﻿<?xml version="1.0" encoding="utf-8"?><rss xmlns:a10="http://www.w3.org/2005/Atom" version="2.0"><channel><title>SoftwareTestPro.com Security Feed</title><description /><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/5614/Risk-Management-IV---A-New-Hope/Testing-Software-Security-Quality-Assurance</guid><link>http://www.softwaretestpro.com/Item/5614/Risk-Management-IV---A-New-Hope/Testing-Software-Security-Quality-Assurance</link><author>matt.heusser@gmail.com</author><category>Testing</category><category>Software</category><category>Security</category><category>Quality Assurance</category><title>Risk Management IV - A New Hope </title><description>Where Matt talks about a few elements of risk management you may not have considered</description><pubDate>Mon, 06 Aug 2012 18:47:14 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/5509/Another-Software-Security-Testing-Thought/Testing-Security-Management</guid><link>http://www.softwaretestpro.com/Item/5509/Another-Software-Security-Testing-Thought/Testing-Security-Management</link><author>dan.alloun@intel.com</author><category>Testing</category><category>Security</category><category>Management</category><title>Another Software Security Testing Thought...</title><description>Yeah!! STPCon Spring 2012 edition is just over, but still plenty of emotions and good stuff to follow up with... It was so great to have this opportunity to share and discuss with other professionals. </description><pubDate>Thu, 19 Apr 2012 08:00:00 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/5429/Software-Security-Testing-%e2%80%93-Are-You-Committed/Software-Software-Test-Professionals-Conference-Testing-Security</guid><link>http://www.softwaretestpro.com/Item/5429/Software-Security-Testing-%e2%80%93-Are-You-Committed/Software-Software-Test-Professionals-Conference-Testing-Security</link><author>dan.alloun@intel.com</author><category>Software</category><category>Software Test Professionals Conference</category><category>Testing</category><category>Security</category><title>Software Security Testing – Are You Committed?</title><description>Looking at our products, they're filled with assets to protect; it could be sensitive data, Intellectual Property or critical functionality. Without doubt some mechanisms are already in place to protect them, but how much do you invest in testing the robustness of these mechanisms? Do you know how to evaluate the risk of having any of them unintentionally exposed? </description><pubDate>Thu, 09 Feb 2012 11:00:00 -0700</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/5356/Enterprise-Security-Now-More-Than-Ever/Software-Development-Test-and-QA-Security</guid><link>http://www.softwaretestpro.com/Item/5356/Enterprise-Security-Now-More-Than-Ever/Software-Development-Test-and-QA-Security</link><author>ashwin.palaparthi@gmail.com</author><category>Software</category><category>Development</category><category>Test and QA</category><category>Security</category><title>Enterprise Security: Now, More Than Ever</title><description>Enterprise security primarily comprising of data protection and privacy continues to be an area of focus for enterprises, be it on the production or the non-production side of the entity. Little wonder enterprise security spending remained surprisingly resistant to enterprise budget pressures even during the recent economic mayhem. </description><pubDate>Thu, 01 Dec 2011 11:00:00 -0700</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/5259/Who-is-Watching-Your-Test-Data/Security-Management-Integration-Software-User</guid><link>http://www.softwaretestpro.com/Item/5259/Who-is-Watching-Your-Test-Data/Security-Management-Integration-Software-User</link><author>daven.kruse@gmail.com</author><category>Security</category><category>Management</category><category>Integration</category><category>Software</category><category>User</category><title>Who is Watching Your Test Data?</title><description>Is your project looking for ways to
reduce invalid defects, maintain
a consistently clean testing
environment, and increase the
effectiveness of its development
resources?
