|
BOS44-300: Secure Code: Issues and Techniques
Presenter:
Leighton Johnson
Breakout Session
-
Level 300 (Advanced)
We will cover the SDLC for secure code:
· Secure Software Concepts - security implications in software development
· Secure Software Requirements - capturing security requirements in the requirements gathering phase
· Secure Software Design - translating security requirements into application design elements
· Secure Software Implementation/Coding - unit testing for security functionality and resiliency to attack, and developing secure code and exploit mitigation
· Secure Software Testing - integrated QA testing for security functionality and resiliency to attack
· Software Acceptance - security implication in the software acceptance phase
· Software Deployment, Operations, Maintenance and Disposal - security issues around steady state operations and management of software
Slides
|
Leighton Johnson
COO, Information Security and Forensics Management Team
Leighton R. Johnson, III is the COO and senior security instructor/consultant with Information Security and Forensics Management Team (ISFMT) of Bath, South Carolina. He has over 35 years experience in Computer Security, Software Development and Communications Equipment Operations & Maintenance. Primary focus areas have included computer security operations, management; information assurance auditing and testing, forensics and incident response activities, software system architecture development verified through modeling & simulation activities and experiments, Radio Frequency (RF) spectrum certification process and evaluations & systems integration activities.
His career has spanned military, federal, & civilian contractor arenas as well as commercial auditing and retail sectors. With his thirty five plus years of experience, Leighton has established the trends for many security certifications. He has served as the Security Manager for various commercial and governmental organizations. He has formed and directed multiple computer incident response teams. He has contributed to tests for numerous certification tests provided by various organizations. He has presented seminars, lectures, and conference presentations on multiple topics in Security and Modeling over the years. He is the adjunct instructor at Augusta State University for Digital and Network Forensics courses.
He currently holds CISSP, CISM, CIFI, CSSLP, MBCI and CISA credentials, as well as memberships in ISC2, ISACA, IISFA, ACFEI, IATAC, IEEE, Infragard, ISSA, ICFP, and BCI.
Website:
http://www.isfmt.com
|