December 2005 - Posts

Security Wiki on Channel9
Today, I cleaned up my Security Wiki on Channel9 at http://channel9.msdn.com/Security The purpose of this Wiki is to let me share information that may not be completely fit and finish like on MSDN. This comes in handy for a few things: EcoSystem . It's Read More...
Posted 24 December 05 08:27 by J.D. Meier | 2 Comments   
Filed under
Web Application Security Frame
The Web Application Security Frame is a set of categories you can use to scope security and improve your effectiveness. It consists of the following categories: Auditing and Logging Authentication Authorization Configuration Management Cryptography Exception Read More...
Posted 18 December 05 06:58 by J.D. Meier | 0 Comments   
Filed under
Domain Specific Categories
As a software engineer, how do you cope with information overload? I suggest domain specific categories. If the basic idea of domain specific languages (DSL) is a software language targeted at a specific area of problems, then domain specific categories Read More...
High ROI Engineering Activities
How do you know which techniques to use to shape your software throughout the life cycle? Start with the high Return On Investment (ROI) activities as a baseline set. You can always supplement or modify for your scenario. Most development shops have some Read More...
What Makes a Good Threat Model
While trying to create threat model template for customers, I analyzed many threat models inside and outside Microsoft. It was insightful to see the patterns of what was useful across threat models and what was noise. A good threat model has the following Read More...
Posted 01 December 05 07:51 by J.D. Meier | 4 Comments   
Filed under

Search

This Blog

Syndication

Page view tracker