<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 软件厂商须承担更多安全责任 &#8211; 从丰田汽车召回事件说起</title>
	<atom:link href="http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/feed/" rel="self" type="application/rss+xml" />
	<link>http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/</link>
	<description>Technologies and comments on cloud and telecom security, bridging China and the world!</description>
	<lastBuildDate>Mon, 05 Mar 2012 09:33:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: 初探ICT供应链完整性(节选) : 弯曲评论</title>
		<link>http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/comment-page-1/#comment-36619</link>
		<dc:creator>初探ICT供应链完整性(节选) : 弯曲评论</dc:creator>
		<pubDate>Tue, 15 Jun 2010 14:02:41 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=1619#comment-36619</guid>
		<description>[...] 【注】本文节选自为即将发布的绿盟技术内刊，我被邀写一写新的动向，于是捉刀砍向最近关注的ICT供应链完整性，或大家更喜欢“安全”。这个话题在这篇初次提到，又在这篇再次涉及到，这次的内容稍微丰富了一些，希望能够给大家在工作研究之余，多一些参考。 [...]</description>
		<content:encoded><![CDATA[<p>[...] 【注】本文节选自为即将发布的绿盟技术内刊，我被邀写一写新的动向，于是捉刀砍向最近关注的ICT供应链完整性，或大家更喜欢“安全”。这个话题在这篇初次提到，又在这篇再次涉及到，这次的内容稍微丰富了一些，希望能够给大家在工作研究之余，多一些参考。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cloud &#38; Telecom Security &#187; 初探ICT供应链完整性(节选)</title>
		<link>http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/comment-page-1/#comment-36618</link>
		<dc:creator>Cloud &#38; Telecom Security &#187; 初探ICT供应链完整性(节选)</dc:creator>
		<pubDate>Tue, 15 Jun 2010 01:44:07 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=1619#comment-36618</guid>
		<description>[...] 【注】本文节选自为即将发布的绿盟技术内刊，我被邀写一写新的动向，于是捉刀砍向最近关注的ICT供应链完整性，或大家更喜欢“安全”。这个话题在这篇初次提到，又在这篇再次涉及到，这次的内容稍微丰富了一些，希望能够给大家在工作研究之余，多一些参考。 [...]</description>
		<content:encoded><![CDATA[<p>[...] 【注】本文节选自为即将发布的绿盟技术内刊，我被邀写一写新的动向，于是捉刀砍向最近关注的ICT供应链完整性，或大家更喜欢“安全”。这个话题在这篇初次提到，又在这篇再次涉及到，这次的内容稍微丰富了一些，希望能够给大家在工作研究之余，多一些参考。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cloud &#38; Telecom Security &#187; RSA 2010 大会纪行</title>
		<link>http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/comment-page-1/#comment-36526</link>
		<dc:creator>Cloud &#38; Telecom Security &#187; RSA 2010 大会纪行</dc:creator>
		<pubDate>Tue, 09 Mar 2010 18:07:38 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=1619#comment-36526</guid>
		<description>[...] Architect, Cloud, Security, Telecom Tags: 2010, 网络安全, RSA    Related Posts2010/02/23 -- 软件厂商须承担更多安全责任 &#8211; 从丰田汽车召回事件说起 (2)2010/02/08 -- ENISA发布移动社会网络安全白皮书 (3)2010/02/03 -- [...]</description>
		<content:encoded><![CDATA[<p>[...] Architect, Cloud, Security, Telecom Tags: 2010, 网络安全, RSA    Related Posts2010/02/23 &#8212; 软件厂商须承担更多安全责任 &#8211; 从丰田汽车召回事件说起 (2)2010/02/08 &#8212; ENISA发布移动社会网络安全白皮书 (3)2010/02/03 &#8212; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/comment-page-1/#comment-36505</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Tue, 23 Feb 2010 21:59:25 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=1619#comment-36505</guid>
		<description>该范本可以在此处下载，内容相当丰富： 

http://www.cscic.state.ny.us/resources/documents/Draft-Application-Security-Procurement-Language-V-2.0-February-2010.pdf</description>
		<content:encoded><![CDATA[<p>该范本可以在此处下载，内容相当丰富： </p>
<p><a href="http://www.cscic.state.ny.us/resources/documents/Draft-Application-Security-Procurement-Language-V-2.0-February-2010.pdf" rel="nofollow">http://www.cscic.state.ny.us/resources/documents/Draft-Application-Security-Procurement-Language-V-2.0-February-2010.pdf</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://sbin.cn/blog/2010/02/23/more-responsibility-by-software-vendors/comment-page-1/#comment-36504</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Tue, 23 Feb 2010 21:46:56 +0000</pubDate>
		<guid isPermaLink="false">http://sbin.cn/blog/?p=1619#comment-36504</guid>
		<description>开发了东西就要用。这不，纽约州的CSCIC就要用上了。人家是已开始就计划好了合作的。这个新生事物对于SDLC相关的服务和产品拉升作用还是很大的。

 New York State holds software developers accountable

18 February 2010
The state of New York is proposing language for inclusion in procurement documents that it hopes will help to enforce secure application development practices among suppliers.

