BankInfoSecurity.com - Information Security News, Regulations, & Education

Bank Information Security Articles

Application Security Over-Confidence: Facts & Myths Revealed

Credit
Eligible
As a BankInfoSecurity.com annual member, this content can be used toward your membership credits and transcript tracking. Click For More Info
Interview with Fortify Software Founder, CTO Roger Thornton
October 24, 2008 - Tom Field, Editorial Director

This article was originally created for BankInfoSecurity.com, and contains information that should interest our GovInfoSecurity.com readers.
Share

Application security is a key focus of regulatory agencies - ensuring that financial institutions pay as much attention to third-party applications as they do to those they develop and manage in-house. In a recent survey conducted by Information Security Media Group, respondents say they are more confident in their own applications vs. those developed by third-party service providers ... yet, they really don't demonstrate vulnerability assessment or remediation processes to justify any level of confidence.

In this exclusive interview, Roger Thornton, founder and CTO of Fortify Software, discusses the survey results and his own market perspective, discussing:

How the survey results jibe with what he sees from customers;
What's beneath the disconnect between confidence and processes?
What are some of the proactive, cost-effective ways companies can tackle application security?



This article requires a full-access membership (free).
Please login or register to countinue reading.
Username:  
Password:
Remember Username?