securityengineering

Cancel Save Edit

patterns & practices Security Engineering


Approach

patterns & practices Security Engineering includes specific security related activities.
http://channel9.msdn.com/wiki/images/SecurityEngineering.gif

These include identifying security objectives, creating threat models, applying secure design guidelines, patterns and principles, conducting architecture and design reviews for security, performing regular code reviews for security, testing for security, and conducting deployment reviews to ensure secure configuration.
For more info, see SecurityEngineeringOverview


Threat Modeling

* ThreatModeling

Design Guidelines

* WebAppSecurityDesignGuidelines

Arch/Design Review

* WebAppSecurityArchDesignReview

Testing

* SecurityTesting

Code Review

* ManagedCodeSecurityCodeReview
* ADONETSecurityCodeReview
* ASPNETSecurityCodeReview
* BufferOverflowsSecurityCodeReview
* CASSecurityCodeReview
* CrossSiteScriptingSecurityCodeReview
* EntServicesSecurityCodeReview
* RemotingSecurityCodeReview
* SQLInjectionSecurityCodeReview
* UnmanagedCodeSecurityCodeReview
* WebServicesSecurityCodeReview

Deployment Review

* ASPNETSecurityDeploymentReview
* IIS5SecurityDeploymentReview
* NetworkSecurityDeplomentReview
* SQL2000SecurityDeploymentReview

Checklists

* ADONETSecurityChecklist
* ArchAndDesignSecurityChecklist
* ASPNETSecurityChecklist
* CLRSecurityChecklist
* EnterpriseServicesSecurityChecklist
* IIS5SecurityChecklist
* NetworkSecurityChecklist
* RemotingSecurityChecklist
* SQL2000SecurityChecklist
* WebServicesSecurityChecklist



Return to PatternsAndPracticesSecurityWiki