The New York State Office of Cyber Security and Critical Infrastructure Coordination (CSCIC) introduced the Application Development Security Procurement Language this month. Heralded as a &quot;living document&quot; by its authors, it is designed to complement the CWE/SANS Top 25 project, which identifies and prioritizes the programming errors most likely to cause security problems for software customers.

The draft procurement language document is intended specifically for custom code development rather than commercial off-the-shelf products. &quot;While these provisions have been drafted for use in a contract for application development, similar language can be incorporated into other procurement documents, including requests for proposals and statements of work,&quot; the document said.

The document provides a template for custom software development contracts. It mandates background checks for software development personnel, adequate training for development teams, and the provision of a single senior information security specialist during the development process.

Vendors should provide written documentation showing proof of secure application development, and should conduct a peer review of all code before it is considered ready for testing, the template says. Written reports should be provided to the purchaser on any security issue identified during the application development lifecycle, and a plan should be established to transfer knowledge to the customer so that the application can be maintained in a production environment.

The template specifically singles out the 25 most dangerous programming errors as identified in the CWE/SANS project, mandating a threat assessment and analysis procedure that covers those flaws.

Other measures mandated by the contract template include identifying the tools used in the development process, along with a set of written secure coding guidelines, documentation of a source code control system, and disclosing all third-party software used in the application.

Not everyone was happy with the idea of tying the procurement language to a broad category of software bugs, however. &quot;I think the idea of linking procurement language to a list of specific bugs as being touted by SANS is counterproductive and silly,&quot; argued Gary McGraw, CEO of application security company Cigital. &quot;Based on my experience as an expert in litigation, my prediction is that there will be zero lawsuits based on this notion and that this list will do nothing to provide safe harbor in the case of insecure software.&quot;</description>
		<content:encoded><![CDATA[<p>开发了东西就要用。这不，纽约州的CSCIC就要用上了。人家是已开始就计划好了合作的。这个新生事物对于SDLC相关的服务和产品拉升作用还是很大的。</p>
<p> New York State holds software developers accountable</p>
<p>18 February 2010<br />
The state of New York is proposing language for inclusion in procurement documents that it hopes will help to enforce secure application development practices among suppliers.</p>
<p>The New York State Office of Cyber Security and Critical Infrastructure Coordination (CSCIC) introduced the Application Development Security Procurement Language this month. Heralded as a &#8220;living document&#8221; by its authors, it is designed to complement the CWE/SANS Top 25 project, which identifies and prioritizes the programming errors most likely to cause security problems for software customers.</p>
<p>The draft procurement language document is intended specifically for custom code development rather than commercial off-the-shelf products. &#8220;While these provisions have been drafted for use in a contract for application development, similar language can be incorporated into other procurement documents, including requests for proposals and statements of work,&#8221; the document said.</p>
<p>The document provides a template for custom software development contracts. It mandates background checks for software development personnel, adequate training for development teams, and the provision of a single senior information security specialist during the development process.</p>
<p>Vendors should provide written documentation showing proof of secure application development, and should conduct a peer review of all code before it is considered ready for testing, the template says. Written reports should be provided to the purchaser on any security issue identified during the application development lifecycle, and a plan should be established to transfer knowledge to the customer so that the application can be maintained in a production environment.</p>
<p>The template specifically singles out the 25 most dangerous programming errors as identified in the CWE/SANS project, mandating a threat assessment and analysis procedure that covers those flaws.</p>
<p>Other measures mandated by the contract template include identifying the tools used in the development process, along with a set of written secure coding guidelines, documentation of a source code control system, and disclosing all third-party software used in the application.</p>
<p>Not everyone was happy with the idea of tying the procurement language to a broad category of software bugs, however. &#8220;I think the idea of linking procurement language to a list of specific bugs as being touted by SANS is counterproductive and silly,&#8221; argued Gary McGraw, CEO of application security company Cigital. &#8220;Based on my experience as an expert in litigation, my prediction is that there will be zero lawsuits based on this notion and that this list will do nothing to provide safe harbor in the case of insecure software.&#8221;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