Look no further than test data.</description><pubDate>Tue, 23 Aug 2011 00:00:00 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/5216/Three-Project-Tips/Testing-Software-Project-Management-Quality-Assurance-Agile-Security</guid><link>http://www.softwaretestpro.com/Item/5216/Three-Project-Tips/Testing-Software-Project-Management-Quality-Assurance-Agile-Security</link><author>matt.heusser@gmail.com</author><category>Testing</category><category>Software</category><category>Project Management</category><category>Quality Assurance</category><category>Agile</category><category>Security</category><title>Three Project Tips</title><description>Where Matt discussed three different dynamics on software projects -- and what to do about them</description><pubDate>Mon, 25 Jul 2011 10:54:27 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/5208/Ross-Collard---2011-Luminary-Award-Winner/Conference-Presentations-Test-and-QA-STP-Community-News-Software-Test-Professionals-Conference-Awards-Performance-Management-Security-Development-Functional-Leadership</guid><link>http://www.softwaretestpro.com/Item/5208/Ross-Collard---2011-Luminary-Award-Winner/Conference-Presentations-Test-and-QA-STP-Community-News-Software-Test-Professionals-Conference-Awards-Performance-Management-Security-Development-Functional-Leadership</link><author>rbaucom@redwoodcollaborative.com</author><category>Conference Presentations</category><category>Test and QA</category><category>STP Community News</category><category>Software Test Professionals Conference</category><category>Awards</category><category>Performance</category><category>Management</category><category>Security</category><category>Development</category><category>Functional</category><category>Leadership</category><category>Software</category><category>Strategy</category><category>Technology</category><category>Testing</category><category>Web</category><title>Ross Collard - 2011 Luminary Award Winner</title><description>Ross Collard has been called a “Jedi master” by the founding President of the Association for Software Testing. Other unsolicited statements call him a “giant of the field” with a “great wealth of knowledge”, and a “moral and intellectual thought leader”.</description><pubDate>Tue, 19 Jul 2011 13:00:00 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/5195/Security-Testing-%e2%80%93-Web-App-%e2%80%93-Some-Tips-For-Newbies/Security-Testing-Web</guid><link>http://www.softwaretestpro.com/Item/5195/Security-Testing-%e2%80%93-Web-App-%e2%80%93-Some-Tips-For-Newbies/Security-Testing-Web</link><author>st@moolya.com</author><category>Security</category><category>Testing</category><category>Web</category><title>Security Testing – Web App – Some Tips For Newbies</title><description>If you’re interested in security testing web applications, these tips will help a non-security tester to consider some techniques to get started. The world of security testing is perhaps the most important, yet it’s often the most neglected aspect to testing.  A lack of security testing opens an organization to business risks and could have severe implications to the financial future of a company.  If you haven’t made security testing part of your repertoire, consider integrating it today into your regular test suite.</description><pubDate>Tue, 05 Jul 2011 11:00:00 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/4977/Day-3---STPCon-2010-Final-Day/Software-Test-Professionals-Conference-Security-Testing</guid><link>http://www.softwaretestpro.com/Item/4977/Day-3---STPCon-2010-Final-Day/Software-Test-Professionals-Conference-Security-Testing</link><author>rbaucom@redwoodcollaborative.com</author><category>Software Test Professionals Conference</category><category>Security</category><category>Testing</category><title>Day 3 - STPCon 2010 Final Day</title><description>This is it, the final day of STPCon 2010 - What do we have planned? </description><pubDate>Thu, 21 Oct 2010 07:51:00 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/4919/Source-of-(test)-power----II/Software-Testing-Test-and-QA-Editorial-Security-Process</guid><link>http://www.softwaretestpro.com/Item/4919/Source-of-(test)-power----II/Software-Testing-Test-and-QA-Editorial-Security-Process</link><author>matt.heusser@gmail.com</author><category>Software</category><category>Testing</category><category>Test and QA</category><category>Editorial</category><category>Security</category><category>Process</category><title>Source of (test) power  - II</title><description>Where does power come from?