Following the Wh1t3 Rabbit - Practical Enterprise Security

Enterprise Security organizations often find themselves caught between the ever-changing needs of the agile business, and the ever-present, ever-evolving threats to that business. At the same time – all too often we security professionals get caught up in “shiny object syndrome” which leads us to spend poorly, allocate resources unwisely, and generally de-couple from the organization we’re chartered to defend. Knowing how to defend begins with knowing what you’ll be defending, why it is worth defending, and who you’ll be defending from… and therein lies the trick. This blog takes the issue of enterprise security head-on, challenging outdated thinking and bringing a pragmatic, business-aligned, beyond the tools perspective … so follow the Wh1t3 Rabbit and remember that tools alone don’t solve problems, strategic thinkers are the key.

Rafal (Principal, Strategic Security Services)

Enterprise Software Security - The 2 Major Viable Models

I've been involved in software security in one way or another for a long time. Whether it's testing applications, reading source code, building a program or helping organizations build out themselves, the patterns that repeat over and over are pretty clear. There are two main models of software security - the auditor and the contributor models.  Let's talk briefly about those.

Search
About the Author(s)


HP Blog

HP Software Solutions Blog

Community Announcements
Follow Us
Labels