Software security : (Record no. 2486)

MARC details
008 - FIXED-LENGTH DATA ELEMENTS--GENERAL INFORMATION
fixed length control field 080309s2006 njua b 001 0 eng
010 ## - LIBRARY OF CONGRESS CONTROL NUMBER
LC control number 2005031598
020 ## - INTERNATIONAL STANDARD BOOK NUMBER
International Standard Book Number 9780321356703
035 ## - SYSTEM CONTROL NUMBER
System control number (Sirsi) u35
040 ## - CATALOGING SOURCE
Original cataloging agency EG-CaNU
Transcribing agency EG-CaNU
Modifying agency EG-CaNU
042 ## - AUTHENTICATION CODE
Authentication code ncode
082 00 - DEWEY DECIMAL CLASSIFICATION NUMBER
Classification number 005.8
Edition number 22
100 1# - MAIN ENTRY--PERSONAL NAME
Personal name McGraw, Gary,
Dates associated with a name 1966-
9 (RLIN) 6907
245 10 - TITLE STATEMENT
Title Software security :
Remainder of title building security in /
Statement of responsibility, etc. Gary McGraw.
260 ## - PUBLICATION, DISTRIBUTION, ETC.
Place of publication, distribution, etc. Upper Saddle River, NJ :
Name of publisher, distributor, etc. Addison-Wesley,
Date of publication, distribution, etc. c2006.
300 ## - PHYSICAL DESCRIPTION
Extent xxxvi, 408 p. :
Other physical details ill. ;
Dimensions 24 cm +
Accompanying material 1 CD-ROM (4 3/4 in.).
490 0# - SERIES STATEMENT
Series statement Addison-Wesley software security series
504 ## - BIBLIOGRAPHY, ETC. NOTE
Bibliography, etc. note Includes bibliographical references and index.
505 0# - FORMATTED CONTENTS NOTE
Formatted contents note Defining a Discipline -- A Risk Management Framework -- Seven Touchpoints for Software Security -- Introduction to Software Security Touchpoints -- Code Review with a Tool -- Architectural Risk Analysis -- Software Penetration Testing -- Risk-based Security Testing -- Abuse Cases -- Software Security meets Security Operations -- Software Security Grows Up -- An Enterprise Software Security Program -- Knowledge for Software Security -- A Taxonomy of Coding Errors -- Annotated Bibliography and References
520 ## - SUMMARY, ETC.
Summary, etc. "When it comes to software security, the devil is in the details. This book tackles the details." --Bruce Schneier, CTO and founder, Counterpane, and author of Beyond Fearand Secrets and Lies "McGraw's book shows you how to make the 'culture of security'part of your development lifecycle." --Howard A. Schmidt, Former White House Cyber Security Advisor "McGraw is leading the charge in software security. His advice is as straightforward as it is actionable. If your business relies on software (and whose doesn't), buy this book and post it up on the lunchroom wall." --Avi Rubin, Director of the NSF ACCURATE Center; Professor, Johns Hopkins University; and coauthor of Firewalls and Internet Security Beginning where the best-selling book Building Secure Softwareleft off, Software Securityteaches you how to put software security into practice.The software security best practices, or touchpoints, described in this book have their basis in good software engineering and involve explicitly pondering security throughout the software development lifecycle. This means knowing and understanding common risks (including implementation bugsand architectural flaws), designing for security, and subjecting all software artifacts to thorough, objective risk analyses and testing. Software Securityis about putting the touchpoints to work for you. Because you can apply these touchpoints to the software artifacts you already produce as you develop software, you can adopt this book's methods without radically changing the way you work. Inside you'll find detailed explanations of Risk management frameworks and processes Code review using static analysis tools Architectural risk analysis Penetration testing Security testing Abuse case development In addition to the touchpoints, Software Securitycovers knowledge management, training and awareness, and enterprise-level software security programs. Now that the world agrees that software security is central to computer security, it is time to put philosophy into practice. Create your own secure development lifecycle by enhancing your existing software development lifecycle with the touchpoints described in this book. Let this expert author show you how to build more secure software by building security in.
596 ## -
-- 1
630 00 - SUBJECT ADDED ENTRY--UNIFORM TITLE
Uniform title CIT.
9 (RLIN) 14
650 #0 - SUBJECT ADDED ENTRY--TOPICAL TERM
Topical term or geographic name entry element Computer security.
9 (RLIN) 6908
Holdings
Withdrawn status Lost status Source of classification or shelving scheme Damaged status Not for loan Home library Current library Shelving location Date acquired Source of acquisition Total Checkouts Full call number Barcode Date last seen Copy number Price effective from Koha item type
    Dewey Decimal Classification     Main library Main library General Stacks 01/26/2020 PURCHASE   005.8 / MC.S 2006 010879 11/24/2019 1 11/24/2019 Books
    Dewey Decimal Classification     Main library Main library General Stacks 01/26/2020 ACA-P   005.8 / MC.S 2006 004635 11/24/2019 6 11/24/2019 Books
    Dewey Decimal Classification     Main library Main library General Stacks 01/26/2020 GIFT   005.8 / MC.S 2006 000286 11/24/2019 8 11/24/2019 Books