<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Application Security</title>
	<atom:link href="http://dedicatedhosting.com/tag/application-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://dedicatedhosting.com</link>
	<description></description>
	<lastBuildDate>Wed, 02 Jun 2010 12:29:04 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Application Development on Dedicated Hosting Platforms Require Security Policies and Collaboration</title>
		<link>http://dedicatedhosting.com/2009/11/application-development-on-dedicated-hosting-platforms-require-security-policies-and-collaboration/</link>
		<comments>http://dedicatedhosting.com/2009/11/application-development-on-dedicated-hosting-platforms-require-security-policies-and-collaboration/#comments</comments>
		<pubDate>Sun, 22 Nov 2009 16:26:28 +0000</pubDate>
		<dc:creator>Alan Weinkrantz</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cloud Hosting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Dan Cornell]]></category>
		<category><![CDATA[Denim Group]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://dedicatedhosting.com/?p=15</guid>
		<description><![CDATA[
			
				
			
		
According to Dan Cornell, Principal and CTO of Denim Group, in a dedicated hosting environment you have more control over the environment that you will be building your applications on.  However, it’s important to also realize that the code you are developing has to be secure as well as the infrastructure components that they are [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: left; margin-left: 0px; margin-right: 10px">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fdedicatedhosting.com%2F2009%2F11%2Fapplication-development-on-dedicated-hosting-platforms-require-security-policies-and-collaboration%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fdedicatedhosting.com%2F2009%2F11%2Fapplication-development-on-dedicated-hosting-platforms-require-security-policies-and-collaboration%2F&amp;source=welovehosting&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>According to <a href="http://www.denimgroup.com/about_team_dan.html">Dan Cornell</a>, Principal and CTO of <a href="http://www.denimgroup.com">Denim Group</a>, in a <a href="http://www.serverbeach.com/">dedicated hosting</a> environment you have more control over the environment that you will be building your applications on.  However, it’s important to also realize that the code you are developing has to be secure as well as the infrastructure components that they are part of.</p>
<p><span id="more-15"></span></p>
<p>Cornell also urges application and security teams to better collaborate in order to ensure successful and secure software development initiatives and to check out <a href="http://www.owasp.org/index.php/Main_Page">OWASP</a> , whose mission is to make application security <a href="https://www.owasp.org/index.php/Category:OWASP_Video">visible,</a> so that <a href="http://www.owasp.org/index.php/Industry:Citations">people and organizations can make informed decisions</a> about true application security risks.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="640" height="385" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/fR0UvalYfbE&amp;hl=en_US&amp;fs=1&amp;rel=0&amp;hd=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="640" height="385" src="http://www.youtube.com/v/fR0UvalYfbE&amp;hl=en_US&amp;fs=1&amp;rel=0&amp;hd=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><strong>Raw Transcript</strong><br />
This is the raw transcript of the video, in case you need it:</p>
<div style="border: 1px solid #000000; padding: 5px; width: 600px; height: 500px; overflow-y: scroll;">
<p>Denim Group with Alan Weinkrantz</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Dan: Well the important thing to understand is that in a dedicated hosting environment you have a lot more control over the environment that you’re going to be building or deploying these applications on.  And so that’s great because it gives you freedom to do a lot of different things, but it’s also important for you to understand that this code you’re developing, that has to be secure, but it also the infrastructure components that it sits on top of – those have to be properly secured  as well.  So it’s important to pay attention to, again, patch management, to making sure that the services, that your application servers and things of that nature are configured in a secure manner so that your infrastructure as well as the code that you’re writing is appropriately secure.  Really the best place to get started looking at application security or looking for application security resources is the open-web application security project or Owasp – www.owasp.org.  And what Owasp is it’s an organization that is dedicated to helping organizations create secure software, appropriately secure software, and spreading information and awareness about these potential issues.  You know the really interesting security things that are happening these days are all happening at the application level, so looking at security and the code that you’re writing, security for the code that you’re deploying – that’s been the case for a couple of years and I think that trend is going to continue as organizations go to take their application security efforts up to the next level.  We’re also seeing now that the economy is starting to thaw a little bit, organizations are coming out of their shells a little bit, whereas the focus used to be like “what is the absolute minimum amount of money that I can spend in order to address compliance issues,”  you know, whatever compliance requirements they have.  Folks are now starting to come out of their shells a little bit and say well let’s make sure we’re actually addressing risk associated with the software that we’ve got, with the infrastructure, and so rather than a very narrow focus on compliance it’s now coming back around to be focused on risk, which is great.  Also, you know what we’ve seen is organizations kind of coming out of the downturn, as things start to thaw out a little bit, they’re not super excited about having a bunch of hardware internally so they’re looking into things such as dedicated hosting in order to provide the hardware infrastructure that they need, and the configurability and control that they need, but not necessarily something that they have to have in-house.</p>
<p>Alan: So Dan, you know, in wrapping things up one of the other things that you brought up in our discussions were you almost have two different camps.  You have the security camp, you have the application developer’s camp, and sometimes the two don’t quite meet.  And one of your areas of expertise is helping and facilitating these two areas to work together as teams, and how… what are your suggestions for application teams, security teams, to work together in a dedicated hosting environment?</p>
<p>Dan: Alright in the application development world the CIO’s are familiar with, they understand the risk, but the people who actually have to fix the problems, the software developers, they don’t report to the CIO.  They report up through, you know, a development organization, you know potentially they report up through different lines of business, and the developers are not necessarily incented or rewarded for how secure they make things, they’re rewarded for features, functions, and timelines, so it is a really challenging thing for a lot of organizations to understand, is how do they get these groups talking to one another.  Because what the security folks are finding on their side are vulnerabilities, but those need to be communicated to the development teams as software defects.  If I’m in development… if I’m a developer I can either build a fancy new feature or I can fix security vulnerabilities.  Either of those activities is going to take… is going to take time out of my day, and so it’s important for security groups to be able to work with their development teams, to communicate their needs from a compliance side, from a risk side, and for the software developers to be able to work with them, and say “Well here is the budget that we have that we’re going to allocate to addressing our exposure to these risks.”  You know, as with a lot of things it’s all about communication, and it’s all about making sure that these two different groups that often have different aims are put in a situation where they can work together to successfully address the issues that come up.</p>
<p>Alan: Well thank you Dan this has been very informative.  How do our viewers find you on the internet?</p>
<p>Dan: Well we’re www.denimgroup.com, that’s our website, and you can follow me on Twitter I’m @danielcornell.</p>
<p>Alan: Thank you for your time today.</p>
<p>Dan: Thank you.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://dedicatedhosting.com/2009/11/application-development-on-dedicated-hosting-platforms-require-security-policies-and-collaboration/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>

