene Kaspersky, chief executive and founder of Kaspersky Lab.
White papers
Want more background on today's hottest IT trends?
Visit IT PRO's white paper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free white papers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.
Sponsored results
- Gem GSP Internet Security Suite
Internet Security Suite includes everything you need to protect your small office or home computer in one modular package featuring MyPrivacy,...
dell business
- Gem Who Do you Think You Are Deluxe
Getting started is easy. Just enter the information you already know and watch your tree take shape. As your research gets going, you can add new...
dell (uk)
- Microsoft 66I-02393
Microsoft Windows Vista Home Premium SP1
ecost software



Social Bookmark this article: What is this?