November 6, 2009, 3:05PM
Gary McGraw on Software Security, the BSIMM Model and Critical Thinking
-
Share
- (1)
Print
E-mail
2 Comments
Digital Underground podcast with Dennis Fisher ![]()
Dennis Fisher talks with Gary McGraw, CTO of Cigital, about the BSIMM security model, the maturation of software security and whether our universities are turning out critical thinkers.
*Podcast audio courtesy of Where's Aubrey
Recommended Reads
Shorten URL: http://threatpost.com/en_us/laj. Click to copy to clipboard or post to Twitter
Threatpost Newsletter
Featured Slideshows
Take Our Poll
Listen to Latest Podcasts
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
Featured White Paper
The 10 Questions You Must Ask Your Endpoint Security Vendor
Read this informative brief, prepared by Cascadia Labs, and learn how to ask the right questions to get the right answers when sourcing endpoint security vendors.
Download Now
Download Now





Comments
Interesting podcast... However, as I read all the hype around BSIMM, I never hear anyone ask about the motivations for doing this work.
As far as I know, both Cigital and Fortify are "for profit" enterprises and the last time I checked, the economy is still moribund. So, in a down economy, husbanding discretionary resources (such as travel budgets) seems prudent.
In light of those facts, a wide-scale data gathering exercise motivated by either altruism or science seems about as plausible as "standing room only" at a Windows 7 neighborhood launch party.
By Gary's own admission, a lot of time has been spent traveling to large companies in the US and Europe to assess their security practices. Gary also noted that none of the companies interviewed thus far are small or medium size companies - you know, the kind that don't have budgets to hire external security consultants.
It appears to this casual observer that BSIMM is being used as a protection racket - to scare enterprises into consulting engagements by pointing out "deficiencies" relative to the rest of the BSIMM data set. It has an interesting self-perpetuating aspect as well; as more data is gathered by companies participating in the BSIMM process, the farther "outside the norm" a target enterprise is shown to be.
How does a concerned enterprise get a higher BSIMM score? Seems obvious.
Dear chicken-poop anonymous poster,
We did the BSIMM for science. Here is a URL:
http://www.informit.com/articles/article.aspx?p=1562220
Capitalism is good.
gem
Post new comment