Software Security Assurance Update

SPOTLIGHT ON: Security in the Software Development Lifecycle

Volume 3, Issue 2

Greetings from SSA Update, a quarterly newsletter from Ounce Labs that bring you the latest information on insights and advancements in Software Security Assurance. This issue presents actionable information on how to integrate security into the software development lifecycle.

IN THIS ISSUE:

SPOTLIGHT ARTICLES
Models for Implementing Security Testing During
Software Development

Establishing Controls for Software Security Assurance

Building Security In: An Ounce 4.0 Product Overview

Gartner IT Security Summit '06 Review: Focus on
Application Security

Q&A With Dr. Herbert H. Thompson, Chief Security
Strategist of Security Innovation


IN THE NEWS
Ounce Labs reaches out to developers with
new analysis tool,
searchappsecurity.com
Targeting security issues during development
ADT Magazine
Ounce’s Code Scanning Prevents Vulnerabilities,
Foils Attacks
CRN

OUNCE POLL

UPCOMING EVENTS


SPOTLIGHT ARTICLES

Models for Implementing Security Testing During Software Development

As organizations drive towards integrating security into the development lifecycle, there are a number of possible organizational and process models. Which is the best for your implementation? Click here for expert insight on the various approaches and their pros and cons.
Click here for full article


Establishing Controls for Software Security Assurance

Leading IT Auditor Charles LeGrand recently authored an article for the Institute of Internal Auditor’s ITAudit online journal. Read his advice on how companies and auditors can identify and implement the most effective software security controls and assurance.
Click here for full article
 

Building Security In: An Ounce 4.0 Product Overview

Read about the latest product release from Ounce Labs, featuring seamless integration of the industry’s leading source code vulnerability analysis into the software development lifecycle. Including a Developer Plug-in offered free of charge, Ounce allows maximum security impact as early as possible in the software lifecycle.
Click here for full article
 

Gartner IT Security Summit ’06 Review: Focus on Application Security

Application security was front and center at the annual Gartner Security Summit in June. Read this report on a key session on building secure applications by two of Gartner’s leading analysts. The summary also includes a link to a webcast of this important presentation.
Click here for full article
 
Read a brief Q&A Dr. Herbert H. Thompson, Chief Security Strategist of Security Innovation, sat down recently for a brief conversation with SSA Update about today’s greatest obstacles and opportunities in application security, and some expert recommendations for implementing an effective software security program.

IN THE NEWS

Ounce Labs reaches out to developers with new analysis tool searchappsecurity.com
Searchappsecurity’s Colleen Frye outlines the significance of Ounce Labs’ June announcement of the company’s latest release, Ounce 4.0.

Targeting security issues during development
ADT Magazine
This article by Jason Turcotte, writing for a leading development-focused magazine, features Ounce customer Brent Huston, security evangelist and CEO of MicroSolved, speaking about his experience switching from competing software to Ounce Labs and his perspective on the company’s latest product announcement.

 

Ounce’s Code Scanning Prevents Vulnerabilities, Foils Attacks, CRN
Paula Rooney of CRN spoke with Ounce partners Unisys and immixGroup about the importance of source code analysis in application security, and the effectiveness of the Ounce solution in their work.

• What group in your organization is responsible for conducting security code reviews? [select one]
IT Security
Development
Both
Don't do security code reviews
Other


OUNCE ANNOUNCES

June 20, 2006
OUNCE LABS NAMES CLAUDIA DENT SENIOR VICE PRESIDENT OF PRODUCT MARKETING

June 14, 2006
OUNCE LABS PARTNERS WITH SECURITY INNOVATION TO ADVANCE SOURCE CODE ANALYSIS CAPABILITIES

June 5, 2006
OUNCE 4.0 DELIVERS MAJOR ADVANCEMENTS IN SOURCE CODE VULNERABILITY ANALYSIS

June 5, 2006
OUNCE LABS NAMED TO SD TIMES 100 FOR 2006

UPCOMING EVENTS

August 13-17, 2006
Air Force Information Technology Conference
Montgomery, AL
Jack Danahy, Speaker
"Software Assurance: DOD Implementation of Source Code Vulnerability Analysis"

August 21-23, 2006
The IIA's Risk and Control Conference
Palm Beach, FL
Jack Danahy, Speaker
"Primary Controls for Software Security"

September 13-14, 2006
5th Annual Cyber Security Executive Summit
New York, NY
Gold Sponsor
Ounce Labs  |  100 Fifth Avenue  |  Waltham, MA 02451  |  www.ouncelabs.com  |  866-33-OUNCE