<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>Application &amp; Cyber Security Blog</title>
    
    
    <link rel="alternate" type="text/html" href="http://blog.securityinnovation.com/blog/" />
    <id>tag:typepad.com,2003:weblog-94118724438890252</id>
    <updated>2012-05-15T11:00:00-04:00</updated>
    <subtitle>a blog covering software engineering, cybersecurity, and application risk management </subtitle>
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/ApplicationCyberSecurityBlog" /><feedburner:info uri="applicationcybersecurityblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://hubbub.api.typepad.com/" /><feedburner:emailServiceId>ApplicationCyberSecurityBlog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><entry>
        <title>Today’s CISO: The Three Personality Types - Technical, Business, and Strategic</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/Ll-O-b7OdPc/todays-ciso-the-three-personality-types-technical-business-and-strategic.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/05/todays-ciso-the-three-personality-types-technical-business-and-strategic.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c016304b1427d970d</id>
        <published>2012-05-15T11:00:00-04:00</published>
        <updated>2012-05-15T11:00:00-04:00</updated>
        <summary type="html">In my previous blog posts, I talked about who the CISO typically reports to today, and my thought that personality should drive where the CISO position resides. In this blog, I’m going to talk about the three major CISO personality types. While no CISO can be described purely one type,...&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/Ll-O-b7OdPc" height="1" width="1"/&gt;</summary>
        <author>
            <name>John Kirkwood</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="CISO Corner" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="John Kirkwood" />
        
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/05/todays-ciso-the-three-personality-types-technical-business-and-strategic.html</feedburner:origLink></entry>
    <entry>
        <title>Today’s CISO: Personality Should Dictate Where the Position Resides</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/9TXKYhlM-i8/todays-ciso-personality-should-dictate-where-the-position-resides.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/05/todays-ciso-personality-should-dictate-where-the-position-resides.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c016304b13e08970d</id>
        <published>2012-05-08T11:00:00-04:00</published>
        <updated>2012-05-08T11:00:00-04:00</updated>
        <summary type="html">In one of my previous blog posts, I talked about where the CISO typically reports to today and presented the notion that organizations need to match the different CISO personality types with corporate security objectives. When you are introduced to a doctor, you would probably naturally ask “What type of...&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/9TXKYhlM-i8" height="1" width="1"/&gt;</summary>
        <author>
            <name>John Kirkwood</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="CISO Corner" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="John Kirkwood" />
        
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/05/todays-ciso-personality-should-dictate-where-the-position-resides.html</feedburner:origLink></entry>
    <entry>
        <title>Boeing Paying Hackers to Break into Their Systems</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/LLIUsPsNTfA/boeing-paying-hackers-to-break-into-their-systems.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/05/boeing-paying-hackers-to-break-into-their-systems.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c016305073d3e970d</id>
        <published>2012-05-03T11:00:00-04:00</published>
        <updated>2012-05-03T11:00:00-04:00</updated>
        <summary type="html">Great Idea - but they’ll need a lot more than TWO! Boeing’s systems need to be capable of staving off hackers, and for more than two years, the company has been employed two cyber security specialists (“hackers”) to test the security of its computer systems. I like it, but there’s...&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/LLIUsPsNTfA" height="1" width="1"/&gt;</summary>
        <author>
            <name>Joe Basirico</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cyber Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Joe Basirico" />
        
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/05/boeing-paying-hackers-to-break-into-their-systems.html</feedburner:origLink></entry>
    <entry>
        <title>Want to Reduce Application Security Risk?  Build more Secure Software</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/VQ7Eyj-hJus/want-to-reduce-application-security-risk-build-more-secure-software.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/05/want-to-reduce-application-security-risk-build-more-secure-software.html" thr:count="1" thr:updated="2012-05-08T16:52:37-04:00" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c016304ccb6da970d</id>
        <published>2012-05-01T11:00:00-04:00</published>
        <updated>2012-05-08T11:50:41-04:00</updated>
        <summary type="html">Our customers are interested in reducing application security risk. Over the years we’ve seen a variety of approaches to this problem and have help many customers on their path toward more secure applications and reduced risk. It’s interesting that you can categorize most approaches into these three areas Find and...&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/VQ7Eyj-hJus" height="1" width="1"/&gt;</summary>
        <author>
            <name>Jason Taylor</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="CTO Corner" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cyber Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Jason Taylor" />
        
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/05/want-to-reduce-application-security-risk-build-more-secure-software.html</feedburner:origLink></entry>
    <entry>
        <title>Today’s CISO:  Where do They Report and Can They be Successful There?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/mQeW-qKBoWI/todays-ciso-where-do-they-report-and-can-they-be-successful-there.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/04/todays-ciso-where-do-they-report-and-can-they-be-successful-there.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c0168eaa689e2970c</id>
        <published>2012-04-26T11:00:00-04:00</published>
        <updated>2012-04-26T11:00:00-04:00</updated>
        <summary type="html">As a CISO myself, I have a vested interest in this question that at first glance, appears to be quite simple. After all, there seems to be little debate as to where other C-officers should report. While there has been some discussion about certain C level offices such as the...&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/mQeW-qKBoWI" height="1" width="1"/&gt;</summary>
        <author>
            <name>John Kirkwood</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="CISO Corner" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="John Kirkwood" />
        
