<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Application Security: A Tool Cannot Solve What Fundamentally is a Process Problem</title>
	<atom:link href="http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/</link>
	<description>A Member of the Gartner Blog Network</description>
	<lastBuildDate>Fri, 13 Nov 2009 14:19:22 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Security Thought for Thursday: DLP Should be a Process, not a Product</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-624</link>
		<dc:creator>Security Thought for Thursday: DLP Should be a Process, not a Product</dc:creator>
		<pubDate>Thu, 10 Sep 2009 22:28:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-624</guid>
		<description>[...] one of the DLP vendors such as McAfee, Symantec, EMC/RSA and so on. Much like I talked about in this post on application security, a product cannot solve what first and foremost is a process problem. The [...]</description>
		<content:encoded><![CDATA[<p>[...] one of the DLP vendors such as McAfee, Symantec, EMC/RSA and so on. Much like I talked about in this post on application security, a product cannot solve what first and foremost is a process problem. The [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Byte Code Analysis is not the same as Binary Analysis</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-427</link>
		<dc:creator>Byte Code Analysis is not the same as Binary Analysis</dc:creator>
		<pubDate>Fri, 24 Jul 2009 18:28:59 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-427</guid>
		<description>[...] posted many times on the importance of application security. Recently, my colleague Joseph Feiman and I published a magic quadrant for static application [...]</description>
		<content:encoded><![CDATA[<p>[...] posted many times on the importance of application security. Recently, my colleague Joseph Feiman and I published a magic quadrant for static application [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-294</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sat, 13 Jun 2009 14:20:07 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-294</guid>
		<description>I am surprised that the research didn&#039;t contain additional guidance such as referring readers to organizations such as OWASP. Would be curious to know why this was left out?</description>
		<content:encoded><![CDATA[<p>I am surprised that the research didn&#8217;t contain additional guidance such as referring readers to organizations such as OWASP. Would be curious to know why this was left out?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Beware New Malware in Web Apps &#124; Computer Security</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-115</link>
		<dc:creator>Beware New Malware in Web Apps &#124; Computer Security</dc:creator>
		<pubDate>Tue, 14 Apr 2009 19:50:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-115</guid>
		<description>[...] vendors aren&#8217;t ready either. It&#8217;s pretty simple. If we don&#8217;t proactively start efforts now to produce more secure applications and demand the same from our software providers, the bad guys will find the vulnerabilities for [...]</description>
		<content:encoded><![CDATA[<p>[...] vendors aren&#8217;t ready either. It&#8217;s pretty simple. If we don&#8217;t proactively start efforts now to produce more secure applications and demand the same from our software providers, the bad guys will find the vulnerabilities for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shrinking Budgets: Application Security Tools vs Process Tradeoff &#171; noFUD - No Fear Uncertainty or Doubt</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-105</link>
		<dc:creator>Shrinking Budgets: Application Security Tools vs Process Tradeoff &#171; noFUD - No Fear Uncertainty or Doubt</dc:creator>
		<pubDate>Fri, 10 Apr 2009 19:44:33 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-105</guid>
		<description>[...] is given to how to integrate this in existing into development lifecycles. Application security is fundamentally a process problem and you can’t solve it just by using [...]</description>
		<content:encoded><![CDATA[<p>[...] is given to how to integrate this in existing into development lifecycles. Application security is fundamentally a process problem and you can’t solve it just by using [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neil MacDonald</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-37</link>
		<dc:creator>Neil MacDonald</dc:creator>
		<pubDate>Tue, 17 Mar 2009 00:12:25 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-37</guid>
		<description>Thanks! 

We&#039;ve been talking about building more secure applications for years. And talking. And talking. But, there&#039;s some hope. You are right - we&#039;ve come a long way in understanding the problem. We&#039;ve got several successful companies that we can point to to start to understand the best practices. 

That&#039;s why I like the study cited in my post above from Fortify and Cigital. It provides at least a framework for starting the discussion. Even if you have started, you could use the study to compare to what you are doing and see what might be missing.</description>
		<content:encoded><![CDATA[<p>Thanks! </p>
<p>We&#8217;ve been talking about building more secure applications for years. And talking. And talking. But, there&#8217;s some hope. You are right &#8211; we&#8217;ve come a long way in understanding the problem. We&#8217;ve got several successful companies that we can point to to start to understand the best practices. </p>
<p>That&#8217;s why I like the study cited in my post above from Fortify and Cigital. It provides at least a framework for starting the discussion. Even if you have started, you could use the study to compare to what you are doing and see what might be missing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashish Popli</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-34</link>
		<dc:creator>Ashish Popli</dc:creator>
		<pubDate>Mon, 16 Mar 2009 17:08:29 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-34</guid>
		<description>This is a great post!

