I am becoming more and more interested in the (ISC)2 Certification called CSSLP: Certified Secure Software Lifecycle Professional
They have a whitepaper for this certification called “Code (In)Security” written by Mano Paul.
I am not allowed to publish the direct link because they request registration before giving the link to the whitepaper. In order to register (gratis), go to this link: http://www.isc2.org/wpv
|
|
My company offers consulting on how to prepare for TISAX, ISO27001, NIS2, CSMS and SOC2 audits. |
|
||
| Get in touch with us here: https://www.endpoint-cybersecurity.com/contact/ |
There is something interesting in this whitepaper: the acronym I.N.S.E.C.U.R.E :
I – Injectable code
N – Non repudiation Mechanisms not present
S – Spoofable code
E – Exception and Errors not Properly handled
C – Cryptographically Weak Code
U – Usafe/Unsecure Functions and Routines in Code
R – Reversible code
E – Elevated Privileges Required to Run
I can’t copy paste what each of these mean, but do please, read the paper 😉
© Copyright 2010 Sorin Mustaca, All rights Reserved. Written For: Sorin Mustaca - Security & Technology
Want to work with me on this topic?
Check Endpoint Cybersecurity to see the consulting services we offer.
You must be logged in to post a comment.