<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.5.1" -->
<rss version="0.92">
<channel>
	<title>Secure Software Engineering Blog</title>
	<link>http://www.secure-software-engineering.com</link>
	<description>Blog for Secure Software Engineering and the development of secure software - including the Security Blog Monkey</description>
	<lastBuildDate>Sun, 09 Mar 2008 11:51:05 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Microsoft Security Risk Management Guide - Worth a look?</title>
		<description><![CDATA[The Security Risk Management Guide by Microsoft assists to place a plan for security risk management. This guide is technology agnostic and references many industry accepted standards for managing security risk. This guide uses industry standards to deliver a hybrid of established risk management models in an iterative four-phase process that seeks to balance cost and effectiveness. The Microsoft security risk management process enables organizations to implement and maintain processes to identify and prioritize risks in their IT environments. This guide seeks to clearly describe a process that organizations can follow to implement and maintain a security risk management program.]]></description>
		<link>http://www.secure-software-engineering.com/2008/02/27/microsoft-security-risk-management-guide-worth-a-look/</link>
			</item>
	<item>
		<title>Debugger and Sandboxes in Windows</title>
		<description><![CDATA[It is not always possible or desirable to set up a Virtual Machine for debugging an application. While useful, it can be boring to work within a VM, and on the other hand it can become an useless complexity. However, you need administrator&#8217;s privilege to debug (seDebugPrivilege turned on). And this means your debuggee will [...]]]></description>
		<link>http://www.secure-software-engineering.com/2008/02/23/debugger-and-sandboxes-in-windows/</link>
			</item>
	<item>
		<title>How secure is SSE-CMM?</title>
		<description><![CDATA[Let us cite from the SSE-CMM website:The SSE-CMM (The Systems Security Engineering Capability Maturity Model) [1] describes the essential characteristics of an organization&#8217;s security engineering process that must exist to ensure good security engineering. The model is intended to be used as a:

Tool for engineering organizations to evaluate security engineering practices and define improvements to [...]]]></description>
		<link>http://www.secure-software-engineering.com/2008/02/19/how-secure-is-sse-cmm/</link>
			</item>
	<item>
		<title>Insecure SPICE?</title>
		<description><![CDATA[
As process engineer I have been recently part of an SPICE (ISO/IEC 15504, Software Process Improvement and Capability dEtermination) assessment [1]. What SPICE is concerned about is the capability provided by the organization&#8217;s management and process definition structures. SPICE is not a methodology. Although SPICE sets out a list of activities that might (and should) [...]]]></description>
		<link>http://www.secure-software-engineering.com/2008/02/18/insecure-spice/</link>
			</item>
</channel>
</rss>
