- Take an Extra 30% Off Any Book: Use promo code HOLIDAY30 at checkout to get an extra 30% off any book for a limited time. Excludes Kindle eBooks and Audible Audiobooks. Restrictions apply. Learn more
Enter your mobile number or email address below and we'll send you a link to download the free Kindle App. Then you can start reading Kindle books on your smartphone, tablet, or computer - no Kindle device required.
To get the free app, enter your email address or mobile phone number.
This is the Mobipocket version of the print book.
"When it comes to software security, the devil is in the details. This book tackles the details."
--Bruce Schneier, CTO and founder, Counterpane, and author ofBeyond FearandSecrets and Lies
"McGraw's book shows you how to make the 'culture of security' part of your development lifecycle."
--Howard A. Schmidt, Former White House Cyber Security Advisor
"McGraw is leading the charge in software security. His advice is as straightforward as it is actionable. If your business relies on software (and whose doesn't), buy this book and post it up on the lunchroom wall."
--Avi Rubin, Director of the NSF ACCURATE Center; Professor, Johns Hopkins University; and coauthor ofFirewalls and Internet Security
Beginning where the best-selling bookBuilding Secure Softwareleft off,Software Securityteaches you how to put software security into practice.The software security best practices, or touchpoints, described in this book have their basis in good software engineering and involve explicitly pondering security throughout the software development lifecycle. This means knowing and understanding common risks (including implementation bugsand architectural flaws), designing for security, and subjecting all software artifacts to thorough, objective risk analyses and testing.
Software Securityis about putting the touchpoints to work for you. Because you can apply these touchpoints to the software artifacts you already produce as you develop software, you can adopt this book's methods without radically changing the way you work. Inside you'll find detailed explanations of
In addition to the touchpoints,Software Securitycovers knowledge management, training and awareness, and enterprise-level software security programs.
Now that the world agrees that software security is central to computer security, it is time to put philosophy into practice. Create your own secure development lifecycle by enhancing your existing software development lifecycle with the touchpoints described in this book. Let this expert author show you how to build more secure software by building security in.
Good book, but I purchased it for the practice software for HP Fortify - which doesn't work. HP no longer supports it, and it won't run without HP support. Read morePublished 2 months ago by Computer Wrangler
This book was prescribed for a course I took in 2011-12. While the book covers the fundamentals well, the enclosed CD, which provides a copy of Fortify software didn't work. Read morePublished 21 months ago by Michigander
The book is good, but installing the Fortify trial is not that easy. I might be missing something here. Fortify rulepack download howto please?Published on August 20, 2013 by Emilio Grande
I did not liek this book at all. It came in handy, but I jut didn't like the way it readPublished on January 13, 2013 by cfuccirun
McGraw is a real pioneer, leading the way in the fundamental issues regarding the software development life cycle. Read morePublished on December 24, 2012 by Jose A. Villegas
the book came fast and the transition was easy. the book is very easy to understand how software security works.Published on February 21, 2012 by viempress