</description><pubDate>Tue, 14 Sep 2010 04:57:05 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/4916/Cigital-Names-Peter-Esparrago-as-President/Management-Security-Services-Software-Research</guid><link>http://www.softwaretestpro.com/Item/4916/Cigital-Names-Peter-Esparrago-as-President/Management-Security-Services-Software-Research</link><author>jrovansek@redwoodco.com</author><category>Management</category><category>Security</category><category>Services</category><category>Software</category><category>Research</category><title>Cigital Names Peter Esparrago as President</title><description>DULLES, Va., September 07, 2010-Cigital, Inc., a leading software security consulting firm, today announced the appointment of Peter Esparrago as President.  Mr. Esparrago is a global technology executive with over 25 years of experience in a wide variety of industries.</description><pubDate>Mon, 13 Sep 2010 08:48:58 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/4880/Cigital-Releases-Groundbreaking-Software-Security-Training-for-Developers/Security-Software-Training</guid><link>http://www.softwaretestpro.com/Item/4880/Cigital-Releases-Groundbreaking-Software-Security-Training-for-Developers/Security-Software-Training</link><author>jrovansek@redwoodco.com</author><category>Security</category><category>Software</category><category>Training</category><title>Cigital Releases Groundbreaking Software Security Training for Developers</title><description>Cigital Releases Groundbreaking Software Security Training for Developers Immediate Feedback Provides Key to Long-Term Change</description><pubDate>Thu, 12 Aug 2010 14:00:00 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/4824/Quality-Vs-Quantity---I/Testing-Software-Test-and-QA-Trends-Exploratory-Security</guid><link>http://www.softwaretestpro.com/Item/4824/Quality-Vs-Quantity---I/Testing-Software-Test-and-QA-Trends-Exploratory-Security</link><author>matt.heusser@gmail.com</author><category>Testing</category><category>Software</category><category>Test and QA</category><category>Trends</category><category>Exploratory</category><category>Security</category><title>Quality Vs. Quantity - I</title><description>If culture is defined as things we believe that we aren't even aware of about how the world works, then when it comes to how to make decisions, there is a sort of culture war going on in the hearts of people all over the world.  Matt Heusser wants to talk about why he chose a road less travelled.</description><pubDate>Tue, 13 Jul 2010 00:02:32 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/4791/Security-Matters/Security-Software-Career-Web</guid><link>http://www.softwaretestpro.com/Item/4791/Security-Matters/Security-Software-Career-Web</link><author>matt.heusser@gmail.com</author><category>Security</category><category>Software</category><category>Career</category><category>Web</category><title>Security Matters</title><description>If you run your business on the web, then exposing all of your customer's data is just a security bug away</description><pubDate>Tue, 22 Jun 2010 05:00:48 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/4753/Security-Tools-Must-Support-An-Existing-Process-Not-Define-a-New-One/Security-Software-Test-and-QA-Testing-Best-Practices-Process-Regression-Tools</guid><link>http://www.softwaretestpro.com/Item/4753/Security-Tools-Must-Support-An-Existing-Process-Not-Define-a-New-One/Security-Software-Test-and-QA-Testing-Best-Practices-Process-Regression-Tools</link><author>dkosorok@ldschurch.org</author><category>Security</category><category>Software</category><category>Test and QA</category><category>Testing</category><category>Best Practices</category><category>Process</category><category>Regression</category><category>Tools</category><title>Security Tools Must Support An Existing Process Not Define a New One</title><description>Trying to introduce Security Testing into your software process can be tricky, just like teaching an old dog new tricks. A good first step would be to introduce a great security tool into an existing process. For example, introduce static source code analysis by adding it to the end of your automated build process. The initial ramp up cost is low, the change in process churn is low, but the value can be very high.</description><pubDate>Thu, 03 Jun 2010 10:04:44 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/4690/Oh-the-Irony!/Security-Software-Web</guid><link>http://www.softwaretestpro.com/Item/4690/Oh-the-Irony!/Security-Software-Web</link><author>matt.heusser@gmail.com</author><category>Security</category><category>Software</category><category>Web</category><title>Oh the Irony!