Looks like SANS decided to take a side in the discussion that Amichai and I have Check out SANS NewsBites Vol. 10 Num. 49 (June 20, 2008).

"A surprising result appeared in the first large test of the secure coding assessment exams in Java and C: they found that programmers are exceptionally well versed in the types of vulnerabilities that may crop up, but shockingly unable to find and fix those vulnerabilities. Apparently security awareness classes do not solve the problem, but give false confidence."









Leave a comment