Yemeni Political Transition: Un Secretary Genera... » The United Nations Secretary-General, Ban Ki-moon has launched inclusive consultations aimed at rest... Police move quickly to douse fears over unexploded... » Police officers from Brent have continued to liaise with local residents and businesses as work cont... Cloud demonstrates a silver lining for Financ... » Manchester:  A shift in thinking across the financial services sector, embracing the advantages of p... Security experts plan new strategies to curtail s... » Woking, Surrey: "An acceptance that security will be breached in most organisations will mean some c... Sniffing and tracking wearable tech and smartpho... » Researchers at Context Information Security have demonstrated how easy it is to monitor and record B... Cryptzone launches revamped EMEA Channel Partner P... » London UK: Cryptzone has announced the details of its revamped EMEA channel partner program as the d... Fortune 100 social media accounts struggle to comp... » LONDON, UK: Proofpoint, Inc. has released the first social media study that exposes the compliance v... 24-hour ‘Groby Challenge’ to raise money for inj... » On Friday 29 May the village of Groby in Leicestershire will see representatives from Groby Village ... Pest Management standard published » BSI, the business standards company, has recently published the first European standard on pest mana... KEMP delivers new high performance ADCs to balance... » KEMP Technologies has announced a new family of high performance Application Delivery Controllers (A...

CLICK HERE TO

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

UK: Ahead of a revamped DEV522: Defending Web Applications Security Essentials course which will debut at SANS Dubai this October, course tutor Jason Lam urges organisations within the region to take a closer look at secure development processes. “Many organisations in the region are increasingly utilising outsourced development to partners in India and China which offer many cost benefits,” explains Lam, “The level of coding is often very good but organisations must still control risk and mandate the security level and defensive requirements – the reality is that you can’t outsource risk.”

 

Lam suggests that organisations have not developed enough skill in defining and managing best practice for working with external development contractors. “The customer must always draft the development framework and then be prepared to test that the application is secure and meets the agreed standard.”

Although a valuable tool, Lam suggests that automated methods for testing the security of applications should not be the only method, “What these tools can’t test for are vulnerabilities that have emerged during development due to poorly defined logic or processes,” says Lam, “Automated testing tools can be effective in finding vulnerabilities such as SQL injection and XSS once the entry points to the web site are located, often times, the testing tools miss a large portion of the site and are totally ignorant to the business logic issues within the website.”

The DEV522 course has been updated extensively to cover some of the major trends in software development and Lam points to the HTML 5 sections as a great example of why organisations have to continually help staff to maintain a relevant skill set. “HTML5 is an incredibly powerful tool set that in many way makes for an easier and more efficient development framework,” says Lam, “But it also has a different set of requirements in terms of secure development which need to be understood and considered to create secure applications. Like all systems, there are also unique weaknesses and potential vulnerabilities when working within HTML 5 and the course will show how developers can mitigate these risks.”

Alongside his role as a certified SANS instructor, Lam heads up cyber defence at a large global financial organisation in Canada and holds a BA in computer science from York University in Toronto, Ontario, as well as the CISSP, GCIA, GCFW, GCUX, GCWN, and GCIH certifications.

The expert also points out that the OWASP Top 10 list of vulnerabilities are still out in the wild and that even with advances in modern programming languages with built in defence mechanisms, there is still a lack of core security skills at the most fundamental level. “Most university courses are still missing out on teaching secure development techniques as an active part of the curriculum,” he points out, “and this imbalance means that organisations must start from the assumption that developers, either in-house or outsourced, may not have these skills by default.”

Lam suggests that every project leader needs to have a baseline set of security skills to allow the sensible creation of a best practice process, “However, there is no universal standard – each organisation needs to build a method that suits its own environment and working practices.”

SANS Dubai 2013, the Gulf Region's largest InfoSec training event will be held at the Hilton Dubai Jumeirah resort from October 26th till November 7th 2013. Alongside Dev522, the event will also host SANS Security 504: Hacker Techniques, Exploits & Incident Handling taught by James Lyne and the popular SEC542: Web App Penetration Testing and Ethical Hacking course with Dave Shackleford. The event is rounded off by FOR408: Computer Forensic Investigations - Windows In-Depth, taught by Jess Garcia