<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Application Security: A Tool Cannot Solve What Fundamentally is a Process Problem</title>
	<atom:link href="http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/</link>
	<description>A Member of the Gartner Blog Network</description>
	<lastBuildDate>Thu, 09 Feb 2012 23:32:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
	<item>
		<title>By: More Application Security Goodness From OWASP</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-1853</link>
		<dc:creator>More Application Security Goodness From OWASP</dc:creator>
		<pubDate>Thu, 14 Jan 2010 14:13:05 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-1853</guid>
		<description>[...] the beginning. Many of the clients I talk with are highly focused on the ‘produce’ part – improving their development processes to ensure that more secure code is produced and that security testing is incorporated in the [...]</description>
		<content:encoded><![CDATA[<p>[...] the beginning. Many of the clients I talk with are highly focused on the ‘produce’ part – improving their development processes to ensure that more secure code is produced and that security testing is incorporated in the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Thought for Thursday: DLP Should be a Process, not a Product</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-624</link>
		<dc:creator>Security Thought for Thursday: DLP Should be a Process, not a Product</dc:creator>
		<pubDate>Thu, 10 Sep 2009 22:28:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-624</guid>
		<description>[...] one of the DLP vendors such as McAfee, Symantec, EMC/RSA and so on. Much like I talked about in this post on application security, a product cannot solve what first and foremost is a process problem. The [...]</description>
		<content:encoded><![CDATA[<p>[...] one of the DLP vendors such as McAfee, Symantec, EMC/RSA and so on. Much like I talked about in this post on application security, a product cannot solve what first and foremost is a process problem. The [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Byte Code Analysis is not the same as Binary Analysis</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-427</link>
		<dc:creator>Byte Code Analysis is not the same as Binary Analysis</dc:creator>
		<pubDate>Fri, 24 Jul 2009 18:28:59 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-427</guid>
		<description>[...] posted many times on the importance of application security. Recently, my colleague Joseph Feiman and I published a magic quadrant for static application [...]</description>
		<content:encoded><![CDATA[<p>[...] posted many times on the importance of application security. Recently, my colleague Joseph Feiman and I published a magic quadrant for static application [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-294</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sat, 13 Jun 2009 14:20:07 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-294</guid>
		<description>I am surprised that the research didn&#039;t contain additional guidance such as referring readers to organizations such as OWASP. Would be curious to know why this was left out?</description>
		<content:encoded><![CDATA[<p>I am surprised that the research didn&#8217;t contain additional guidance such as referring readers to organizations such as OWASP. Would be curious to know why this was left out?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Beware New Malware in Web Apps &#124; Computer Security</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-115</link>
		<dc:creator>Beware New Malware in Web Apps &#124; Computer Security</dc:creator>
		<pubDate>Tue, 14 Apr 2009 19:50:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-115</guid>
		<description>[...] vendors aren&#8217;t ready either. It&#8217;s pretty simple. If we don&#8217;t proactively start efforts now to produce more secure applications and demand the same from our software providers, the bad guys will find the vulnerabilities for [...]</description>
		<content:encoded><![CDATA[<p>[...] vendors aren&#8217;t ready either. It&#8217;s pretty simple. If we don&#8217;t proactively start efforts now to produce more secure applications and demand the same from our software providers, the bad guys will find the vulnerabilities for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shrinking Budgets: Application Security Tools vs Process Tradeoff &#171; noFUD - No Fear Uncertainty or Doubt</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-105</link>
		<dc:creator>Shrinking Budgets: Application Security Tools vs Process Tradeoff &#171; noFUD - No Fear Uncertainty or Doubt</dc:creator>
		<pubDate>Fri, 10 Apr 2009 19:44:33 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-105</guid>
		<description>[...] is given to how to integrate this in existing into development lifecycles. Application security is fundamentally a process problem and you can’t solve it just by using [...]</description>
		<content:encoded><![CDATA[<p>[...] is given to how to integrate this in existing into development lifecycles. Application security is fundamentally a process problem and you can’t solve it just by using [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neil MacDonald</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-37</link>
		<dc:creator>Neil MacDonald</dc:creator>
		<pubDate>Tue, 17 Mar 2009 00:12:25 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-37</guid>
		<description>Thanks! 

We&#039;ve been talking about building more secure applications for years. And talking. And talking. But, there&#039;s some hope. You are right - we&#039;ve come a long way in understanding the problem. We&#039;ve got several successful companies that we can point to to start to understand the best practices. 

That&#039;s why I like the study cited in my post above from Fortify and Cigital. It provides at least a framework for starting the discussion. Even if you have started, you could use the study to compare to what you are doing and see what might be missing.</description>
		<content:encoded><![CDATA[<p>Thanks! </p>
<p>We&#8217;ve been talking about building more secure applications for years. And talking. And talking. But, there&#8217;s some hope. You are right &#8211; we&#8217;ve come a long way in understanding the problem. We&#8217;ve got several successful companies that we can point to to start to understand the best practices. </p>
<p>That&#8217;s why I like the study cited in my post above from Fortify and Cigital. It provides at least a framework for starting the discussion. Even if you have started, you could use the study to compare to what you are doing and see what might be missing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashish Popli</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-34</link>
		<dc:creator>Ashish Popli</dc:creator>
		<pubDate>Mon, 16 Mar 2009 17:08:29 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-34</guid>
		<description>This is a great post!

After several years of working in application security domain and reading this post just by chance, I felt a lot of data points are nicely  amalgamated.

I am happy that we have come a long way in understanding the problem - the first step in solving it.</description>
		<content:encoded><![CDATA[<p>This is a great post!</p>
<p>After several years of working in application security domain and reading this post just by chance, I felt a lot of data points are nicely  amalgamated.</p>
<p>I am happy that we have come a long way in understanding the problem &#8211; the first step in solving it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yet another big company with SQL Injection problems (British Telecom) &#124; N-Stalker Web Security Community</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-33</link>
		<dc:creator>Yet another big company with SQL Injection problems (British Telecom) &#124; N-Stalker Web Security Community</dc:creator>
		<pubDate>Fri, 13 Mar 2009 23:59:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-33</guid>
		<description>[...] good post that we read today really fit this problem: &#8220;Application Security: A Tool Cannot Solve What Fundamentally is a Process Problem&#8220;  that simply agrees with that. Companies aren&#8217;t making their home work: scanning [...]</description>
		<content:encoded><![CDATA[<p>[...] good post that we read today really fit this problem: &#8220;Application Security: A Tool Cannot Solve What Fundamentally is a Process Problem&#8220;  that simply agrees with that. Companies aren&#8217;t making their home work: scanning [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mandeep Khera</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-30</link>
		<dc:creator>Mandeep Khera</dc:creator>
		<pubDate>Fri, 13 Mar 2009 03:38:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-30</guid>
		<description>Neil

I couldn&#039;t agree with you  more. As we have talked before a few times  , throwing just the technology at a problem is a bad idea. Without a sound process, all automation attempts can fail regardless of whether it&#039;s ERP, App Security, or any other business process. Process defines the clear path to your goal, automation gets you there faster than manual efforts. 

Thanks!</description>
		<content:encoded><![CDATA[<p>Neil</p>
<p>I couldn&#8217;t agree with you  more. As we have talked before a few times  , throwing just the technology at a problem is a bad idea. Without a sound process, all automation attempts can fail regardless of whether it&#8217;s ERP, App Security, or any other business process. Process defines the clear path to your goal, automation gets you there faster than manual efforts. </p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

