<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8954966646386655038.post997520619345174114..comments</id><updated>2009-05-28T14:59:03.859-04:00</updated><category term='IT Security'/><category term='Government 2.0 Security'/><category term='SRF'/><category term='Web Application Security'/><category term='Web 2.0 Security'/><category term='Certification and Accreditation'/><category term='Security Requirements Framework'/><category term='SDLC Security'/><category term='Security Requirements'/><category term='FISMA'/><category term='Secure SDLC'/><category term='Security Resources'/><category term='Security Budget'/><category term='Security Innovation'/><category term='FISMA 2.0'/><category term='Web Application Security 2.0'/><category term='QA Security'/><category term='WAS 2.0'/><title type='text'>Comments on Jason Yuen - "Understanding Information Security": Web Application Security - Part 2: How to Define S...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.jason-yuen.com/feeds/997520619345174114/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html'/><author><name>Jason Yuen</name><uri>http://www.blogger.com/profile/01689037743235268269</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_aVbrSQzZtzw/SXCVKavNwmI/AAAAAAAAAts/ARE75ujHsoM/S220/untitled.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-8577131523496800734</id><published>2009-05-28T14:57:27.055-04:00</published><updated>2009-05-28T14:57:27.055-04:00</updated><title type='text'>I am a Sr. IT Security contractor for the USDA, an...</title><content type='html'>I am a Sr. IT Security contractor for the USDA, and we are an app dev shop. NIST guidance has largely been written as general guidance at the system level. It is very true that current NIST guidance lacks a security perspective at the application layer.  I am authoring and modeling a process and corresponding documentation similar to what you have indicated here; security tasks as they apply to each phase of the SDLC, including the RA and the C&amp;amp;A process.  &lt;br /&gt;&lt;br /&gt;One other large gap I see in my day-to-day work is lack of written policies or even basic methodology on application level data archival procedures and overall application decommissioning process and policies.&lt;br /&gt;&lt;br /&gt;I certainly have my work cut out for me, but change is coming. It&amp;#39;s a very huge, slow moving locomotive on this side of the wall.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/8577131523496800734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/8577131523496800734'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html?showComment=1243537047055#c8577131523496800734' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-997520619345174114' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/997520619345174114' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1672000139'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-3799364597288946345</id><published>2009-02-10T11:48:00.000-05:00</published><updated>2009-02-10T11:48:00.000-05:00</updated><title type='text'>Dan, thanks for the feedback.  I agree that web ap...</title><content type='html'>Dan, thanks for the feedback.  I agree that web application security is a glaring omission from NIST's library.  The commercial side is way ahead of NIST; no surprise at all.  The problem is the lack of collaboration between private and government sectors.  Hopefully, this will change in the Obama Administration.&lt;BR/&gt;&lt;BR/&gt;There is a lack of implementation guidance associated with NIST.  I believe that more tools and useable methodologies need to be created.  Only after they have been integrated into existing processes will we see improvement.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/3799364597288946345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/3799364597288946345'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html?showComment=1234284480000#c3799364597288946345' title=''/><author><name>Jason Yuen</name><uri>http://www.blogger.com/profile/01689037743235268269</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='26' src='http://1.bp.blogspot.com/_aVbrSQzZtzw/SXCVKavNwmI/AAAAAAAAAts/ARE75ujHsoM/S220/untitled.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-997520619345174114' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/997520619345174114' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-520946566'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-448091244267675506</id><published>2009-02-10T11:28:00.000-05:00</published><updated>2009-02-10T11:28:00.000-05:00</updated><title type='text'>You are right that there is a gap between 800-53 a...</title><content type='html'>You are right that there is a gap between 800-53 and SDLC requirements for each project.  It&amp;#39;s an unfortunate reality that NIST has to write it&amp;#39;s guidance for the broadest audience and then encourage end users to properly adapt them for their own needs.&lt;BR/&gt;&lt;BR/&gt;This may be changing slightly in the future.  NIST can&amp;#39;t be too specific when writing documentation but it has changed its focus in the new FISMA documentation (800-37 Rev 1, 800-53 Rev 3, 800-39, etc.) from a C&amp;amp;A cycle to an authorization process tied to the paired Risk Management Framework and Software Development Life Cycle.  This should help ease the requirements for SDLC practitioners to meet authorization process requirements.&lt;BR/&gt;&lt;BR/&gt;If you haven&amp;#39;t looked at NIST SP 800-64 Rev. 2, Security Considerations in the System Development Life Cycle it is worth reviewing.  While not a perfect document it can aid in the process of identifying authorization requirements for projects.  I recently contacted NIST regarding their plans for what I see as a glaring omission in their guidance, web application security.  They are planning on working on guidance for this but as yet are not actively developing the guidance.&lt;BR/&gt;&lt;BR/&gt;For what it&amp;#39;s worth I am currently working on mapping 800-53 to the newly developed OWASP Software Assurance Maturity Model (SAMM) ( http://opensamm.org/Home.html ). So far I am liking some of the design features of this framework and think it may be useful as a C&amp;amp;A/security authorization process tool.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/448091244267675506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/448091244267675506'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html?showComment=1234283280000#c448091244267675506' title=''/><author><name>DanPhilpott</name><uri>http://www.blogger.com/profile/05604476378903988024</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://www.systemsfirm.com/200x200Mev2.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-997520619345174114' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/997520619345174114' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-896710523'/></entry><entry><id>tag:blogger.com,1999:blog-8954966646386655038.post-5993197808809521032</id><published>2009-02-10T11:11:00.000-05:00</published><updated>2009-02-10T11:11:00.000-05:00</updated><title type='text'>Right on. To complement Jason's points, many organ...</title><content type='html'>Right on. To complement Jason's points, many organizations today develop security requirements based on 800-53. That may be sufficient if your goal merely is “compliance readiness”. Else, we can only generate FUNCTIONAL security requirements from 800-53. Others come from the maturity of the organization’s security program. For example, Requirement generated by historical data: An organization has been performing VA/SCA for a period of time and notice that there is trend in most codes (developers are not validating input). This should be added to what Jason called SRF.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/5993197808809521032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8954966646386655038/997520619345174114/comments/default/5993197808809521032'/><link rel='alternate' type='text/html' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html?showComment=1234282260000#c5993197808809521032' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.jason-yuen.com/2009/01/web-application-security-part-2-how-to.html' ref='tag:blogger.com,1999:blog-8954966646386655038.post-997520619345174114' source='http://www.blogger.com/feeds/8954966646386655038/posts/default/997520619345174114' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1014509427'/></entry></feed>
