November 6, 2009, 3:05PM

Gary McGraw on Software Security, the BSIMM Model and Critical Thinking

Digital Underground podcast with Dennis Fisher

Dennis Fisher talks with Gary McGraw, CTO of Cigital, about the BSIMM security model, the maturation of software security and whether our universities are turning out critical thinkers.

You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.

*Podcast audio courtesy of Where's Aubrey

(Download)

Subscribe to the Digital Underground podcast on 

 

Shorten URL: http://threatpost.com/en_us/laj. Click to copy to clipboard or post to Twitter

Comments

Interesting podcast...  However, as I read all the hype around BSIMM, I never hear anyone ask about the motivations for doing this work. 

As far as I know, both Cigital and Fortify are "for profit" enterprises and the last time I checked, the economy is still moribund. So, in a down economy, husbanding discretionary resources (such as travel budgets) seems prudent.

In light of those facts, a wide-scale data gathering exercise motivated by either altruism or science seems about as plausible as "standing room only" at a Windows 7 neighborhood launch party.  

By Gary's own admission, a lot of time has been spent traveling to large companies in the US and Europe to assess their security practices. Gary also noted that none of the companies interviewed thus far are small or medium size companies - you know, the kind that don't have budgets to hire external security consultants.

It appears to this casual observer that BSIMM is being used as a protection racket - to scare enterprises into consulting engagements by pointing out "deficiencies" relative to the rest of the BSIMM data set.  It has an interesting self-perpetuating aspect as well; as more data is gathered by companies participating in the BSIMM process, the farther "outside the norm" a target enterprise is shown to be.

How does a concerned enterprise get a higher BSIMM score?  Seems obvious.

 

Dear chicken-poop anonymous poster,

We did the BSIMM for science.  Here is a URL:

http://www.informit.com/articles/article.aspx?p=1562220

Capitalism is good.

gem

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
Please enter the two words below to help prevent spam.
Incorrect please try again
Enter the words above: Enter the numbers you hear:

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy