<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Akshay on the business of security : Application Security</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx</link><description>Tags: Application Security</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Shrinking Budgets: Application Security Tools vs Process Tradeoff</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2009/04/29/shrinking-budgets-application-security-tools-vs-process-tradeoff.aspx</link><pubDate>Thu, 30 Apr 2009 08:25:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9578566</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/9578566.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=9578566</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=9578566</wfw:comment><description>An all too familiar scene repeated itself two weeks ago. My good friend &amp;amp; CISO of a mid-sized technology company, lets call him Alok, went into a budget planning meeting and came out as a shadow of his former self. To be more precise a 85% version...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2009/04/29/shrinking-budgets-application-security-tools-vs-process-tradeoff.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9578566" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Tools/default.aspx">Tools</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>The InfoSec X Prize: Fundamental Change Through Competition</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2009/01/22/the-infosec-x-prize-fundamental-change-through-competition.aspx</link><pubDate>Fri, 23 Jan 2009 01:06:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9371057</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/9371057.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=9371057</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=9371057</wfw:comment><description>Today I had a thought provoking conversation with Dr. Peter Diamandis , Chairman and CEO of Zero Gravity Corporation &amp;amp; X Prize Foundation, on radical &amp;amp; fundamental change. Change that advances the status quo rather than relying on incremental...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2009/01/22/the-infosec-x-prize-fundamental-change-through-competition.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9371057" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Business/default.aspx">Business</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Leadership/default.aspx">Leadership</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Innovation/default.aspx">Innovation</category></item><item><title>Application Security Development Lifecycle 5A: Is Threat Modeling Right For You?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx</link><pubDate>Wed, 11 Jun 2008 18:06:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8590916</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8590916.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8590916</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8590916</wfw:comment><description>Several enterprises are increasingly investing time and money in building application security tasks into their existing SDLCs. Some of them have also reached the conclusion that proactive approaches , like threat modeling, have more ROI than reactive...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8590916" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Business/default.aspx">Business</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Governance+Series/default.aspx">Governance Series</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>OWASP Conference Update</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/08/owasp-conference-update.aspx</link><pubDate>Mon, 09 Jun 2008 04:42:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8582715</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8582715.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8582715</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8582715</wfw:comment><description>I will be presenting at the OWASP conference in Denver, CO this Tuesday, June 10th. The presentation will focus on the value that organizations especially ISVs can derive from threat modeling of line of business applications. For some time now, I've been...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/08/owasp-conference-update.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8582715" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Conference/default.aspx">Conference</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Speaking/default.aspx">Speaking</category></item><item><title>Application Security development Lifecycle 4: Finding the right security talent</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/01/application-security-development-lifecycle-4-finding-the-right-security-talent.aspx</link><pubDate>Sun, 01 Jun 2008 22:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8551936</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8551936.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8551936</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8551936</wfw:comment><description>After about an hour of nodding his head vigorously in agreement with some of our lessons learnt, my customer jumped up and exclaimed, " Great!! Now where do I find another 20 people like these?" (pointing to my team)... I thought about it a while and...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/01/application-security-development-lifecycle-4-finding-the-right-security-talent.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8551936" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Education/default.aspx">Education</category></item><item><title>How Microsoft IT does Secure Application Development: Webcast</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/27/how-microsoft-it-does-secure-application-development-webcast.aspx</link><pubDate>Tue, 27 May 2008 19:20:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8554014</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8554014.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8554014</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8554014</wfw:comment><description>Technorati Tags: Conference , SDLC , SDL , IT , ISV I will be discussing Microsoft IT's approach to secure application development, with a special focus on how we integrate security into the IT line-of-business SDLC, in a webcast this Thursday May 29th....