Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
26
27
28
29
30
31
1
2
3
4
6
7
8
10
11
12
13
14
15
17
18
20
21
22
24
25
28
29
30
31
1
2
3
4
5
Food and Beverages
2021-07-26 - 2021-07-27    
12:00 am
The conference highlights the theme “Global leading improvement in Food Technology & Beverages Production” aimed to provide an opportunity for the professionals to discuss the [...]
European Endocrinology and Diabetes Congress
2021-08-05 - 2021-08-06    
All Day
This conference is an extraordinary and leading event ardent to the science with practice of endocrinology research, which makes a perfect platform for global networking [...]
Big Data Analysis and Data Mining
2021-08-09 - 2021-08-10    
All Day
Data Mining, the extraction of hidden predictive information from large databases, is a powerful new technology with great potential to help companies focus on the [...]
Agriculture & Horticulture
2021-08-16 - 2021-08-17    
All Day
Agriculture Conference invites a common platform for Deans, Directors, Professors, Students, Research scholars and other participants including CEO, Consultant, Head of Management, Economist, Project Manager [...]
Wireless and Satellite Communication
2021-08-19 - 2021-08-20    
All Day
Conference Series llc Ltd. proudly invites contributors across the globe to its World Convention on 2nd International Conference on Wireless and Satellite Communication (Wireless Conference [...]
Frontiers in Alternative & Traditional Medicine
2021-08-23 - 2021-08-24    
All Day
World Health Organization announced that, “The influx of large numbers of people to mass gathering events may give rise to specific public health risks because [...]
Agroecology and Organic farming
2021-08-26 - 2021-08-27    
All Day
Current research on emerging technologies and strategies, integrated agriculture and sustainable agriculture, crop improvements, the most recent updates in plant and soil science, agriculture and [...]
Agriculture Sciences and Farming Technology
2021-08-26 - 2021-08-27    
All Day
Current research on emerging technologies and strategies, integrated agriculture and sustainable agriculture, crop improvements, the most recent updates in plant and soil science, agriculture and [...]
CIVIL ENGINEERING, ARCHITECTURE AND STRUCTURAL MATERIALS
2021-08-27 - 2021-08-28    
All Day
Engineering is applied to the profession in which information on the numerical/mathematical and natural sciences, picked up by study, understanding, and practice, are applied to [...]
Diabetes, Obesity and Its Complications
2021-09-02 - 2021-09-03    
All Day
Diabetes Congress 2021 aims to provide a platform to share knowledge, expertise along with unparalleled networking opportunities between a large number of medical and industrial [...]
Events on 2021-07-26
Food and Beverages
26 Jul 21
Events on 2021-08-05
Events on 2021-08-09
Events on 2021-08-16
Events on 2021-08-19
Events on 2021-08-23
Events on 2021-09-02
Latest News

Cigital’s BSIMM7 finds new industries taking on security challenges

Enterprises are realizing they need to adjust their security initiatives, and as result, software security is finally becoming mainstream. But with the rise of new trends like the Internet of Things and containerization, it’s up to security teams to teach developers how to secure their code.

Cigital addresses these trends in BSIMM7, the latest version of its software security measurement tool. BSIMM7 looks at the value of software security, as well as industry changes surrounding security practices. The model it uses also has data on what firms are doing to stay secure, as well as the efforts to demonstrate what the companies are doing right.

The BSIMM7 model has expanded to include the largest amount of companies in its eight years of addressing software security, said Gary McGraw, CTO of Cigital.

(Related: Microsoft announces new security capabilities)

The model now draws from 95 organizations in six areas: financial services, independent software vendors, cloud, healthcare, Internet of Things, and insurance. (The last two industries were added this year.)

Industries represented within those areas included telecommunications, security, retail and energy, and it covered companies like Aetna, Bank of America, EMC, JPMorgan Chase, Siemens, Target and Wells Fargo.

McGraw said that Cigital tracks many industries, but only reported the data when they have at least nine companies in an area. This way, Cigital can report the data without “outing” any particular firm, he said.

Last year, the BSIMM6 model introduced the healthcare industry to bolster the dataset and show other healthcare firms what’s at risk within their systems. During this time, Cigital found software security to be lagging here. While healthcare software security has improved lately, McGraw said it still has a way to go.

On the other hand, the insurance vertical is slightly more mature than healthcare, and firms that were not paying attention to software security are now trying to up their efforts, according to McGraw.

Just like healthcare, data breaches are a big security risk for insurance companies, said McGraw. As this industry goes through its own digital transformation, it will completely change it will operate, he said.

“You used to go into your local insurance agent once every long time, but now insurance companies are releasing apps, and they have mobile solutions,” said McGraw. “As they adopt these new technology, they need to be really careful [of vulnerabilities].”

The BSIMM7 model is based on observation, and it serves as a “measuring stick” for software security for product security teams or software security groups (SSGs), said McGraw. The BSIMM is meant for use by anyone responsible for creating and executing a software security initiative, but developers looking to gain more insight into software security can benefit from the report as well.

“We still have many more people to teach about software security and building security in,” said McGraw.

According to the report, 272,782 developers have been directly touched by the BSIMM. With new technologies like IoT and containers, McGraw said it’s up to the SSGs to teach developers how to implement security better as software changes.

“That’s the job of the SSG, it’s to teach developers how to build security better,” said McGraw. “And that’s what we do at Cigital all day, we teach armies of developers how to code better, how to review their code with modern tools, what they can do when transporting their code to the cloud, and how to design and architect their code to be secure. All of those things are described by the BSIMM.”

Source