Episode 7: Gary McGraw on Security

Published: Aug. 20, 2007, midnight

b'

Guest: Gary McGraw

\\n

Host: Michael Kircher

\\n\\n

Software security is an issue that everyone faces but that\\n not everyone gets right. Sometimes, our languages programming\\n claim to provide us a level of security that they cannot deliver.\\n

\\n\\n

Fortunately, folks like Gary McGraw, the CTO of Cigital, have\\n studied software, language technology, and security. McGraw\\n defines software security as "how to approach computer security\\n if you are a software developer or architect". In his experience,\\n the best way to build secure software is to have the people who\\n build our systems think carefully about security while they are\\n building them. Security is part of both the system\'s architecture\\n and its implementation.

\\n\\n

At ooPSLA, McGraw -- a globally-recognized\\n authority on software security and the author of six best selling\\n books on this topic -- is teaching a tutorial called\\n \\n Software Security: Building Security In\\n that will present a detailed approach to getting past theory and\\n putting software security into practice. The tutorial will give\\n a lesson in applied risk management and then present a number of\\n software security best practices.

\\n\\n

Listen to this podcast to hear Michael Kircher of SE Radio chat\\n with Gary about software security, patterns of attack on software,\\n and some of the most timely issues in security as applied to\\n on-line games.

'