Developing Secure Software: Experiences From an International Software Vendor

By Achim D. Brucker.

Developing secure software is, in general, challenging and requires and end-to-end secure software development lifecycle. It is particular challenging if the secure software development lifecycle needs to fit the whole range of software products from small mobile apps to large scale enterprise system and needs to be applicable to a wide range of software development methodologies.

In this presentation, I will, in general, present the secure software development lifecycle of a a large European software vendor and, in particular, discuss the experiences in rolling out SAST and DAST tools to a world-wide developer community.

Please cite this work as follows:
A. D. Brucker, “Developing secure software: Experiences from an international software vendor,” presented at the OWASP meeting sheffield, Sheffield, UK, Feb. 25, 2016. Author copy: http://logicalhacking.com/publications/talk-brucker-owasp-secure-software-2016/

BibTeX
@Unpublished{ talk:brucker:owasp-secure-software:2016,
  date       = {2016-02-25},
  title      = {Developing Secure Software: Experiences From an International
                Software Vendor},
  author     = {Achim D. Brucker},
  venue      = {Sheffield, UK},
  eventtitle = {OWASP Meeting Sheffield},
  abstract   = {Developing secure software is, in general, challenging and
                requires and end-to-end secure software development lifecycle.
                It is particular challenging if the secure software
                development lifecycle needs to fit the whole range of software
                products from small mobile apps to large scale enterprise
                system and needs to be applicable to a wide range of software
                development methodologies.
                
                In this presentation, I will, in general, present the secure
                software development lifecycle of a a large European software
                vendor and, in particular, discuss the experiences in rolling
                out SAST and DAST tools to a world-wide developer community.},
  areas      = {software, security},
  note       = {Author copy: \url{http://logicalhacking.com/publications/talk-brucker-owasp-secure-software-2016/}},
}