<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>J.D. Meier's Blog : Competitive Studies</title><link>http://blogs.msdn.com/jmeier/archive/tags/Competitive+Studies/default.aspx</link><description>Tags: Competitive Studies</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Security Innovation Security Engineering Study</title><link>http://blogs.msdn.com/jmeier/archive/2006/04/02/security-innovation-security-engineering-study.aspx</link><pubDate>Sun, 02 Apr 2006 05:41:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:566726</guid><dc:creator>J.D. Meier</dc:creator><slash:comments>3</slash:comments><comments>http://blogs.msdn.com/jmeier/comments/566726.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jmeier/commentrss.aspx?PostID=566726</wfw:commentRss><description>&lt;P&gt;&lt;BR&gt;The Security Innovation Security Engineering study,&amp;nbsp;&amp;nbsp;&lt;A href="http://www.securityinnovation.com/resources/SDLC/index.shtml" mce_href="http://www.securityinnovation.com/resources/SDLC/index.shtml"&gt;Comparing Security in the Application Lifecycle - Microsoft and IBM Development Platforms Compared&lt;/A&gt;, is timely, given the emerging industry emphasis on integrating security in the life cycle.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;My favorite quote in the study is "&lt;EM&gt;The patterns &amp;amp; practices security guidance covers the key security engineering activities better than any other resource we’ve found&lt;/EM&gt;."&amp;nbsp; I think this reflects the fact we have more than 2,500 pages of security guidance (see &lt;A href="http://msdn.com/SecurityGuidance" mce_href="http://msdn.com/SecurityGuidance"&gt;Security Guidance&lt;/A&gt;, &lt;A href="http://msdn.com/SecurityEngineering" mce_href="http://msdn.com/SecurityEngineering"&gt;Security Engineering&lt;/A&gt;, &lt;A href="http://msdn.com/ThreatModeling" mce_href="http://msdn.com/ThreatModeling"&gt;Threat Modeling&lt;/A&gt;, and &lt;A href="http://msdn.com/SecNet" mce_href="http://msdn.com/SecNet"&gt;Improving Web Application Security&lt;/A&gt;) , and we've integrated our guidance into MSF/VS 2005 (see MS&lt;A href="http://blogs.msdn.com/jmeier/archive/2006/03/17/553965.aspx" mce_href="http://blogs.msdn.com/jmeier/archive/2006/03/17/553965.aspx"&gt;F/VS 2005 and p&amp;amp;p Integration&lt;/A&gt;.)&amp;nbsp; &lt;/P&gt;
&lt;P&gt;The study was available from the MSDN Security DevCenter for a while but seems to have fallen off.&amp;nbsp; I've summarized the study here for quick reference:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overview&lt;/STRONG&gt;&lt;BR&gt;Security Innovation evaluated the guidance and tools of Microsoft's and IBM's development platforms.&amp;nbsp; The study compared the support available to a development team via security guidance, documentation and security focused features in the life-cycle tool suites.&amp;nbsp; Gartner reviewed the approach.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;STRONG&gt;Evaluation Criteria&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Coverage&lt;/STRONG&gt;.&amp;nbsp; &lt;EM&gt;How well do the provided tools and guidance cover the key set of security areas?&amp;nbsp;&lt;/EM&gt; 
&lt;LI&gt;&lt;STRONG&gt;Quality&lt;/STRONG&gt;.&amp;nbsp; &lt;EM&gt;How effective and accurate are the tools and guidance?&lt;/EM&gt; 
&lt;LI&gt;&lt;STRONG&gt;Visibility&lt;/STRONG&gt;.&amp;nbsp; &lt;EM&gt;How easy is it to find the tools and guidance and then apply it to your security needs?&lt;/EM&gt; 
&lt;LI&gt;&lt;STRONG&gt;Usability&lt;/STRONG&gt;.&amp;nbsp; &lt;EM&gt;Are the tools and guidance precise, comprehensive and easy to use?&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Ratings&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Outstanding:&lt;/STRONG&gt; 81-100% 
&lt;LI&gt;&lt;STRONG&gt;Good:&lt;/STRONG&gt; 61-80% 
&lt;LI&gt;&lt;STRONG&gt;Average:&lt;/STRONG&gt; 41-60% 
&lt;LI&gt;&lt;STRONG&gt;Below Average:&lt;/STRONG&gt; 21-40% 
&lt;LI&gt;&lt;STRONG&gt;Poor:&lt;/STRONG&gt; 0-20%&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Scorecard Categories&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Basic Platform Security&lt;/STRONG&gt;.&amp;nbsp; When used in accordance with its documentation, a platform should be inherently secure. 
