Comments
Niklas Bjorkman wrote: Firstly I agree with your conclusion. NewSQL takes the best of the traditional databases and NoSQL databases to combine the benefits of both worlds. I do not agree that NewSQL vendors focus on giving scale-out features to transactional data. The NewSQL market is focusing on giving true ACID support combined with extreme performance, stepping away from the traditional relational structures in databases. A lot of developers appreciate the ease of accessing data using SQL and I think we will see more and more databases supporting standard SQL. As you said - NewSQL databases often maintain the...
Cloud Computing
Conference & Expo
November 2-4, 2009 NYC
Register Today and SAVE !..

2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
In many cases, the end of the year gives you time to step back and take stock of the last 12 months. This is when many of us take a hard look at what worked and what did not, complete performance reviews, and formulate plans for the coming year. For me, it is all of those things plus a time when I u...
SYS-CON.TV
Veracode’s eLearning Program Guides Developers in Creating Secure Applications

Veracode, Inc., the leader in cloud-based application security testing, encourages application developers to take a more proactive role in securing applications as part of a larger call to action to protect companies from vulnerabilities. Each year, companies spend billions of dollars on outsourcing software development, yet very little is spent on security verification, resulting in security breaches caused by software vulnerabilities.

Veracode also aims to limit the amount of security checks companies have to make when purchasing third-party applications by offering to developers a web-based eLearning training program. The online courses provide developers with certification and CPE credits and teach developers secure coding for ASP.NET, J2EE and C/C++. eLearning also aims to help developers measure and track their development progress and comply with ISO regulations and industry standards such as SANS Application Security Procurement Contract Language.

“The simple fact is that if someone wants your intellectual property, they are going to use the software you bought, built or outsourced to get it,” said Chris Eng, vice president of research, Veracode. “We developed these eLearning courses to provide developers with the guidelines and best practices that they should take to ensure the security of their customers.”

Veracode suggests that by following its eLearning development suggestions, developers will be able to:

  1. Protect companies from vulnerabilities. With the vast amount of threats that constantly pressure companies and government, it is important to ensure that the software applications these organizations utilize are completely secure. To certify applications are free of vulnerabilities, several processes must be employed within the Secure Development Lifecycle (SDLC), including testing the application’s security controls at each stage of development. Such tests include static analysis, dynamic analysis or penetration testing.
  2. Preserve data, IP and brand reputation. Some of the most critical application security flaws, including Cross Site Scripting (XSS) and broken authentication, allow for easy exploitation where attackers can completely take over the software, steal data, or prevent the software from working at all. In order to prevent these flaws, security practices must be integrated within the SDLC, and security of internally developed applications must be verified before they are deployed. Additionally, staying on top of patches and software updates can help bring attention to previously undiscovered flaws.
  3. Perform business as usual. During the SDLC, developers must model an application, scan the code, check the quality and ensure that it meets regulations, on top of building a unique and useful application. Automated secure development testing tools help developers adhere to these development steps, while finding and fixing security issues at the same time. Veracode offers these services as well as secure development training so that developers can gain further education and insight into security issues they may have created.

Veracode wants all developers to keep these guidelines in mind when creating applications, as they allow them to detect flaws, test the security features of the applications, and ensure the customer’s data is protected above all else.

About Veracode

Veracode is the only independent provider of cloud-based application intelligence and security verification services. The Veracode platform provides the fastest, most comprehensive solution to improve the security of internally developed, purchased or outsourced software applications and third-party components. By combining patented static, dynamic and manual testing, extensive eLearning capabilities, and advanced application analytics, Veracode enables scalable, policy-driven application risk management programs that help identify and eradicate numerous vulnerabilities by leveraging best-in-class technologies from vulnerability scanning to penetration testing and static code analysis. Veracode delivers unbiased proof of application security to stakeholders across the software supply chain while supporting independent audit and compliance requirements for all applications no matter how they are deployed, via the web, mobile or in the cloud. Veracode works with customers in more than 80 countries worldwide representing Global 2000 brands. For more information, visit www.veracode.com, follow on Twitter: @Veracode or read the Veracode Blog.

About Business Wire
Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

SOA World Latest Stories
Cloud enables SMBs to access new, scalable resources – previously only available to enterprises – in flexible and cost-effective ways. McKinsey’s SMB Cloud Report projects the public cloud market to reach $40-$50 billion by 2015, with SMBs comprising 65% of public cloud spending in 201...
Dell’s board has again asked billionaire Carl Icahn and his buddy Southeastern Asset Management for more information about their proposal to take over the company. Icahn asked Dell for more information after Dell posted its quarterly results last week and Dell flatly said “no.” It...
In the face of rapidly increasing amounts of unstructured data, industry is investing heavily to turn machines into services and connect them to analytics engines that will extract an extraordinary amount of value and unleash a productivity revolution for both businesses and consumers....
Compuware Corporation has announced the convergence of dynaTrace PurePath® Technology and the Gomez Performance Network, creating a powerful User Experience Management (UEM) solution. Compuware now offers a APMaaS solution that provides a complete UEM offering, including real-user, syn...
Fancy that. Dell said Monday that its “current in-house multi-tenant public cloud IaaS will be discontinued in the US in favor of best-in-class partner offerings” that it’ll deliver as a single-source supplier. While it’s preaching the gospel of customer choice, it’s saving badly nee...
Looking to hang with the cool kids, Yahoo CEO Marissa Mayer, swearing “not to screw it up,” is buying Tumblr for a cool $1.1 billion, a big chunk of her $5.4 billion pocketbook since it’s “substantially all” in cash. The New York-based acquisition will remain a separate business with...
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON Featured Whitepapers
ADS BY GOOGLE