(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/27/how-microsoft-it-does-secure-application-development-webcast.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8554014" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Conference/default.aspx">Conference</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Speaking/default.aspx">Speaking</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Increase the TCO, kill the project: An ad-hoc analogy</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/14/increase-the-tco-kill-the-project-an-ad-hoc-analogy.aspx</link><pubDate>Wed, 14 May 2008 19:07:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8483470</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8483470.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8483470</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8483470</wfw:comment><description>The other day I was subject to the assertion that the only asset an IT security organizations should care about is data. Now being in the application security business, I should have been jumping at this validation but couldn't. The IT security org needs...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/14/increase-the-tco-kill-the-project-an-ad-hoc-analogy.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8483470" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Financial+Analysis/default.aspx">Financial Analysis</category></item><item><title>Application Security Development Lifecycle 3: Funding Models</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/08/application-security-governance-3-funding-models.aspx</link><pubDate>Thu, 08 May 2008 21:48:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8469533</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8469533.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8469533</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8469533</wfw:comment><description>Now that you've decided (or battled) to set up an application security program you realize that it actually needs to get funded. You must master the art of delicately drinking from the fire hydrant of line of business applications. In my experience helping...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/08/application-security-governance-3-funding-models.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8469533" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Front Range web application security summit in Denver</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/01/front-range-web-application-security-summit-in-denver.aspx</link><pubDate>Thu, 01 May 2008 20:11:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8445348</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8445348.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8445348</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8445348</wfw:comment><description>I will be speaking at the Front Range OWASP Conference (FROCo8) in Denver on June 10th. The focus of the conference to share the experiences that the speakers had around solving technical and management issues surrounding application security. I'll be...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/01/front-range-web-application-security-summit-in-denver.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8445348" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Conference/default.aspx">Conference</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Speaking/default.aspx">Speaking</category></item><item><title>Application Security Development Lifecycle 2: Mandatory or Not?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/22/application-security-governance-2-mandatory-or-not.aspx</link><pubDate>Tue, 22 Apr 2008 10:36:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8416189</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8416189.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8416189</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8416189</wfw:comment><description>Large enterprises tend to have a number of line of business (LOB) applications supporting business operations. It becomes key for an application security program to help the organization manage the risk posed by each of these applications. Applications...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/22/application-security-governance-2-mandatory-or-not.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8416189" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security Development Lifecycle 1: Understanding your portfolio</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/07/application-security-governance-1-understanding-your-portfolio.aspx</link><pubDate>Mon, 07 Apr 2008 19:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6397859</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/6397859.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=6397859</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=6397859</wfw:comment><description>"How many applications do you have and what do they do?" It seems simple enough yet this questions seems to perplex many a smart mind. Having posed it to over a hundred and fifty CSO/CIOs over the last year, I have rarely received a clear answer that...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/07/application-security-governance-1-understanding-your-portfolio.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=6397859" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security Development Lifecycle Series</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/02/application-security-governance-series.aspx</link><pubDate>Thu, 03 Apr 2008 09:54:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6395326</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/6395326.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=6395326</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=6395326</wfw:comment><description>After several requests from customers about information on how enterprise class application security programs are set up, I am writing a series of blogs about my experience helping some large enterprises set up application security teams similar to the...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/02/application-security-governance-series.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=6395326" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Encounters making an Application Security Case Study Video</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2007/06/12/encounters-making-an-application-security-case-study-video.aspx</link><pubDate>Tue, 12 Jun 2007 19:23:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3252372</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/3252372.