|
|
||||||
|
||||||
| Index Link To US Private Messages Archive FAQ RSS | ||||||
| Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help. |
Share Thread: & Tags
|
||||
|
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
I have recently opened a software as a service business. I spoke to somebody the other day about having to have my software audited by a security specialist before it would be taken seriously and I was asked to provide an installation of the source code on their server.
I find this rather hard to believe that a professional security audit should ever even have to look at the internal functions of the software at all. I mean... should a website be deemed secure by a code audit? My code is close to ten megabytes. Who in thier right mind would audit such a thing manually. There must be some sort of Xenu style program which can certify your software? In any event. I do believe that such things must exist and I am curious at to what types there are, what levels of certification... basically any information would be useful... James SaaS for small business
__________________
James Weisbrod - programmer |
|
|||||
|
Quote:
Quote:
Quote:
Quote:
Quote:
__________________
James Weisbrod - programmer Last edited by MrGamm; 02-11-2008 at 02:13 PM. |
|
|||
|
Ah so you are saying the program(?) is for use on an intranet only?
If you want a company to certify a program (do we mean script?) as secure then yes they do need to look at the code. They need to see how it handles any data sent to it by users for one thing.
__________________
Carbonize |
|
||||
|
I don't know why I said CERN, I should have said CERT, or more specifically US-CERT, the United States Computer Emergency Response Team, a division of Homeland Security. They are a good source of vulnerability information. As far as I know, they don't provide any auditing, they act more as a clearinghouse for vulnerability information. If a product is commonly used, they log information about vulnerabilities detected and reported by others, along with remediation information.
US Government version: US-CERT: United States Computer Emergency Readiness Team Carnegie Mellon University's version: http://www.cert.gov/ I guess the first thing I really should have asked is what is it that you are trying to demonstrate is secure? Is this software you have written or third party software you install as a service? Is this a standalone application, a network or Internet-capable application, or a web script? And is this software for business use, or for consumers? Also, does the software "touch" personally identifiable information, financial information, or medical information?
__________________
The best way to learn anything, is to question everything. |
|
||||
|
What about the security layer of the web? That is in my view the first step in setting up a site and a web business. It can save you from days and months of work if your site grows large enough.
Scroll down to the heading "Advice for webmasters, especially those who want to set up a new site". Many of the advices given there also applies to webmasters running old sites. It can even be valid on an Intranet, as long as there are different Ip's on the intranet. |
|
||||
|
Quote:
What would be the best option for someone like myself looking for more credibility?
__________________
James Weisbrod - programmer |
|
||||
|
That's the company that sends all of my sites referral spam... what a way to advertise eh?
__________________
James Weisbrod - programmer |
![]() |
|
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| PHP Security | seo111hello | Internet Security Discussion Forum | 0 | 08-02-2007 02:17 AM |
| Security breach | edhan | Internet Security Discussion Forum | 10 | 05-18-2007 03:52 PM |
| Security flaws in XP SP2 | netman4ttm | Internet Security Discussion Forum | 0 | 08-18-2004 07:03 PM |
| Security | shawc | Web Programming Discussion Forum | 1 | 06-01-2004 03:20 PM |
| Certifications and impact on prospective clients/employers? | sajdlz | Graphics & Design Discussion Forum | 3 | 04-16-2004 03:22 PM |
|
WebProWorld |
Advertise |
Contact Us |
About |
Forum Rules |
MVP's |
Archive |
Newsletter Archive |
Top |
WebProNews
WebProWorld is an iEntry, Inc. ® site - © 2009 All Rights Reserved Privacy Policy and Legal iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509 |