&lt;LI&gt;&lt;STRONG&gt;Platform Security Services&lt;/STRONG&gt;.&amp;nbsp; A mature platform should include services that make it easier for developers to implement security features in their applications. 
&lt;LI&gt;&lt;STRONG&gt;Platform Security Guidance&lt;/STRONG&gt;. A secure platform is much less useful if it lacks proper guidance. 
&lt;LI&gt;&lt;STRONG&gt;Software Security Engineering Guidance&lt;/STRONG&gt;.&amp;nbsp; It is not possible to develop a secure application unless security is a focus during every phase of the development lifecycle. 
&lt;LI&gt;&lt;STRONG&gt;Security Tools&lt;/STRONG&gt;.&amp;nbsp; A secure platform should include tools that make it easier to define, design, implement, test, and deploy a secure application.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Results of the Study&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;First, here's a&amp;nbsp;couple key points, then the&amp;nbsp;summaries are below:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft beat IBM in every category around guidance.&lt;/STRONG&gt; 
&lt;LI&gt;&lt;STRONG&gt;Microsoft beat IBM in three out of four categories around tools.&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;BR&gt;&lt;STRONG&gt;IBM&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt;Platform Overall&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Overall: 36% 
&lt;LI&gt;Coverage: 62% 
&lt;LI&gt;Quality: 70% 
&lt;LI&gt;Visibility: 17% 
&lt;LI&gt;Usability: 72%&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Platform Security Guidance&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Overall: 50% 
&lt;LI&gt;Coverage: 81% 
&lt;LI&gt;Quality: 85% 
&lt;LI&gt;Visibility: 17% 
&lt;LI&gt;Usability: 84%&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Security Engineering Guidance&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Overall: 25% 
&lt;LI&gt;Coverage: 50% 
&lt;LI&gt;Quality: 64% 
&lt;LI&gt;Visibility: 17% 
&lt;LI&gt;Usability: 69%&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Security Tools&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Overall: 32% 
&lt;LI&gt;Coverage: 55% 
&lt;LI&gt;Quality: 59% 
&lt;LI&gt;Visibility: 56% 
&lt;LI&gt;Usability: 63%&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt;Platform Overall&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Overall: 67% 
&lt;LI&gt;Coverage: 88% 
&lt;LI&gt;Quality: 85% 
&lt;LI&gt;Visibility: 61% 
&lt;LI&gt;Usability: 80%&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;Platform Security Guidance 
&lt;OL&gt;
&lt;LI&gt;Overall: 76% 
&lt;LI&gt;Coverage: 93% 
&lt;LI&gt;Quality: 85% 
&lt;LI&gt;Visibility: 67% 
&lt;LI&gt;Usability: 91%&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Security Engineering Guidance&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Overall: 78% 
&lt;LI&gt;Coverage: 100% 
&lt;LI&gt;Quality: 89% 
&lt;LI&gt;Visibility: 67% 
&lt;LI&gt;Usability: 79%&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Security Tools&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Overall: 47% 
&lt;LI&gt;Coverage: 71% 
&lt;LI&gt;Quality: 78% 
&lt;LI&gt;Visibility: 50% 
&lt;LI&gt;Usability: 68%&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Quotes from the Study&lt;/STRONG&gt;&lt;BR&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;EM&gt;Microsoft’s overall rating of 67% reflects the impressive level of focus Microsoft has applied to application security in the past several years.&lt;/EM&gt; 
&lt;LI&gt;&lt;EM&gt;IBM’s overall score of 36% is the result of a more disjointed approach to security.&amp;nbsp; Security guidance is spread throughout the IBM web site and is difficult to discover.&lt;/EM&gt; 