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=3252372</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=3252372</wfw:comment><description>&lt;p&gt;Microsoft IT has been developing an engineering based application security lifecycle for about 5 years now. The ACE team is responsible for helping develop and maintain this lifecycle called the Security Development Lifecycle for IT (SDL for IT) which is currently used to secure line of business applications developed by Microsoft IT. This lifecycle has been adapted to work with other business units within Microsoft. Microsoft IT has taken this experience building an adaptable and scalable application security development lifecycle and exposed it to our customers.&lt;/p&gt; &lt;p&gt;A large part of my job profile is to help large enterprise customers adapt the SDL for IT to work with their business. This is particularly challenging as the core-competency, organizational structure and technical depth of each company&amp;nbsp;and each industry vertical is very different.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Customer:&lt;/strong&gt; The First American Corporation (&lt;a href="http://moneycentral.msn.com/detail/stock_quote?Symbol=US:FAF" target="_blank"&gt;NYSE: FAF&lt;/a&gt;) is a large financial services organization&amp;nbsp;based in Santa Ana, CA. The &lt;a title="First American Case Study" href="http://msdn2.microsoft.com/en-us/security/aa570410.aspx" target="_blank"&gt;case study video&lt;/a&gt;&amp;nbsp;features FAF executives Jeff Klopfer and Scott Campbell talking&amp;nbsp;about First American's experience with the SDL for IT process. &amp;nbsp;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Making the video:&lt;/strong&gt; In response to customer requests to hear success stories around SDL for IT, I started a quest to find a customer based within my region&amp;nbsp;with whom we could conduct a case study. There were several challenges while making this video and I want to discuss my experience leading the creation of this case study.&lt;/p&gt; &lt;p&gt;The unique challenge here was to get funding and well, finding a producer who could do it in time (3 weeks from first contact to deliverable). Microsoft unlike a lot of companies has its own studios and several vendors who are well versed with making case study videos.&lt;/p&gt; &lt;p&gt;Things to do while making a video case study:&lt;/p&gt; &lt;ol&gt; &lt;li&gt;&lt;strong&gt;Clarify objectives: &lt;/strong&gt;You will find that a case study has a lot of moving parts and stakeholders. A set of written objectives and metrics on how to evaluate the achievement of those objectives is very critical. All the stakeholders need to approve this. Remember the customer will only endorse a study that they have analyzed to be accurately reflecting their views.  &lt;li&gt;&lt;strong&gt;Target Audience:&lt;/strong&gt; The target audience should be identified and the messaging needs to address areas of interest to the target audience. Audiences one could consider while building an IT case study are technical: architects, developers, testers; sales and marketing; operational managers; or business decision makers  &lt;li&gt;&lt;strong&gt;Find Producer:&lt;/strong&gt; Identifying a producer early during the project can have several advantages including an easier scheduling process and innovative story boards. Story boarding is very vital to highlight&amp;nbsp;the points you want to leave the audience with.&amp;nbsp;Remember that you have around&amp;nbsp;2-3 minutes to tell a story.  &lt;li&gt;&lt;strong&gt;Shooting:&lt;/strong&gt; While at the customers location keep scouting for a cool location to shoot the video. Personally, I prefer locations that do not have too much going on in the background. Don't wear clothing which will blur in low quality videos. This includes stripped or checked clothes. Check with the video team and communicate this to the individuals involved ahead of time.  &lt;li&gt;&lt;strong&gt;Identify Executives:&lt;/strong&gt; The&amp;nbsp;case study&amp;nbsp;needs to communicate some tangible message.&amp;nbsp;My experience is that the message is best received from an organizational counterpart&amp;nbsp;of your target audience. A CIO&amp;nbsp;to&amp;nbsp;a CIO or Architect to Architect.  &lt;li&gt;&lt;strong&gt;Editing:&lt;/strong&gt; Editing a video requires a huge time commitment from the person commissioning the study. They have to work with the producer and editor to ensure that the messaging is accurate and more importantly they provide the domain expertise that the video team does not possess.  &lt;li&gt;&lt;strong&gt;Format:&lt;/strong&gt; The case study should be available in both high and low quality. Also get the raw footage from the producer for subsequent alterations or expansions.&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;In any case, watch the case study and let me know what you think. In the meantime, I will begin lobbying for an Oscar category for case study videos.&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3252372" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Business/default.aspx">Business</category></item><item><title>CSO Summit: Securing the retail application</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2007/06/06/cso-summit-securing-the-retail-application.aspx</link><pubDate>Thu, 07 Jun 2007 03:14:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3129125</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/3129125.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=3129125</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=3129125</wfw:comment><description>&lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:f78ac861-f410-42a3-a687-1633a42f52d6" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Conferences" rel="tag"&gt;Conferences&lt;/a&gt;&lt;/div&gt; &lt;p&gt;Last month I presented a talk about the security risks faced by the retail industry at the Microsoft &lt;a href="https://www.ustechsregister.com/csosummit/Main.aspx?"