</title><description>So last week I wrote an article for SearchSoftwareQuality on Quick Attacks for Web Security.</description><pubDate>Tue, 30 Mar 2010 13:30:36 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/3053/TQA--Review-%e2%80%9cThe-Definitive-Guide-to-Quality-Application-Delivery%e2%80%9d-by-Don-Jones-an-e-book/Performance-Membership-Life-Cycle-Development-Security-Functional-Software-Testing-Requirements</guid><link>http://www.softwaretestpro.com/Item/3053/TQA--Review-%e2%80%9cThe-Definitive-Guide-to-Quality-Application-Delivery%e2%80%9d-by-Don-Jones-an-e-book/Performance-Membership-Life-Cycle-Development-Security-Functional-Software-Testing-Requirements</link><author>rhand@softwaretestpro.com</author><category>Performance</category><category>Membership</category><category>Life Cycle</category><category>Development</category><category>Security</category><category>Functional</category><category>Software</category><category>Testing</category><category>Requirements</category><title>TQA- Review “The Definitive Guide to Quality Application Delivery” by Don Jones an e-book.</title><description>&lt;p&gt;If you are part of the &lt;span class="caps"&gt;STP&lt;/span&gt; community you have received the opportunity to download a new e-book, “The Definitive Guide to Quality Application Delivery” by Don Jones sponsored by Micro Focus. This guide is an extremely comprehensive effort, and I have been finding it very helpful in my education about the role of testing in the Software Development Life Cycle. As a quality/testing professional you may find it interesting for different reasons but I thought I would share some thoughts and try to encourage you to take advantage of this complimentary resource from &lt;span class="caps"&gt;STP&lt;/span&gt; on behalf of the book’s sponsor Micro Focus.&lt;/p&gt;
&lt;p&gt;This book is a complete guide so I can’t share it all but I chose some excerpts that I found interesting. The book is over 200 pages jammed packed with great resources for the testing professional and all functional roles in the development of quality applications. Don Jones does a great job organizing &amp;#8230;&lt;/p&gt;</description><pubDate>Tue, 30 Mar 2010 07:00:00 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/3031/Don%27t-Leave-Security-for-Last/Security-Metrics-Quality-Assurance-Management-Acceptance-Cloud-Functional-Testing-Requirements-Research-Web</guid><link>http://www.softwaretestpro.com/Item/3031/Don%27t-Leave-Security-for-Last/Security-Metrics-Quality-Assurance-Management-Acceptance-Cloud-Functional-Testing-Requirements-Research-Web</link><author>cec1e62c6abde98@stpcollab.com</author><category>Security</category><category>Metrics</category><category>Quality Assurance</category><category>Management</category><category>Acceptance</category><category>Cloud</category><category>Functional</category><category>Testing</category><category>Requirements</category><category>Research</category><category>Web</category><title>Don't Leave Security for Last</title><description>At the peak of the dot-com boom, my firm consulted extensively for large organizations concerned about the risks of Internet-based applications. My experience with one client in particular—we’ll call it Company X to protect its identity—remains the most palpable argument for integrating security throughout the software lifecycle.</description><pubDate>Wed, 03 Mar 2010 08:00:00 -0700</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/3029/Of-Security-Finance-and-Other-Practical-Matters/Editorial-Security-Load-Performance-Cloud-Software-Testing-Web</guid><link>http://www.softwaretestpro.com/Item/3029/Of-Security-Finance-and-Other-Practical-Matters/Editorial-Security-Load-Performance-Cloud-Software-Testing-Web</link><author>rcollar@attglobal.net</author><category>Editorial</category><category>Security</category><category>Load</category><category>Performance</category><category>Cloud</category><category>Software</category><category>Testing</category><category>Web</category><title>Of Security, Finance and Other Practical Matters</title><description>As guest editor for this issue of STP, I was asked to select the theme and to recommend authors. My theme can be summarized as “topics that intrigue me this month,” which (I claim) is more an enlightened than a haphazard assortment. I am proud to bring you some of the best new thinking in software security, financial software testing, practical experiences in performance testing, and testing centers of excellence.