For Application Development & Program Management Professionals (Length: 15 pages)

March 10, 2009

Use Threat Modeling To Develop More-Secure Applications

The Payoff Is High For Avoiding Security Vulnerabilities During Development

by Mike Gualtieri

with Mike Gilpin, Chenxi Wang, Ph.D., Wallis Yu


Executive Summary (This is a document excerpt)

Many application architects and developers don't know enough about developing secure applications. Worse, many of them have a naive notion of application security that lulls them into thinking they have all the security bases covered. This means that security and risk professionals often uncover security vulnerabilities late in the software development life cycle — or, heaven forbid, the vulnerabilities become a feature story on the front page of The Wall Street Journal. The later security holes are detected, the more it costs to plug them. The solution is to avoid security vulnerabilities as early as possible by employing principles of secure design such as threat modeling. Developers and auditors can use code analysis tools such as Coverity Prevent, Fortify 360, and Ounce Labs' Ounce to uncover familiar vulnerabilities such as buffer overflows and SQL injection. But these tools are only part of the solution; developers should also do threat modeling on new and existing applications. Microsoft's SDL Threat Modeling Tool is a unique new tool that helps developers identify and mitigate security risks to make applications more secure from the get-go.

Buy Risk-Free

Download and print PDF immediately. Price: US $1749

Our Money-Back Guarantee: If you are not completely satisfied, return it for a full refund within three weeks of your online purchase.

Already a Forrester Client?
Log in to read this document.

Add to cart

TABLE OF CONTENTS

NOTES & RESOURCES

itemYou Must Develop More-Secure Applications

itemThreat Modeling Is Essential To Making Applications Secure

itemSpeed Threat Modeling With A Tool-Enabled, Four-Step Process

recommendations

itemModel Threats To Develop More-Secure Applications

WHAT IT MEANS

itemMore Threat Modeling Tools Will Help Developers Take The Lead

Forrester interviewed Cigital, Coverity, Microsoft, Scorpion Software, and other experts in application development security.

Related Research Documents

itemInquiry Spotlight: Application Security, Q4 2008

October 17, 2008

itemManaging Application Security From Beginning To End

August 14, 2007

Find Documents In Related Categories

This document falls under the following categories. Click on a link below to find similar documents.

Analyst: Mike Gualtieri
Technology: Application Security, Security & Risk, Security Operations
Geography: Asia Pacific, Europe, North America

Archived Teleconference:
Event Processing Breaks Out; These Are The Top Products
Original air date: Thursday, August 13, 2009
corner border corner
Ratings and Comments
NOT YET RATED
corner border corner