Some Surprises in the New New York Cybersecurity Regulations

eschuman's picture
By Evan Schuman February 2, 2017  | Security News

In the US, there exist no meaningful national cybersecurity rules, but, as a practical matter, that is likely to change this year. But it's not coming from Congress. The catalyst is new rules slated to start in March from the New York State Department of Financial Services. In financial areas, that New York department is typically mimicked by a wide range of other state regulators, along with... READ MORE

Podcast: AppSec in Review - Making Sense of the New York DFS Cybersecurity Regulations

sciccone's picture
By Suzanne Ciccone January 28, 2017  | Security News

The New York Department of Financial Services recently issued proposed regulations for cybersecurity that seek to standardize the way that financial services institutions protect information systems and the business and personal information they manage. Organizations covered by the new cybersecurity regulation include banks and trust companies, insurance companies, mortgage lenders, investment... READ MORE

My Advice to Software Vendors: Answer Security Questions Before Your Customers Start Asking

chausammann's picture
By Christine Hausammann January 27, 2017  | Managing AppSec
Answer Security Questions Before Your Customers Start Asking

Companies that sell software for a living are gradually facing more and more pressure to cough up proof of security for their products. Working on the business development team at Veracode, I’ve seen this tidal wave growing, and my best advice to software vendors is to be proactive. If you learn what to expect and how to answer different attestation requests, you’ll be ahead of many... READ MORE

Podcast: Challenges of the Digital Economy

sciccone's picture
By Suzanne Ciccone January 26, 2017  | Security News

The digital innovations used by companies are making it easier for companies to improve their productivity. They also remove barriers for startups to enter new markets and make our everyday lives easier. However, the digital economy comes with challenges and risks. During the fifth installment of Veracode’s Cyber Second Podcast, Brian Fitzgerald, CMO at Veracode discusses the challenges... READ MORE

How We’re Making Developer Training More Interactive, Flexible and Fun

eying's picture
By Emilie Ying January 24, 2017  | Secure Development
Veracode video-based developer training

Everyone knows security training is important. But many organizations struggle to make security training more effective. At Veracode, we’ve implemented several innovations to make our eLearning platform even more engaging, relevant, user-friendly and fun. Over the past five years, we have continued to add online courses to keep up with the changing climate of threats in the real world,... READ MORE

Securing DevOps: Enough With the Cynicism

jlavery's picture
By Jessica Lavery January 23, 2017  | Secure Development
Cynicism about devops is popular initially.

If an industry continuously talks about how a trend is going to be a hurdle, it becomes a hurdle. Conversely, if an industry views the trend as an opportunity and talks about it in such terms, thinking shifts toward the potential this trend brings for improvement. We are seeing this phenomenon with DevOps, but not in a good way. Security professionals are talking about the hurdles of securing... READ MORE

Apple's Abandonment Of Its Own App Security Deadline Is Bad For So Many Reasons

eschuman's picture
By Evan Schuman January 16, 2017  | Security News

Have a great idea for the most effective way to make life easier for cyberthieves, especially those who are focused on ineffective app security. All you have to do is get one of the most powerful brands in computing to publicly declare a security deadline and then have it quietly withdraw that deadline on the eve of it being effective. For a terrific example of well this can undermine app... READ MORE

What’s the Worst That Can Happen? The Cost of a “Wait and See” AppSec Plan

sciccone's picture
By Suzanne Ciccone January 10, 2017  | Managing AppSec

In a previous blog post, we talked about the cost of a “do nothing” AppSec plan. In that blog post, we pointed out that ignoring application security can be a costly move. Why? Because your chance of a breach is very high, and so is the cost incurred from most breaches. In addition, you could now face regulatory fines by ignoring application security. But a “wait and see”... READ MORE

The Five Parts of Third-Party Application Security

gjames's picture
By Griff James January 5, 2017  | Managing AppSec

Third-party application security assurance is an essential part of a mature IT security program. While it’s true that every company today is a software company, the majority of applications within an enterprise’s application portfolio will be developed by third parties – often as off-the-shelf products.  A study by Quocirca found that the average enterprise has roughly 600... READ MORE

Can You Defend Your AppSec Program? Be Ready to Answer These Questions

jzorabedian's picture
By John Zorabedian January 3, 2017  | Managing AppSec

Every AppSec manager needs to work with stakeholders across the organization, from the CISO to development, and departments making their own decisions about buying the software they depend on to do their jobs. If you want to earn buy-in for your AppSec program, you’ll have to be responsive to different concerns for each type of stakeholder. To help you, we offer this list of questions you... READ MORE

Love to learn about Application Security?

Get all the latest news, tips and articles delivered right to your inbox.

 

 

 

contact menu