Three Preparations For A Software Security Assessment

If your development group or organization has an upcoming software security assessment scheduled here are three things to think about while making your preparations. Assets (Dependencies) – Be sure that you have all application assets together that are needed to build the application. If the assessment will be done in your test/development area then this will […]

Read more
Coveros and Fortify Software Partner on Application Security

Coveros selected by Fortify as Preferred Consulting Partner Herndon, Va., August 26, 2009 — Coveros, Inc., a company that helps organizations accelerate the delivery of secure, reliable software, today announced it has been selected by Fortify Software as a Preferred Consulting Partner. Under the terms of the partnership, Coveros will recommend Fortify’s Software Security Assurance […]

Read more
Sonar for code quality

Sonar is a tool to analyze and visualize code quality in Java projects. It isn’t a static code analysis tool itself, rather it uses a number of open source tools to analyze the code, then Sonar gathers the metrics. Its strength is in providing a dashboard, trend reports, and drill downs to help visualize the state […]

Read more
Three – A Very Special Number

I believe that three is a very special number. I can think of (at least) three things to support my belief: H2O Liquid, Solid, Gas It is what it is, although it exists in three different forms (water, ice, steam). Spacial Dimensions Height, Width, Depth These are used to describe the 3D world in which we […]

Read more
Three Common Coding Omissions

I have worked as part of a team going into client locations and performing software security assessments. While analyzing the findings of these assessments I have seen a common set of coding omissions that, if implemented, would eliminate the majority of the vulnerabilities that were identified. A brief description of each follows. Input Validation Data […]

Read more
Coveros Named a Finalist for Hottest Bootstrap Company by NVTC

Company Recognized as One of Northern Virginia’s Emerging Stars Herndon, Va., June 26, 2009 — Coveros, Inc., a company that helps organizations accelerate the delivery of secure and reliable software, today announced it has been selected as a finalist in the Hottest Bootstrap category of the Northern Virginia Technology Council (NVTC) Hot Ticket Awards. The […]

Read more
Transitioning to Agile

At the 2009 Better Software Conference, Jeff Payne delivered this presentation about what to do and what NOT to do when transitioning to Agile. The presentation also talks about the advantages and challenges in that transition. Better Software — Agile Transition

Read more
iHuddle

Daily stand up meetings, or huddles as Scrum calls them, are a core Agile practice that promotes communication and project visibility. They are an invaluable tool for identifying but not solving problems. So what do you do when a part of your team is in another city or continent? You iHuddle. Er, ah, what is […]

Read more
Cost effective security testing: test early, test often

  I was recently reminiscing with a friend regarding some of the hairier projects we had worked on together. One in particular stood out. It was for a financial services company. While the project itself had no specific security requirements, the company decided toward the end of the project that it needed to have security […]

Read more
X