</description><pubDate>Mon, 01 Mar 2010 08:00:00 -0700</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/3035/Financial-Software-Testing/Agile-Performance-Security-Technology-Services-Exploratory-Load-Software-Testing-Web</guid><link>http://www.softwaretestpro.com/Item/3035/Financial-Software-Testing/Agile-Performance-Security-Technology-Services-Exploratory-Load-Software-Testing-Web</link><author>bernie@testassured.com</author><category>Agile</category><category>Performance</category><category>Security</category><category>Technology</category><category>Services</category><category>Exploratory</category><category>Load</category><category>Software</category><category>Testing</category><category>Web</category><title>Financial Software Testing</title><description>Wall Street crises and other market madness intensify the pressure to improve transparency, speed and accuracy.</description><pubDate>Mon, 01 Mar 2010 08:00:00 -0700</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/3017/The-Potential-of-Load-Testing-in-the-Cloud/Interviews-Security-Cloud-Load-Technology-Testing-Web</guid><link>http://www.softwaretestpro.com/Item/3017/The-Potential-of-Load-Testing-in-the-Cloud/Interviews-Security-Cloud-Load-Technology-Testing-Web</link><author>amuns@stpcollaborative.com</author><category>Interviews</category><category>Security</category><category>Cloud</category><category>Load</category><category>Technology</category><category>Testing</category><category>Web</category><title>The Potential of Load Testing in the Cloud</title><description>Andrew Muns sits down with Tom Lounibos, the CEO of SOASTA</description><pubDate>Mon, 01 Feb 2010 08:00:00 -0700</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/4660/Testing-Web-20-Apps/Security-Testing-Web</guid><link>http://www.softwaretestpro.com/Item/4660/Testing-Web-20-Apps/Security-Testing-Web</link><author>matt.heusser@gmail.com</author><category>Security</category><category>Testing</category><category>Web</category><title>Testing Web 2.0 Apps</title><description>I did at talk at STPCon this year on Testing Web 2.</description><pubDate>Wed, 06 Jan 2010 11:44:50 -0700</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/2971/The-Power-of-10/Test-and-QA-Security-Software</guid><link>http://www.softwaretestpro.com/Item/2971/The-Power-of-10/Test-and-QA-Security-Software</link><a10:author><a10:name>Gerard  Holzmann</a10:name><a10:email>8736d9b1bb65079@stpcollab.com</a10:email></a10:author><a10:author><a10:name>Michael McDougall</a10:name><a10:email>b81675597ffe01a@stpcollab.com</a10:email></a10:author><category>Test and QA</category><category>Security</category><category>Software</category><title>The Power of 10</title><description>In life-critical software, undiscovered bugs can be fatal. These simple rules can improve the quality and reliability of any application.</description><pubDate>Thu, 01 Oct 2009 07:00:00 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/2942/Use-Case-Schmoose-Case/Newsletters-Test-and-QA-Agile-Security-Performance-Cloud-Functional-Software-Testing-Web</guid><link>http://www.softwaretestpro.com/Item/2942/Use-Case-Schmoose-Case/Newsletters-Test-and-QA-Agile-Security-Performance-Cloud-Functional-Software-Testing-Web</link><author>224@stpcollab.com</author><category>Newsletters</category><category>Test and QA</category><category>Agile</category><category>Security</category><category>Performance</category><category>Cloud</category><category>Functional</category><category>Software</category><category>Testing</category><category>Web</category><title>Use Case, Schmoose Case </title><description>Someone failed to account for indecision, and it ruined a perfectly good TV experience. OK, no one died, but when a test team assumes that users know precisely what they want, they might be missing revenues from flip-flopping potential customers</description><pubDate>Tue, 15 Sep 2009 07:00:00 -0600</pubDate></item><item><guid isPermaLink="true">http://www.softwaretestpro.com/Item/2637/Static-Dynamic-Analysis-Separate-Cooperation/Best-Practices-Security-Services-Research-Web</guid><link>http://www.softwaretestpro.com/Item/2637/Static-Dynamic-Analysis-Separate-Cooperation/Best-Practices-Security-Services-Research-Web</link><author>joel@joelshore.com</author><category>Best Practices</category><category>Security</category><category>Services</category><category>Research</category><category>Web</category><title>Static, Dynamic Analysis: Separate Cooperation </title><description>Static and dynamic analysis—they run separately but work together.</description><pubDate>Fri, 01 May 2009 07:00:00 -0600</pubDate></item></channel></rss>