Most organizations employ firewalls, antivirus software, and intrusion detection systems to fend off attackers, yet computer security issues are escalating. The core problem lies in bad software. Traditional solutions merely address symptoms reactively rather than tackling the underlying issues. This book advocates for a proactive approach to computer security, emphasizing the importance of getting security right from the outset. It is essential reading for security professionals who recognize software as a significant risk and for developers aiming to create secure code. Suitable for all involved in software development—from managers to programmers—this guide is your initial step toward enhancing software security. It offers expert insights and techniques to safeguard critical software by considering threats and vulnerabilities early in the development process. You will learn to assess acceptable risk levels, create security tests, and address vulnerabilities before software release. The book presents ten guiding principles for software security and detailed strategies to help you design robust systems. By building secure software, you can effectively defend against breaches, avoid the "penetrate and patch" cycle, and maintain customer trust while saving time, money, and credibility.
Gary McGraw Bücher