&lt;LI&gt;&lt;EM&gt;The patterns &amp;amp; practices security guidance covers the key security engineering activities better than any other resource we’ve found.&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;More Information&lt;BR&gt;&lt;/STRONG&gt;For more information, see &lt;A href="http://www.securityinnovation.com/resources/SDLC/index.shtml" mce_href="http://www.securityinnovation.com/resources/SDLC/index.shtml"&gt;Comparing Security in the Application Lifecycle - &lt;BR&gt;Microsoft and IBM Development Platforms Compared&lt;/A&gt; at Security Innovation's site.&amp;nbsp; They created four documents that take you through the details and results: Executive Summary, Research Overview, Full Detailed Reports and Results, and Methodology.&lt;BR&gt;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=566726" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jmeier/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/jmeier/archive/tags/Competitive+Studies/default.aspx">Competitive Studies</category></item><item><title>OpenHack 4 (eWeek Labs): Web Application Security</title><link>http://blogs.msdn.com/jmeier/archive/2006/04/02/566716.aspx</link><pubDate>Sun, 02 Apr 2006 04:31:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:566716</guid><dc:creator>J.D. Meier</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.msdn.com/jmeier/comments/566716.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jmeier/commentrss.aspx?PostID=566716</wfw:commentRss><description>&lt;P&gt;Whenever I bring up the OpenHack 4 competition, most aren't ware of it.&amp;nbsp; It was an interesting study because it was effectively an open "hack me with your best shot" competition.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;I happened to know the folks on the MS side, like Erik Olson and Girish Chander, that helped secure the application, so it had some of the best available security engineering.&amp;nbsp; In fact, customers commented that it's great that Microsoft can secure its applications ... but what about its customers?&amp;nbsp; That comment was inspiration for our &lt;A href="http://msdn.com/SecNet"&gt;Improving Web Application Security:Threats and Countermeasures&lt;/A&gt; guide. &lt;/P&gt;
&lt;P&gt;I've summarize OpenHack 4 here, so it's easier for me to reference. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overview of OpenHack 4&lt;/STRONG&gt;&lt;BR&gt;In October 2002, eWeek Labs launched its fourth annual OpenHack online security contest.&amp;nbsp; It was designed to test enterprise security by exposing systems to the real-world rigors of the Web.&amp;nbsp; Microsoft and Oracle were given a sample Web application by eWeek and were asked to redevelop the application using their respective technologies. Individuals were then invited to attempt to compromise the security of the resulting sites.&amp;nbsp; Acceptable breaches&amp;nbsp;included of cross-site scripting attacks, dynamic Web page source code disclosure, Web page defacement, posting malicious SQL commands to the databases, and theft of credit card data from the databases used.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Outcome of the Competition&lt;/STRONG&gt;&lt;BR&gt;The&amp;nbsp;Web site built by Microsoft engineers using the Microsoft .NET Framework, Microsoft Windows 2000 Advanced Server, Internet Information Services 5.0, and Microsoft SQL Server 2000 &lt;STRONG&gt;successfully withstood over 82,500 attempted attacks&lt;/STRONG&gt; to emerge from the eWeek OpenHack 4 competition unscathed&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;More Information&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;For more information on implementation details of the Microsoft Web application and configuration used for the OpenHack competition, see "&lt;A href="http://msdn.microsoft.com/library/en-us/dnnetsec/html/openhack.asp"&gt;Building and Configuring More Secure Web Sites: Security Best Practices for Windows 2000 Advanced