<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://website.isecpartners.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>iSEC Partners - </title>
 <link>http://website.isecpartners.com/secure_development_life_cycle_sdlc_services</link>
 <description></description>
 <language>en</language>
<item>
 <title>Automated Application &amp; Source Code Testing</title>
 <link>http://website.isecpartners.com/automated_application_source_code_testing</link>
 <description> &lt;ul&gt;
&lt;li&gt;Use open source static analysis tools to detect use of prohibited libraries or unsafe functions
&lt;li&gt;Use open source static analysis tools to detect the lack of secure libraries like input filtering
&lt;li&gt;Use open source static analysis tools to detect C/C++ memory errors
&lt;li&gt;Use commercial web application scanning tools and filter results to provide relevance
&lt;li&gt;Use commercial source code scanning tools and filter results to provide relevance
&lt;li&gt;Use commercial binary analysis tools and filter results to provide relevance
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Tue, 01 May 2007 04:19:14 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">215 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>SDLC Process Gap Analysis</title>
 <link>http://website.isecpartners.com/sdlc_process_gap_analysis</link>
 <description> &lt;ul&gt;
&lt;li&gt;Analysis of current Threat Modeling Processes
&lt;li&gt;Analysis of current Secure Development Guidelines
&lt;li&gt;Analysis of current negative QA testing in development and QA organizations
&lt;li&gt;Analysis of current Developer Training Initiatives
&lt;li&gt;Recommendations for Automated Application &amp;amp; Source Code Testing
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Tue, 01 May 2007 04:18:40 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">214 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Secure Framework Development</title>
 <link>http://website.isecpartners.com/secure_framework_development</link>
 <description> &lt;p&gt;The &quot;iSEC SecureWeb Framework&quot;&lt;/p&gt;
&lt;p&gt;Pre-created J2EE classes that provide the basis for providing web security services:
&lt;ul&gt;
&lt;li&gt;Input validation classes with common pre-defined types (safe HTML, SSN, credit cards, etc.)
&lt;li&gt;XSRF protection framework, including a token generator and a simple interface to query the “action state” of the client
&lt;li&gt;Output validation framework, perhaps implemented as a servlet or tied to a compositing engine
&lt;li&gt;Secure data-access-layer class, which can wrap JDBC and guarantee prevention of SQL Injection
&lt;li&gt;Security anomaly framework.  A simple framework that can be tuned by the end customer, that collects data and makes it easy to create business rules that detect fraud, such as a single user logging in from multiple geographical locations within a certain period of time.
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Tue, 01 May 2007 04:18:10 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">213 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Developer Training</title>
 <link>http://website.isecpartners.com/developer_training</link>
 <description> &lt;ul&gt;
&lt;li&gt;Improving Software Security through Life Cycle Changes
&lt;li&gt;Web Application Security QA Testing
&lt;li&gt;Application Security Best Practices
&lt;li&gt;Penetration Testing &amp;amp; Binary Analysis
&lt;li&gt;Windows Vista Security for Developers
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Tue, 01 May 2007 04:17:38 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">212 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Custom Protocol and Application Fuzzer Development</title>
 <link>http://website.isecpartners.com/custom_fuzzer_development</link>
 <description> &lt;p&gt;Use valid test data to inject random data into the following input fields:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Event driven inputs.  Usually from a graphical user interface, or possibly from a mechanism in an embedded system.
&lt;li&gt;Character driven inputs.  Files or data streams such as sockets.
&lt;li&gt;Database inputs.  Tabular data, such as relational databases.
&lt;li&gt;Inherited program state such as environment variables
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Tue, 01 May 2007 04:17:11 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">211 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Development/Security Team Staff Augmentation</title>
 <link>http://website.isecpartners.com/development_security_team_staff_augmentation</link>
 <description> &lt;ul&gt;
&lt;li&gt;Standards/procedures/and examples that drive security into engineering and QA
&lt;li&gt;Specific guidelines for avoiding problems found during penetration testing and previous assessments
&lt;li&gt;Standards for measuring applications against the new Secure Development Guidelines
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Tue, 01 May 2007 04:16:43 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">210 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Secure Development Guideline Creation</title>
 <link>http://website.isecpartners.com/secure_development_guideline_creation</link>
 <description> &lt;ul&gt;
&lt;li&gt;Standards/procedures/and examples that drive security into engineering and QA
&lt;li&gt;Specific guidelines for avoiding problems found during penetration testing and previous assessments
&lt;li&gt;Standards for measuring applications against the new Secure Development Guidelines
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Tue, 01 May 2007 04:16:10 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">209 at http://website.isecpartners.com</guid>
</item>
</channel>
</rss>
