How To Measure Developer Security Knowledge

简介: Aspect Security has launched a free baseline knowledge tool that claims to produce an accurate ...

Aspect Security has launched a free baseline knowledge tool that claims to produce an accurate assessment of a development team's knowledge of application security. Secure Coder Analytics can be accessed online to determine the skill set and level of a group of developers or individuals.

"How do you know what you don't know? That's the challenge facing development teams that want to develop secure code. There's no shame in not knowing all of the tricky aspects of application security, and now you can find out where your gaps are," said Jeff Williams, CEO of Aspect Security.

Williams is also cofounder of the Open Web Application Security Project (OWASP), and he contends his firm's Secure Coder Analytics takes a developer approximately 20 minutes to complete and tests knowledge in various security areas via a multiple-choice assessment.

Questions are randomized from what is said to be an "extensive" pool of questions. Managers of development teams can set up their own tests and invite developers to participate anonymously. After participating, each developer sees their own grade and managers can see aggregate scores that reveal the strengths and weaknesses of the team as a whole.

Aspect Security's eLearning curriculum features 53 learning modules at three different levels of technical depth. The company says that its eLearning solution is in use by developers worldwide at many corporate entities, including giants in the financial, shipping, and logistics and airline industries and government agencies.


目录
相关文章
|
安全
Information Systems Security Assessment – Open information security framework
The Information Systems Security Assessment Framework (ISSAF) seeks to integrate the following m...
990 0
Uptime And Monitoring Strategies For Cloud-Based E-Commerce Applications/Websites
In order to keep your e-commerce site functioning properly, you need to take positive steps to monitor both its performance and functionality.
1522 0
Attack OGC WFS Implementation
http://docs.opengeospatial.org/is/04-094r1/04-094r1.
1147 0
The 11-Step Guide to BYOD Security. How to Avoid Getting Fired
https://heimdalsecurity.com/blog/byod-security/
713 0
|
安全
Security Analytics and Threat Analysis brighttalk
https://www.brighttalk.com/community/it-security/summit/securityanalyticsfeb2015 ...
823 0
|
安全
Security Analytics: Detecting Advanced Threats and Fraud
https://www.brighttalk.com/webcast/574/136917
900 0
Predicting Malicious Behavior: Tools and Techniques for Ensuring Global Security
http://www.wiley.com/WileyCDA/WileyTitle/productCd-1118896696.
787 0
|
安全