This article examines several standards and enumerations that are changing the concepts of assurance, compliance, and security in enterprises, products, and practices—and shows how procurement officers, government organizations, and software professionals can benefit from them.
The National Defense Industrial Association’s “Engineering for System Assurance” Guidebook is a must-have for DoD organizations and contractors, and this article examines its benefits in the areas of assurance case claims and the DoD Management Framework.
Confidentiality, integrity, and availability are cornerstones for evaluating the survivability of a system, and the authors share a methodology for assessment as well as their first-hand experience with the most prevalent forms of direct attack.
The authors show how to use software security practices from the recently published “Software Security Engineering: A Guide for Project Managers” as a tool in selecting practices that will lead to more security-responsive and robust systems.
The authors look in-depth at CI: how it works, its tools and products, its relation to the “economics of testing,” and how an organization can successfully choose, incorporate, and utilize commercial and open source CI tools.
I have found CrossTalk to be an exceptional resource. In general, CrossTalk is a vast repository of knowledge for those in defense software engineering. Virtually every software topic has its own theme issue. One of our software engineers asked me what I knew about Agile Software Development. I immediately directed him to your April 2007 issue, themed Agile Development, which was easy to access on your Web site .