HOME > SECURITY RESOURCES
Ounce Product Infosheet
Managing Software Risk: An Executive Call to Action
Frequently Asked Questions [FAQ]
Application Security Topics [FAQ]
These library resources require an Ounce Labs ID. Log in or register.
Two leading researchers from the Ounce Labs Advanced Research Team discuss their recent documentation of two vulnerabilities in the commonly used Spring framework that is utilized for creating dynamic, robust, highly scalable Web applications in Java.
Ryan Berg, Chief Scientist for Ounce Labs, discusses the critical areas in source code that must be reviewed to find and eliminate the flaws that threaten private data.
Three experts on PCI and application security address the latest updates to the PCI application security regulations, and how leading organizations are addressing them, according to a recent survey.
Jack Danahy, CTO and Founder of Ounce Labs, discusses the recent “clarification” of this critical PCI requirement, and how organizations should respond.
Jack Danahy, the founder and Chief Technology Officer of Ounce Labs, discusses how to hold outsourcers accountable.
Peter Schoof, Security Editor at eBizQ, talks with CTO Jack Danahy about
managing the security risks in outsourced software development.
Anthony Gerkis of Accenture and Jack Danahy of Ounce Labs discuss best
practices to manage and measure security in the SDLC.
Bruce Mayhew, Director, Advanced Security Research Group at Ounce Labs, discusses the latest techniques and tools to identify and eliminate malicious code in software.
Ryan Berg, Ounce Labs Chief Scientist, discusses the risks and concerns around e-voting.
Jack Danahy, Ounce CTO, talks with Network World about the threat to
custom applications.
Network World
Dr. Hugh Thompson of People Security discusses the new standard for
identifying risks to data and operations.
SearchSecurity
Your software is trying to tell you something
An Application Security Tools Report Card
A Practical Guide from Accenture and Ounce Labs
Uncover critical flaws, create efficient remediation workflow, and produce the right metrics for monitoring compliance
A Source Code Security Review Checklist
Implementing Source Code Vulnerability Testing in the Software Development Lifecycle
Securing Web Services and Ajax is about more than just securing the client.
A Source Code Security Analysis Case Study
A Framework for Software Vulnerability Management and Audit
The Need for Software Security Assurance
The Top Web Application Vulnerabilities and How to Hunt Them Down at the Source
Methods for Software Risk Assessment
Source Code Vulnerability Analysis and the Need for Metrics
How to Manage Risk in Outsourced Applications
Compliance Guide for Commercial Organizations
Compliance Guide for Financial Services
Compliance Guide for Federal Agencies
The Need for Secure Software For Financial Service Providers
The Need for Secure Software in Healthcare
The Need for Secure Software for Government Agencies