Resources: SDLC
Showing Resources: 1–10 of 13
A Source Code Security Review Checklist
Code review is a well-regarded practice for improving quality and security, but it has historically been a seldom-applied technique because of its cost in time and resources. Through the tailored use of the Ounce tools and their output, it is now practical to perform security analysis ...
Implementing Source Code Vulnerability Testing in the SDLC
Frequently Asked Questions about the most effective ways to include source code analysis in a secure development process
Frequently Asked Questions about the application security testing and assessment process
A global defense systems integrator initiated a secure coding initiative program to select and deploy a solution which would add software security best practices to throughout the development lifecycle. ...
Ryan Berg, Chief Scientist for Ounce Labs, discusses the critical areas in source code that must be reviewed to find and eliminate the flaws that threaten private data.
Two leading researchers from the Ounce Labs Advanced Research Team discuss their recent documentation of two vulnerabilities in the commonly used Spring framework that is utilized for creating dynamic, robust, highly scalable Web applications in Java.
Anthony Gerkis of Accenture and Jack Danahy of Ounce Labs discuss best practices to manage and measure security in the SDLC
A Practical Guide from Accenture and Ounce Labs