By Jeff Williams, Co-Founder, Chief Technology Officer
January 9, 2014
Here's the dirty little secret everybody in application security knows but few are willing to say out loud: Until you actually fix your code, you haven't actually improved your application security.
It sounds like a no-brainer. Really it does. But with traditional tools you might be working really hard just to generate a large pile of risks that you will triage, rank, sort, graph, and report. But after all this work, your code is just as insecure as before because at the end of the day, nothing really matters until you fix the code. You can run all the tools you want, but they don't change code. Humans change code. And changing the code is what matters most.
Some organizations are currently tracking thousands of risks in their software portfolio. Why aren't they just fixing them?
So you know the problems. And the irrationalities behind them. The question remains: What will you do with the knowledge you now have. Our Solution? Just Do It. Just make the change. And get focused on fixing code, not just finding problems.
You knew that was coming. For it's the same advice everyone gets when they are hemming and hawing between two decisions. It's the iconic advice Nike gives: "Just Do It".
Give Contrast a try.
So go ahead. Break free. Blaze new trails. Be original. And help your code and your business be more secure. Because until you actually fix your code, you haven't actually improved your application security.
Jeff brings more than 20 years of security leadership experience as co-founder and Chief Technology Officer of Contrast Security. He recently authored the DZone DevSecOps, IAST, and RASP refcards and speaks frequently at conferences including JavaOne (Java Rockstar), BlackHat, QCon, RSA, OWASP, Velocity, and PivotalOne. Jeff is also a founder and major contributor to OWASP, where he served as Global Chairman for 9 years, and created the OWASP Top 10, OWASP Enterprise Security API, OWASP Application Security Verification Standard, XSS Prevention Cheat Sheet, and many more popular open source projects. Jeff has a BA from Virginia, an MA from George Mason, and a JD from Georgetown.
Get the latest content from Contrast directly to your mailbox. By subscribing, you will stay up to date with all the latest and greatest from Contrast.