&gt;Chief Security Officer Summit&lt;/a&gt; in Redmond. This was a gathering of several hundred CSOs from major Microsoft customers to share their experience around security in their organizations and to help them understand our strategy around security. &lt;p&gt;My talk was based upon interactions and research my team has done with several large organizations in the retail vertical. I've come up with a couple of very plausible real world scenarios that can allow a technical risk to transcend the enterprise IT boundary and impact the core business processes. &lt;p&gt;Scenario 1:Stealing credit card info from Point of Sales systems in-store &lt;p&gt;Ease of exploitability: &lt;i&gt;medium&lt;/i&gt;.  &lt;p&gt;Impact is &lt;i&gt;critical. &lt;/i&gt;&lt;/p&gt; &lt;p&gt;Attacker steals credit card data from Point of Sales (POS) system that talks to retail application client and web service across the web. This system does financial applications over the Internet.  &lt;p&gt;In most cases enterprises expect the attack surface to be communication going over the "Internet", however my experience has been that it is trivial to attack POS systems in stores or retail outlets and obtain that data before it is transmitted across the web. The attack surface is not limited to the web. &lt;p&gt;Scenario 2: Compromise Supply Chain Management System &lt;p&gt;Ease of exploitability:&amp;nbsp;&lt;em&gt;hard&lt;/em&gt;  &lt;p&gt;Impact is &lt;i&gt;critical. &lt;/i&gt;&lt;/p&gt; &lt;p&gt;In several SCM systems unauthenticated web service are used to generate control data like shipping addresses. An attacker can use compromised web service to inject malicious data into shipping system. As a result&amp;nbsp;100,000 wool sweaters could be sent to Miami in July. Threat modeling and security code reviews can be used to minimize the possibility of this attack succeeding. &lt;p&gt;&lt;i&gt;&lt;/i&gt; &lt;p&gt;Our investigations led us to determine that from a business perspective the highest application risk to retail organizations comes in the following threats:  &lt;p&gt;&lt;img height="12" alt="*" src="http://blogs.msdn.com/blogfiles/akshay_aggarwal/WindowsLiveWriter/CSOSummitSecuringtheretailapplication_F7C7/clip_image002.gif" width="12"&gt; Insufficient authentication mechanisms&lt;/p&gt; &lt;p&gt;&lt;img height="12" alt="*" src="http://blogs.msdn.com/blogfiles/akshay_aggarwal/WindowsLiveWriter/CSOSummitSecuringtheretailapplication_F7C7/clip_image002_1.gif" width="12"&gt; Poor authorization model &lt;/p&gt; &lt;p&gt;&lt;img height="12" alt="*" src="http://blogs.msdn.com/blogfiles/akshay_aggarwal/WindowsLiveWriter/CSOSummitSecuringtheretailapplication_F7C7/clip_image002_2.gif" width="12"&gt; Lacking input validation controls  &lt;p&gt;&lt;img height="12" alt="*" src="http://blogs.msdn.com/blogfiles/akshay_aggarwal/WindowsLiveWriter/CSOSummitSecuringtheretailapplication_F7C7/clip_image002_3.gif" width="12"&gt; Susceptible to Denial of Service issues  &lt;p&gt;&lt;img height="12" alt="*" src="http://blogs.msdn.com/blogfiles/akshay_aggarwal/WindowsLiveWriter/CSOSummitSecuringtheretailapplication_F7C7/clip_image002_4.gif" width="12"&gt; Non-standard deployment of point of sales systems  &lt;p&gt;&lt;img height="12" alt="*" src="http://blogs.msdn.com/blogfiles/akshay_aggarwal/WindowsLiveWriter/CSOSummitSecuringtheretailapplication_F7C7/clip_image002_5.gif" width="12"&gt; SCM systems susceptible to insider attacks  &lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=3129125" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Business/default.aspx">Business</category></item><item><title>The Business of Application Security &amp; Performance</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2007/05/08/the-business-of-application-security-performance.aspx</link><pubDate>Tue, 08 May 2007 10:12:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2475654</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/2475654.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=2475654</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=2475654</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;As I fly from San Jose to Seattle passing over Crater Lake pondering over what this blog will be about, two things come to mind.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The first is that the business of developing secure, high performance line of business applications is an area I have had an opportunity to work with several CSOs/CIOs on and would like to capture this interactive knowledge. The second is purely about leadership. I encouraged the 10 people who report to me to blog and can’t really do so without taking the time out to do so myself.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;Over the past few years I have evolved from a Senior Security Technologist striving towards securing Microsoft’s critical applications and software to an Engagement Manager on the Application Consulting &amp;amp; Engineering (ACE) Services team at Microsoft. The ACE team as you can gather from this &lt;A class="" title="ACE team blog" href="http://blogs.msdn.com/ace_team/" target=_blank mce_href="http://blogs.msdn.com/ace_team/"&gt;blog&lt;/A&gt; is the team at Microsoft IT responsible for application security, privacy and performance.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face="Times New Roman"&gt;&lt;SPAN style="mso-bidi-font-weight: bold"&gt;I was hired around 2 years ago with the aim of helping the ACE team start a consulting practice around security by leveraging internal MSIT learning and taking it out to major clients and partners. This is has since expanded to the area of security and performance consulting. My role is to &lt;/SPAN&gt;manage the business lines in the East and West Regions of the United States, Asia Pacific, Middle East and Latin America. Apart from that my current responsibilities include developing strategies for scaling Microsoft’s application security practice, incubating new service lines and establishing offshore capabilities.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&lt;FONT face="Times New Roman" size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT face="Times New Roman" size=3&gt;This blog will focus on the business aspects of application security and performance as well as experiences relating to leadership development.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=2475654" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Performance/default.aspx">Performance</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Business/default.aspx">Business</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Leadership/default.aspx">Leadership</category></item></channel></rss>