Articles | In the Press | Advance Praise

Articles

In the Press

BSIMM mentions on Twitter...

Advance Praise

"Nokia's participation in the BSIMM Europe project reflects a mutual, ongoing interest in setting, updating, and maintaining the highest standards in software security. The insights gained from the BSIMM project will doubtlessly further the definition of standards, which will not only serve as critical tools for measuring and comparing, but also enable the evolution of software security initiatives."

Janne Uusilehto
Head of Product Security
Nokia

"The path of improved software security has historically been a rocky one. To make it worse, the path has rarely been properly marked. The BSIMM fills this critical gap by providing a smoother, followable track to software security improvements. This practical maturity model allows organizations to benchmark their efforts against those of enterprises who have succesful software security programs. By identifying what activities they could implement or strengthen, based on a comparison with industry best practices, organizations will be able to plan and implement activities which lead to more secure software."

Charles Kolodgy
Research Director
Secure Products
IDC

"In their groundbreaking BSIMM study, application security luminaries McGraw, Chess and Migues provide us with the guidance to achieve superior application security. They show us how we all might adopt the leading-edge practices of nine of the most advanced organizations in this space. This report will provide a huge boost to what is arguably the most critical goal of today's information professionals ... secure software."

C. Warren Axelrod, Ph.D.
Executive Advisor, Financial Services Technology Consortium
Author "Outsourcing Information Security"

"The BSIMM effort is a fabulous step forward for Software Security as a whole, since it represents what these huge enterprises are actually doing in practice. It helps us all move the discipline significantly closer to being a sound engineering practice. Kudos!"

Kenneth R. van Wyk
KRvW Associates, LLC
Co-author of "Secure Coding"

"Microsoft's Security Development Lifecycle (SDL) was one of the first real enterprise software security methodologies, and we are always eager to share our ideas and best practices with the industry. BSIMM provides a public 'yardstick' for measuring the progress of any organization's own software assurance program."

Steve Lipner
Microsoft
Co-author of "The Security Development Lifecycle"

"I was surprised by the amount of common ground discovered between the financial services organizations, ISVs, and technology companies in the BSIMM study. All software security initiatives are by no means identical, but these findings demonstrate that an organization isn't going it alone when it comes to software security—you can learn from your peers. The BSIMM encapsulates important lessons from the best programs around."

Jim Routh
CISO of Depository Trust & Clearing Corporation (DTCC)

"Comprehensive software security involves a combination of people, processes, and technologies, and it almost always requires some change to the way the organization operates. As software security comes of age, using a maturity model will only help to accelerate your enterprise security initiative."

Joe Feiman
Gartner

"Many people ask 'where do we start, and where do we go from here?' when considering building or expanding their software security initiative. Encompassing so many aspects - not the least of which are organizational rather than technical in nature—the use of a maturity model will help in setting proper strategic direction while not forgetting about the elements needed to make much-needed tactical wins."

Ramon Krikken
Analyst - Security and Risk Management Strategies
Burton Group

"EMC has made significant investments in software security with the goal of delivering more secure products to our customers. By opening our own practices to help define the Building Security in Maturity Model, we wish to help advance the adoption of software assurance practices in the industry, which is a critical objective for EMC."

Eric Baize
Senior Director, Product Security Office
EMC

"When I heard about BSIMM I let out a cheer—at long last a practical guide for those that want to do application security for real. Gary and the gang behind this deserve a real pat on the back."

Nigel Stanley
Security Practice Leader
Bloor Research

"It's great to see that someone is offering practical advice in this area. It's past time that the industry started treating software development as serious business."

Marcus J Ranum
CSO, Tenable Network Security
Inventor of the firewall

"The BSIMM goes a long way towards transforming software security from an alchemy-like art to an Empirical science. By studying real software security initiatives, Gary, Sammy and Brian have created an important yardstick for software security."

Avi Rubin, Ph.D.
Professor of Computer Science, Johns Hopkins University
Author of Brave New Ballot