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/04/todays-ciso-where-do-they-report-and-can-they-be-successful-there.html</feedburner:origLink></entry>
    <entry>
        <title>EU to potentially punish publishers of cyber attack tools</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/JBY4svOxMe0/eu-to-potentially-punish-publishers-of-cyber-attack-tools.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/04/eu-to-potentially-punish-publishers-of-cyber-attack-tools.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c0168ea769cbb970c</id>
        <published>2012-04-24T11:15:00-04:00</published>
        <updated>2012-04-24T11:15:00-04:00</updated>
        <summary type="html">There is a draft law by the EU that would make attacks on IT systems a criminal offense and punishable by at least two years in prison. Additionally, possessing or distributing hacking software and tools would be an offense. I understand the potential motive here: reduce the number of attacks...&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/JBY4svOxMe0" height="1" width="1"/&gt;</summary>
        <author>
            <name>Eadams</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="CEO Blog" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cyber Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Ed Adams" />
        
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/04/eu-to-potentially-punish-publishers-of-cyber-attack-tools.html</feedburner:origLink></entry>
    <entry>
        <title>Effective Application Security Testing: The Evil Streak</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/Q3z0l-cjF2k/effective-application-security-testing-the-evil-streak.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/04/effective-application-security-testing-the-evil-streak.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c01630407296f970d</id>
        <published>2012-04-17T10:50:00-04:00</published>
        <updated>2012-04-12T10:52:14-04:00</updated>
        <summary type="html">We've made it to the last part of my four part series on what makes a great security tester or hacker. Even though this fourth piece is what I consider to be the most important and exciting quality of a hacker, I do recommend you go back and read the...&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/Q3z0l-cjF2k" height="1" width="1"/&gt;</summary>
        <author>
            <name>Joe Basirico</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cyber Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Joe Basirico" />
        
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/04/effective-application-security-testing-the-evil-streak.html</feedburner:origLink></entry>
    <entry>
        <title>Effective Application Security Testing: A Great Security Tester has a Great Imagination</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/fLxI6574hNg/effective-application-security-testing-a-great-security-tester-has-a-great-imagination.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/04/effective-application-security-testing-a-great-security-tester-has-a-great-imagination.html" thr:count="2" thr:updated="2012-04-11T12:52:40-04:00" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c0168e9d9dc3e970c</id>
        <published>2012-04-10T11:07:00-04:00</published>
        <updated>2012-04-09T11:11:30-04:00</updated>
        <summary type="html">In my previous posts I talked about an overview of what makes a great security tester, and in-depth about what it means to have complete knowledge of the system. If you haven’t read those yet, I suggest you do so now, that’ll help set the stage for the following post....&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/fLxI6574hNg" height="1" width="1"/&gt;</summary>
        <author>
            <name>Joe Basirico</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cyber Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Joe Basirico" />
        
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/04/effective-application-security-testing-a-great-security-tester-has-a-great-imagination.html</feedburner:origLink></entry>
    <entry>
        <title>GOP version of CyberSecurity Bill introduced</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/eHOUPhN_sFY/gop-version-of-cybersecurity-bill-introduced.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/04/gop-version-of-cybersecurity-bill-introduced.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c0167648ec2b3970b</id>
        <published>2012-04-03T11:00:00-04:00</published>
        <updated>2012-04-03T13:32:17-04:00</updated>
        <summary type="html">one step forward, two steps back A Republican bill was introduced in the House of Representatives this week (ref: http://thehill.com/blogs/hillicon-valley/technology/218421-secure-it-act-introduced-in-the-house) similar to the cleverly-named but ill-conceived SECURE IT bill GOP Senators introduced last month. A major difference between this bill and the Lieberman-Collins bill (as well as the Langevin bill...&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/eHOUPhN_sFY" height="1" width="1"/&gt;</summary>
        <author>
            <name>Eadams</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="CEO Blog" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cyber Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Ed Adams" />
        
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/04/gop-version-of-cybersecurity-bill-introduced.html</feedburner:origLink></entry>
    <entry>
        <title>Where Can We Harness AppSec Talent? In College, that’s Where.</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ApplicationCyberSecurityBlog/~3/HOOIm6mSmXg/where-can-we-harness-appsec-talent-in-college-thats-where.html" />
        <link rel="replies" type="text/html" href="http://blog.securityinnovation.com/blog/2012/03/where-can-we-harness-appsec-talent-in-college-thats-where.html" thr:count="1" thr:updated="2012-04-29T04:42:25-04:00" />
        <id>tag:typepad.com,2003:post-6a014e607b2bef970c0168e94c1130970c</id>
        <published>2012-03-28T10:00:00-04:00</published>
        <updated>2012-03-28T13:26:21-04:00</updated>
        <summary type="html">Yesterday, Security Innovation and the University of Central Florida launched a seriously groundbreaking certification program through UCF’s division of Continuing Education: the Secure Software Development Certificate Program. (SSD) Why is this so cool? Well, for one, UCF (which happens to be the second-largest university in the US) selected our TeamProfessor...&lt;img src="http://feeds.feedburner.com/~r/ApplicationCyberSecurityBlog/~4/HOOIm6mSmXg" height="1" width="1"/&gt;</summary>
        <author>
            <name>Tom Bain</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Tom Bain" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Application Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Application Security certification" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Application Security training" />
        <category scheme="http://sixapart.com/ns/types#tag" term="appsec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Security Innovation" />
        <category scheme="http://sixapart.com/ns/types#tag" term="University of Central Florida" />
        



    <feedburner:origLink>http://blog.securityinnovation.com/blog/2012/03/where-can-we-harness-appsec-talent-in-college-thats-where.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 -->