Server, Internet Information Services 5.0, SQL Server 2000, and the .NET Framework&lt;/A&gt;" &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=566716" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jmeier/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/jmeier/archive/tags/Competitive+Studies/default.aspx">Competitive Studies</category></item><item><title>@Stake Security Study: .NET 1.1 vs. WebSphere 5.0</title><link>http://blogs.msdn.com/jmeier/archive/2006/04/02/566708.aspx</link><pubDate>Sun, 02 Apr 2006 03:15:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:566708</guid><dc:creator>J.D. Meier</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.msdn.com/jmeier/comments/566708.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jmeier/commentrss.aspx?PostID=566708</wfw:commentRss><description>&lt;P&gt;I like competitive studies.&amp;nbsp; I'm usually more interested in the methodology than the outcome.&amp;nbsp; The methodology&amp;nbsp;acts as a blueprint for what's important in a particular&amp;nbsp;problem space.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;One of my favorite studies was the original @Stake study comparing .NET 1.1 vs. IBM's WebSphere security, not just because our&amp;nbsp;body of guidance made a&amp;nbsp;direct and&amp;nbsp;substantial&amp;nbsp;difference in the&amp;nbsp;outcome, but because @Stake used a comprehensive set categories and an evaluation criteria matrix that demonstrated a lot of depth.&lt;/P&gt;
&lt;P&gt;Because the information from the original report can be difficult to find and distill, I'm summarizing it below:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overview&amp;nbsp;of Report&lt;BR&gt;&lt;/STRONG&gt;In June 2003, @Stake, Inc., an independent security consulting firm, released results of a Microsoft-commissioned study that found Microsoft's .Net platform to be superior to IBM's WebSphere for secure application development and deployment.&amp;nbsp; @stake performed an extensive analysis comparing security in the .NET Framework 1.1, running on Windows Server 2003, to IBM WebSphere 5.0, running on both Red Hat Linux Advanced Server 2.1 and a leading commercial distribution of Unix..&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;STRONG&gt;Findings&lt;BR&gt;&lt;/STRONG&gt;Overall, @stake found that: &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Both platforms provide infrastructure and effective tools for creating and deploying secure applications 
&lt;LI&gt;The .NET Framework 1.1 running on Windows Server 2003 scored slightly better with respect to conformance to security best practices&amp;nbsp; 
&lt;LI&gt;&amp;nbsp;The Microsoft solution scored even higher with respect to the ease with which developers and administrators can implement secure solutions&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Approach&lt;/STRONG&gt;&lt;BR&gt;@stake evaluated the level of effort required for developers and system administrators to create and deploy solutions that implement security best practices, and to reduce or eliminate most common attack surfaces.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;STRONG&gt;Evaluation Criteria&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Best practice compliance&lt;/STRONG&gt;.&amp;nbsp; For a given analysis topic, to what degree did the platform permit implementation of best practices? 
&lt;LI&gt;&lt;STRONG&gt;Implementation complexity&lt;/STRONG&gt;.&amp;nbsp;&amp;nbsp; How difficult was it for the developer to implement the desired feature? 
&lt;LI&gt;&lt;STRONG&gt;Documentation and examples&lt;/STRONG&gt;.&amp;nbsp; How appropriate was the documentation?&amp;nbsp; 
&lt;LI&gt;&lt;STRONG&gt;Implementor competence&lt;/STRONG&gt;.&amp;nbsp; How skilled did the developer need to be in order to implement the security feature? 
