Archive for the 'ACE Team' Category
« Mark Curphey - SecurityBuddha.com
home page
March 6, 2008
It’s true, I read about it in one of those productivity blogs you know; the ones that are so compelling that they actually make you totally unproductive while reading them. Boom boom, he’s on all night ladies and gentlemen. The gist of the post was that you should write down your five year goal in [...]
Categories: ACE Team, Cool Business, Platforms, Productivity, Ramblings, Security 2.0, Security Platforms, Working at Microsoft
Comments: Be the first to comment
February 28, 2008
It’s no real secret what I am doing at Microsoft although I haven’t really blogged about it much. I do plan to start in the coming weeks with some long posts about platforms, information security BPM, applying business management techniques to the information security discipline, dashboards and business intelligence etc.
Before I do that and hot [...]
Categories: ACE Team, Certification, Compliance, Dashboards, Information Security Economics, Microsoft, Security Industry, Visualization
Comments: 1 Comment
February 27, 2008
A warm welcome to Andreas Fuchsberger who joins our team next week. Andreas lectures application security on the Royal Holloway Information Security Masters Degree and among other things participates in the ISO Security Standards process. We worked together before at ISS, in the mid-nineties he was one of my lecturers and we are delighted to [...]
Categories: ACE Team, Microsoft
Comments: Be the first to comment
February 23, 2008
So I don’t get accused of jumping on the bandwagon in months to come, I have today drawn some new conclusions about platforms and “next.0″ Internet apps. As we all watch on to see if FaceBook topples back into the blue ocean or becomes a Google, my current conclusion is that I am simply bored [...]
Categories: ACE Team, Careers, Microsoft, Working Life, Working at Microsoft
Comments: 2 Comments
February 18, 2008
There is a nice video on the Virtual TechEd site here of RR, a Security Developer MVP.
Raffaele Rialdi sits down with Lori Grosland and explains his work with security and the software development life cycle. He also talks about threat modeling and how there are new ways that it is being used to identify [...]
Categories: ACE Team, Information Security Economics, Security Industry, Threat Modeling, Web Security, Working at Microsoft
Comments: Be the first to comment
January 25, 2008
Virtual labs, Videos and more
http://www.microsoft.com/click/hellosecureworld/default.mspx
Categories: ACE Team, Microsoft, Software Development, Software Security, Web Security, Working at Microsoft
Comments: 2 Comments
January 18, 2008
[I wrote this blog post at 30,000 ft, listening to KT Tunstall's Drastic Fantastic album on my way back from a week in Tel Aviv. ]
In the New Year my part of the ACE Team expanded to include our Israel operations and I have been lucky enough to have inherited Alik Levin and Nimrod Luria. [...]
Categories: ACE Team, Microsoft, Travel, Where in the World is Curphey, Working Life, Working at Microsoft
Comments: 2 Comments
January 17, 2008
My colleague and legendary Hummus eater Alik Levin (that’s my plate at lunchtime today but rumours are that he once ate two) has written an excellent post about how to use the Guidance Explorer to generate a checklist while performing security code reviews.
His first post on his personal blog is here and a more comprehensive [...]
Categories: ACE Team, Information Security Economics, Microsoft, Security Blogs, Software Development, Software Security, Threat Modeling, Web Security
Comments: 2 Comments
January 9, 2008
New article from John Steer on my team
Security Policies in the Application Development Process
Categories: ACE Team, Microsoft, Software Development, Software Security, Threat Modeling, Web Security
Comments: Be the first to comment
January 7, 2008
This paper from IEEE describes how Ford Motor Company use the Threat and Application Modelling tool from my team to improve the security of their business applications.
Abstract: “Ford Motor Company is currently introducing threat modeling on strategically important IT applications and business processes. The objective is to support close collaboration between IT Security & [...]
Categories: ACE Team, Threat Modeling, Visualization, Web Security, information security
Comments: 3 Comments
Recent Comments