After several years of working in application security domain and reading this post just by chance, I felt a lot of data points are nicely  amalgamated.

I am happy that we have come a long way in understanding the problem - the first step in solving it.</description>
		<content:encoded><![CDATA[<p>This is a great post!</p>
<p>After several years of working in application security domain and reading this post just by chance, I felt a lot of data points are nicely  amalgamated.</p>
<p>I am happy that we have come a long way in understanding the problem &#8211; the first step in solving it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yet another big company with SQL Injection problems (British Telecom) &#124; N-Stalker Web Security Community</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-33</link>
		<dc:creator>Yet another big company with SQL Injection problems (British Telecom) &#124; N-Stalker Web Security Community</dc:creator>
		<pubDate>Fri, 13 Mar 2009 23:59:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-33</guid>
		<description>[...] good post that we read today really fit this problem: &#8220;Application Security: A Tool Cannot Solve What Fundamentally is a Process Problem&#8220;  that simply agrees with that. Companies aren&#8217;t making their home work: scanning [...]</description>
		<content:encoded><![CDATA[<p>[...] good post that we read today really fit this problem: &#8220;Application Security: A Tool Cannot Solve What Fundamentally is a Process Problem&#8220;  that simply agrees with that. Companies aren&#8217;t making their home work: scanning [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mandeep Khera</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-30</link>
		<dc:creator>Mandeep Khera</dc:creator>
		<pubDate>Fri, 13 Mar 2009 03:38:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-30</guid>
		<description>Neil

I couldn&#039;t agree with you  more. As we have talked before a few times  , throwing just the technology at a problem is a bad idea. Without a sound process, all automation attempts can fail regardless of whether it&#039;s ERP, App Security, or any other business process. Process defines the clear path to your goal, automation gets you there faster than manual efforts. 

Thanks!</description>
		<content:encoded><![CDATA[<p>Neil</p>
<p>I couldn&#8217;t agree with you  more. As we have talked before a few times  , throwing just the technology at a problem is a bad idea. Without a sound process, all automation attempts can fail regardless of whether it&#8217;s ERP, App Security, or any other business process. Process defines the clear path to your goal, automation gets you there faster than manual efforts. </p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack Danahy</title>
		<link>http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/comment-page-1/#comment-29</link>
		<dc:creator>Jack Danahy</dc:creator>
		<pubDate>Thu, 12 Mar 2009 15:55:03 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2009/03/07/application-security-a-tool-cannot-solve-what-fundamentally-is-a-process-problem/#comment-29</guid>
		<description>I support Neil&#039;s conclusion entirely.

In a recent trip to Dallas, I met with two very different organizations in this area.  One had taken the time to first think about their process and their people, prior to looking for products to solve the problem.  The second was completely focused on the product accquistion, allowing the urgency of their interest in the space to dominate their thinking, and causing them to delay their planning for the reality of the ultimate roll-out and return on investment.  I hope that they can be successful, but it is far from assured.

I hope that people take Neil&#039;s recommendation to heart.

For a supporting discussion of the same topic, take a look at my post &quot;Five Rules to Saving Money by Avoiding Security Shelfware&quot; at :  http://suitablesecurity.blogspot.com

Jack</description>
		<content:encoded><![CDATA[<p>I support Neil&#8217;s conclusion entirely.</p>
<p>In a recent trip to Dallas, I met with two very different organizations in this area.  One had taken the time to first think about their process and their people, prior to looking for products to solve the problem.  The second was completely focused on the product accquistion, allowing the urgency of their interest in the space to dominate their thinking, and causing them to delay their planning for the reality of the ultimate roll-out and return on investment.  I hope that they can be successful, but it is far from assured.</p>
<p>I hope that people take Neil&#8217;s recommendation to heart.</p>
<p>For a supporting discussion of the same topic, take a look at my post &#8220;Five Rules to Saving Money by Avoiding Security Shelfware&#8221; at :  <a href="http://suitablesecurity.blogspot.com" rel="nofollow">http://suitablesecurity.blogspot.com</a></p>
<p>Jack</p>
]]></content:encoded>
	</item>
</channel>
</rss>
