Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
27
28
29
30
31
1
2
3
4
5
6
7
8
9
10
12
13
14
15
16
19
21
22
24
26
27
28
29
30
11 Jun
2019-06-11 - 2019-06-13    
All Day
HIMSS and Health 2.0 European Conference Helsinki, Finland 11-13 June 2019 The HIMSS & Health 2.0 European Conference will be a unique three day event you [...]
7th Epidemiology and Public Health Conference
2019-06-17 - 2019-06-18    
All Day
Time : June 17-18, 2019 Dubai, UAE Theme: Global Health a major topic of concern in Epidemiology Research and Public Health study Epidemiology Meet 2019 in [...]
Inaugural Digital Health Pharma Congress
2019-06-17 - 2019-06-21    
All Day
Inaugural Digital Health Pharma Congress Join us for World Pharma Week 2019, where 15th Annual Biomarkers & Immuno-Oncology World Congress and 18th Annual World Preclinical Congress, two of Cambridge [...]
International Forum on Advancements in Healthcare - IFAH USA 2019
2019-06-18 - 2019-06-20    
All Day
International Forum on Advancements in Healthcare - IFAH (formerly Smart Health Conference) USA, will bring together 1000+ healthcare professionals from across the world on a [...]
Annual Congress on  Yoga and Meditation
2019-06-20 - 2019-06-21    
All Day
About Conference With the support of Organizing Committee Members, “Annual Congress on Yoga and Meditation” (Yoga Meditation 2019) is planned to be held in Dubai, [...]
Collaborative Care & Health IT Innovations Summit
2019-06-23 - 2019-06-25    
All Day
Technology Integrating Pre-Acute and LTPAC Services into the Healthcare and Payment EcosystemsHyatt Regency Inner Harbor 300 Light Street, Baltimore, Maryland, United States of America, 21202 [...]
2019 AHA LEADERSHIP SUMMIT
2019-06-25 - 2019-06-27    
All Day
Welcome Welcome to attendee registration for the 27th Annual AHA/AHA Center for Health Innovation Leadership Summit! The 2019 AHA Leadership Summit promotes a revolution in thinking [...]
Events on 2019-06-11
11 Jun
Events on 2019-06-17
Events on 2019-06-20
Events on 2019-06-23
Events on 2019-06-25
2019 AHA LEADERSHIP SUMMIT
25 Jun 19
San Diego
Latest News

Cigital’s BSIMM7 finds new industries taking on security challenges

Enterprises are realizing they need to adjust their security initiatives, and as result, software security is finally becoming mainstream. But with the rise of new trends like the Internet of Things and containerization, it’s up to security teams to teach developers how to secure their code.

Cigital addresses these trends in BSIMM7, the latest version of its software security measurement tool. BSIMM7 looks at the value of software security, as well as industry changes surrounding security practices. The model it uses also has data on what firms are doing to stay secure, as well as the efforts to demonstrate what the companies are doing right.

The BSIMM7 model has expanded to include the largest amount of companies in its eight years of addressing software security, said Gary McGraw, CTO of Cigital.

(Related: Microsoft announces new security capabilities)

The model now draws from 95 organizations in six areas: financial services, independent software vendors, cloud, healthcare, Internet of Things, and insurance. (The last two industries were added this year.)

Industries represented within those areas included telecommunications, security, retail and energy, and it covered companies like Aetna, Bank of America, EMC, JPMorgan Chase, Siemens, Target and Wells Fargo.

McGraw said that Cigital tracks many industries, but only reported the data when they have at least nine companies in an area. This way, Cigital can report the data without “outing” any particular firm, he said.

Last year, the BSIMM6 model introduced the healthcare industry to bolster the dataset and show other healthcare firms what’s at risk within their systems. During this time, Cigital found software security to be lagging here. While healthcare software security has improved lately, McGraw said it still has a way to go.

On the other hand, the insurance vertical is slightly more mature than healthcare, and firms that were not paying attention to software security are now trying to up their efforts, according to McGraw.

Just like healthcare, data breaches are a big security risk for insurance companies, said McGraw. As this industry goes through its own digital transformation, it will completely change it will operate, he said.

“You used to go into your local insurance agent once every long time, but now insurance companies are releasing apps, and they have mobile solutions,” said McGraw. “As they adopt these new technology, they need to be really careful [of vulnerabilities].”

The BSIMM7 model is based on observation, and it serves as a “measuring stick” for software security for product security teams or software security groups (SSGs), said McGraw. The BSIMM is meant for use by anyone responsible for creating and executing a software security initiative, but developers looking to gain more insight into software security can benefit from the report as well.

“We still have many more people to teach about software security and building security in,” said McGraw.

According to the report, 272,782 developers have been directly touched by the BSIMM. With new technologies like IoT and containers, McGraw said it’s up to the SSGs to teach developers how to implement security better as software changes.

“That’s the job of the SSG, it’s to teach developers how to build security better,” said McGraw. “And that’s what we do at Cigital all day, we teach armies of developers how to code better, how to review their code with modern tools, what they can do when transporting their code to the cloud, and how to design and architect their code to be secure. All of those things are described by the BSIMM.”

Source