Home › Compliance ›
This discussion is closed: you can't post new comments.
November 6, 2009, 3:05PM
Gary McGraw on Software Security, the BSIMM Model and Critical Thinking
Digital Underground podcast with Dennis Fisher ![]()
Dennis Fisher talks with Gary McGraw, CTO of Cigital, about the BSIMM security model, the maturation of software security and whether our universities are turning out critical thinkers.
*Podcast audio courtesy of Where's Aubrey
Recommended Reads
Commenting on this Article is closed.
Today's Most Popular
Most Commented Stories
Newsletter Sign-up
Take Our Poll
The Internet Crime Complaint Center recently warned of malware targeting travelers connecting to Wi-Fi. When traveling, do you
Connect to anything
20%
Only connect to password-protected, secure connections
38%
Only use websites with HTTPS
28%
I don’t pay attention to how I access the internet while traveling
14%
Total votes: 65
Listen to Latest Podcasts
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.





Comments
Interesting podcast... However, as I read all the hype around BSIMM, I never hear anyone ask about the motivations for doing this work.
As far as I know, both Cigital and Fortify are "for profit" enterprises and the last time I checked, the economy is still moribund. So, in a down economy, husbanding discretionary resources (such as travel budgets) seems prudent.
In light of those facts, a wide-scale data gathering exercise motivated by either altruism or science seems about as plausible as "standing room only" at a Windows 7 neighborhood launch party.
By Gary's own admission, a lot of time has been spent traveling to large companies in the US and Europe to assess their security practices. Gary also noted that none of the companies interviewed thus far are small or medium size companies - you know, the kind that don't have budgets to hire external security consultants.
It appears to this casual observer that BSIMM is being used as a protection racket - to scare enterprises into consulting engagements by pointing out "deficiencies" relative to the rest of the BSIMM data set. It has an interesting self-perpetuating aspect as well; as more data is gathered by companies participating in the BSIMM process, the farther "outside the norm" a target enterprise is shown to be.
How does a concerned enterprise get a higher BSIMM score? Seems obvious.
Dear chicken-poop anonymous poster,
We did the BSIMM for science. Here is a URL:
http://www.informit.com/articles/article.aspx?p=1562220
Capitalism is good.
gem
GEM,
After short-term improvements in coding practices, do you see other possible long-term eventual outcomes for this study ie. turn-key bundled options for software development, a ranking system for vendors or a seal of approval?