Ramon Krikken

A member of the Gartner Blog Network

Entries Tagged as 'application security'


Creating an Appetizing and Healthy Application Security Diet

by Ramon Krikken  |  July 2, 2012  |  Comments Off

In the recent month I’ve done both a Security Summit talk and a webinar about application security. The gist of the presentations – at least what I wanted customers to take away – is that we can’t sell application security to developers and architects by perpetuating the train-test-fix cycle of pain. It feels, though, like [...]

Comments Off

Category: Applications Security     Tags: , , , , ,

Encryption Won’t Always Save You, but it Certainly Will Cost You

by Ramon Krikken  |  June 20, 2012  |  1 Comment

I have encryption on my mind again a lot lately. It certainly has something to do with work in progress for presentations I’m giving at our Catalyst 2012 conference (“Protecting Data in the Public Cloud: Encryption, Obfuscation, or Snake Oil?” and “Scenarios: Encryption, Tokenization, Anonymization, or None of the Above”). But it’s also because I’m [...]

1 Comment »

Category: Security     Tags: , , , , , , , ,

The “Application Layer” – a Important Matter of Perspective

by Ramon Krikken  |  April 25, 2012  |  Comments Off

Security at the application-layer is getting ever more attention due to the large number of vulnerabilities that keep popping up in off-the-shelf and home-built software (although, in my opinion, it is still not getting enough attention). Aside from expanding security activities in the SDLC, we’re seeing calls for – amongst things – application monitoring. But [...]

Comments Off

Category: Applications Security     Tags: , ,

What is the Right Level of Developer Security Training?

by Ramon Krikken  |  April 19, 2012  |  Comments Off

We’re always working on updating our software security / application security coverage, and the time has come to spend a few months on gathering new information for the application security program guidance document. To make it more than “here’s another general maturity model – do everything it says,” I’m looking for what makes and breaks [...]

Comments Off

Category: Security     Tags: , , , , ,