IN THIS ISSUE:
SPOTLIGHT ARTICLES
- Beyond Bugs: Scanning Code for Design Flaws Software security is not just about eliminating coding errors, it is having the security mechanisms in place in the code, implemented properly, that protect data integrity and ensure privacy. This article discusses the range of design flaws and issues that must be considered, and scanned for, as part of any source code security review.
- Ounce Announces Integration with Leading Pen Testing Solutions In an effort to provide customers with the most flexible and accurate approach to vulnerability remediation, Ounce Labs has announced product integration that combines its product’s source code assessment results with findings from Cenzic® Hailstorm®, SPI Dynamics™ WebInspect™, and Watchfire® AppScan®. Find out more about this important step in identifying exploitable vulnerabilities.
- Updated PCI Standards Require Source Code Analysis The major credit card vendors recently updated the mandated security requirements for any of their members, merchants and service providers that store, process or transmit cardholder data. This standard includes specific instructions to analyze web-facing applications for common security vulnerabilities. Get the latest details.
- Securing the SDLC: An Expert Webinar How you improve software security during the development lifecycle? How can you effectively combine your organization's development skills and security expertise to deliver more secure software? This expert webcast features actionable advice from two of the industry's leading experts on application security, Dr. Herbert H. Thompson, and Ryan Berg of Ounce Labs.
- Q&A With Brent Huston, CEO of Microsolved, Inc. Read a brief Q&A Brent Huston, CEO of MicroSolved, a provider of risk management consulting for Fortune 500 corporations and government agencies, sat down recently for a brief conversation with Ounce Labs about recent trends in the threat landscape and the impact on organizational approaches to operational security and data privacy.
IN THE NEWS
- Software security: How closely should you look? The Globe and Mail
- A Process for Performing Security Code Reviews IEEE Computer Society