&lt;LI&gt;&lt;STRONG&gt;Time to implement&lt;/STRONG&gt;.&amp;nbsp; How long did it take to implement the desired security feature or behavior?&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;BR&gt;&lt;STRONG&gt;Ratings for the Evaluation Criteria&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt;Best Practice Compliance Ratings&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Not possible 
&lt;LI&gt;Developer implement 
&lt;LI&gt;Developer extend 
&lt;LI&gt;Wizard 
&lt;LI&gt;Transparent&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Implementation Complexity Ratings&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Large amount of code 
&lt;LI&gt;Medium amount of code 
&lt;LI&gt;Small amount of code 
&lt;LI&gt;Wizard + 
&lt;LI&gt;Wizard&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Quality of Documentation and Sample Code Ratings&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Incorrect or Insecure 
&lt;LI&gt;Vague or Incomplete 
&lt;LI&gt;Adequate 
&lt;LI&gt;Suitable 
&lt;LI&gt;Best Practice Documentation&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Developer/Administrator Competence Ratings&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Expert (5+ years of experience 
&lt;LI&gt;Expert/intermediate (3-5 years of experience) 
&lt;LI&gt;Intermediate 
&lt;LI&gt;Intermediate/novice 
&lt;LI&gt;Novice (0-1 years of experience)&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Time to Implement&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;High (More than 4 hours) 
&lt;LI&gt;Medium to High (1 to 4 hours) 
&lt;LI&gt;Medium (16-60 minutes) 
&lt;LI&gt;Low to Medium&amp;nbsp; (6-15 minutes ) 
&lt;LI&gt;Low (5 minutes or less )&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;BR&gt;&lt;STRONG&gt;Scorecard Categories&lt;BR&gt;&lt;/STRONG&gt;The scorecard was organized&amp;nbsp;by&amp;nbsp;application,&amp;nbsp;Web server and platform categories.&amp;nbsp; Each category was&amp;nbsp;divided into smaller categories to test the evaluation criteria (best practice compliance, implementation complexity, quality of documentation, developer competence, and time to implement).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Application Server Categories&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;LI&gt;&lt;EM&gt;Application Logging Services&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Exception Management 
&lt;LI&gt;Logging Privileges 
&lt;LI&gt;Log Management&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Authentication and Access Control&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI dir=ltr&gt;Login Management 
&lt;LI dir=ltr&gt;Role Based Access Control 
&lt;LI dir=ltr&gt;Web Server Integration&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Communications&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Communication Security 
&lt;LI&gt;Network Accessible Services&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Cryptography&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Cryptographic Hashing 
&lt;LI&gt;Encryption Algorithms 
&lt;LI&gt;Key Generation 
&lt;LI&gt;Random Number Generation 
&lt;LI&gt;Secrets Storage 
&lt;LI&gt;XML Cryptography&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Database Access&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI dir=ltr&gt;Database Pool Connection Encryption 
&lt;LI dir=ltr&gt;Data Query Safety&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Data Validation&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Common Validators 
&lt;LI&gt;Data Sanitization 
&lt;LI&gt;Negative Data Validation 
&lt;LI&gt;Output Filtering 
&lt;LI&gt;Positive Data Validation 
&lt;LI&gt;Type Checking&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Information Disclosure&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI dir=ltr&gt;Error Handling 
&lt;LI dir=ltr&gt;Stack Traces and Debugging&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Runtime Container Security&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Code Security 
&lt;LI&gt;Runtime Account Privileges&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Web Services&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Credentials Mapping 
&lt;LI&gt;SOAP Router Data Validation&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Host and Operating System Categories&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt;IP Stack Hardening&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Protocol Settings&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Service Minimization&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Installed Packages 
&lt;LI&gt;Network Services&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Web Server Categories&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt;Architecture&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Security Partitioning&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Authentication&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Authentication Input Validation 
&lt;LI&gt;Authentication Methods 
&lt;LI&gt;Credential Handling 
&lt;LI&gt;Digital Certificates 
&lt;LI&gt;External Authentication 
&lt;LI&gt;Platform Integrated Authentication&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Communication Security&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Session Encryption&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Information Disclosure&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Error Messages and Exception Handling 
&lt;LI&gt;Logging 
&lt;LI&gt;URL Content Protection&lt;/LI&gt;&lt;/OL&gt;
&lt;LI&gt;&lt;EM&gt;Session Management&lt;/EM&gt; 
&lt;OL&gt;
&lt;LI&gt;Cookie Handling 
&lt;LI&gt;Session Identifier 
&lt;LI&gt;Session Lifetime&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;More Information&lt;/STRONG&gt;&lt;BR&gt;For more information on the original @stake report, see the eWeek.com article, &lt;A href="http://www.eweek.com/article2/0,1895,1113313,00.asp"&gt;.Net, WebSphere Security Tested&lt;/A&gt;.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=566708" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jmeier/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/jmeier/archive/tags/Competitive+Studies/default.aspx">Competitive Studies</category></item></channel></rss>