Secure Coding mailing list archives

Classification/Enumeration of Software Defect Mitigations


From: "Steven M. Christey" <coley () linus mitre org>
Date: Thu, 21 Oct 2010 13:47:06 -0400 (EDT)


All,

Both WASC and the MITRE CWE team have begun exploring the feasibility of enumerating or classifying the types of mitigations that are used to fix software defects/weaknesses. Does anybody know of such work in this area? (We can draw from sources such as McGraw/Viega "Building Secure Software," and 'indirect' sources such as ESAPI, but I was wondering if there was something that was a little more focused on mitigations.)

CWE status:

http://www.webappsec.org/lists/websecurity/archive/2010-10/msg00065.html

WASC status:

http://www.webappsec.org/lists/websecurity/archive/2010-10/msg00066.html



Thanks,
Steve
_______________________________________________
Secure Coding mailing list (SC-L) SC-L () securecoding org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates
_______________________________________________


Current thread: