<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Do We Need an ISO Secure Coding Standard?</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Thu, 03 Aug 2006 00:15:41 -0000</lastBuildDate><item><title>Re: Do We Need an ISO Secure Coding Standard?</title><link>http://www.matasano.com/log/388/do-we-need-an-iso-secure-coding-standard/#comment-2320038</link><description>Fair point. I think I'm really just pointing out that "building security into the QA process" is underrated and valuable.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Thu, 03 Aug 2006 00:15:41 -0000</pubDate></item><item><title>Re: Do We Need an ISO Secure Coding Standard?</title><link>http://www.matasano.com/log/388/do-we-need-an-iso-secure-coding-standard/#comment-2320037</link><description>&amp;gt;The solution to the secure coding problem is going &lt;br&gt;&amp;gt;to come from security QA, not secure coding.&lt;br&gt;&lt;br&gt;I'm going to disagree with that, I've been implementing security into the SDLC of many large companies for about a year now. In my experience the secure coding problem is eliminated by education, policies, _and_ security QA to catch violations of said polices. With management buy-in essential to every step of the process (You've got an overflow in your code, your bonus just dropped 10%...yes there exist large companies that are implementing this sort of penalty system for policy violations)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ErikC</dc:creator><pubDate>Wed, 02 Aug 2006 08:36:22 -0000</pubDate></item><item><title>Re: Do We Need an ISO Secure Coding Standard?</title><link>http://www.matasano.com/log/388/do-we-need-an-iso-secure-coding-standard/#comment-2320036</link><description>The solution is not more lists of things not to do, its checking technology to tell you when you did do one of those things.&lt;br&gt;&lt;br&gt;NIST SAMATE already has a short list of things not to do in their Source Code Analysis Tool Functional Specification</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris W.</dc:creator><pubDate>Fri, 28 Jul 2006 14:51:33 -0000</pubDate></item></channel></rss>