Core Software Security: Security at the Source (Hardcover)
暫譯: 核心軟體安全:源頭的安全性 (精裝版)
James Ransome, Anmol Misra
- 出版商: Auerbach Publication
- 出版日期: 2013-12-09
- 售價: $5,500
- 貴賓價: 9.5 折 $5,225
- 語言: 英文
- 頁數: 416
- 裝訂: Hardcover
- ISBN: 1466560959
- ISBN-13: 9781466560956
-
相關分類:
資訊安全
-
相關翻譯:
軟件安全 : 從源頭開始 (Core Software Security: Security at the Source) (簡中版)
海外代購書籍(需單獨結帳)
相關主題
商品描述
"... an engaging book that will empower readers in both large and small software development and engineering organizations to build security into their products. ... Readers are armed with firm solutions for the fight against cyber threats."
—Dr. Dena Haritos Tsamitis. Carnegie Mellon University
"... a must read for security specialists, software developers and software engineers. ... should be part of every security professional’s library."
—Dr. Larry Ponemon, Ponemon Institute
"... the definitive how-to guide for software security professionals. Dr. Ransome, Anmol Misra, and Brook Schoenfield deftly outline the procedures and policies needed to integrate real security into the software development process. ...A must-have for anyone on the front lines of the Cyber War ..."
—Cedric Leighton, Colonel, USAF (Ret.), Cedric Leighton Associates
"Dr. Ransome, Anmol Misra, and Brook Schoenfield give you a magic formula in this book - the methodology and process to build security into the entire software development life cycle so that the software is secured at the source! "
—Eric S. Yuan, Zoom Video Communications
There is much publicity regarding network security, but the real cyber Achilles’ heel is insecure software. Millions of software vulnerabilities create a cyber house of cards, in which we conduct our digital lives. In response, security people build ever more elaborate cyber fortresses to protect this vulnerable software. Despite their efforts, cyber fortifications consistently fail to protect our digital treasures. Why? The security industry has failed to engage fully with the creative, innovative people who write software.
Core Software Security expounds developer-centric software security, a holistic process to engage creativity for security. As long as software is developed by humans, it requires the human element to fix it. Developer-centric security is not only feasible but also cost effective and operationally relevant. The methodology builds security into software development, which lies at the heart of our cyber infrastructure. Whatever development method is employed, software must be secured at the source.
Book Highlights:
- Supplies a practitioner's view of the SDL
- Considers Agile as a security enabler
- Covers the privacy elements in an SDL
- Outlines a holistic business-savvy SDL framework that includes people, process, and technology
- Highlights the key success factors, deliverables, and metrics for each phase of the SDL
- Examines cost efficiencies, optimized performance, and organizational structure of a developer-centric software security program and PSIRT
- Includes a chapter by noted security architect Brook Schoenfield who shares his insights and experiences in applying the book’s SDL framework
View the authors' website at http://www.androidinsecurity.com/
商品描述(中文翻譯)
'... 一本引人入勝的書籍,將使大型和小型軟體開發及工程組織的讀者能夠將安全性融入其產品中。... 讀者將獲得對抗網路威脅的堅實解決方案。'
—德娜·哈里托斯·查米提斯博士,卡內基梅隆大學
'... 對於安全專家、軟體開發人員和軟體工程師來說,這是一本必讀之作。... 應該成為每位安全專業人士的圖書館一部分。'
—拉里·波內蒙博士,波內蒙研究所
'... 軟體安全專業人士的權威實用指南。Ransome博士、Anmol Misra和Brook Schoenfield巧妙地概述了將真正的安全性整合到軟體開發過程中所需的程序和政策。... 對於任何在網路戰爭前線的人來說,這是必備之書...'—塞德里克·萊頓,美國空軍退役上校,塞德里克·萊頓協會
'Ransome博士、Anmol Misra和Brook Schoenfield在這本書中給你一個魔法公式 - 將安全性融入整個軟體開發生命週期的方法論和過程,確保軟體在源頭上就得到保障!'
—艾瑞克·S·袁,Zoom Video Communications
有關網路安全的宣傳很多,但真正的網路阿基里斯之踵是安全性不足的軟體。數以百萬計的軟體漏洞形成了一個網路的紙牌屋,我們在其中進行數位生活。作為回應,安全專業人士建立了越來越複雜的網路堡壘來保護這些脆弱的軟體。儘管他們的努力,網路防禦始終無法保護我們的數位財寶。為什麼?安全產業未能充分與創造性和創新的人員合作,這些人員負責編寫軟體。
核心軟體安全闡述了以開發者為中心的軟體安全,這是一個整體過程,旨在激發創意以增強安全性。只要軟體是由人類開發的,就需要人類的元素來修復它。以開發者為中心的安全不僅可行,而且具有成本效益和操作相關性。這種方法論將安全性融入軟體開發,這是我們網路基礎設施的核心。無論採用何種開發方法,軟體必須在源頭上得到保障。
書籍亮點:
- 提供了SDL的實務觀點
- 將敏捷方法視為安全的促進者
- 涵蓋了SDL中的隱私要素
- 概述了一個包括人員、過程和技術的整體商業導向SDL框架
- 突顯了SDL每個階段的關鍵成功因素、交付成果和指標
- 檢視以開發者為中心的軟體安全計畫和PSIRT的成本效益、優化性能和組織結構
- 包括著名安全架構師Brook Schoenfield的一章,他分享了在應用本書的SDL框架中的見解和經驗
查看作者的網站:http://www.androidinsecurity.com/