Skip to Content
The Myths of Security
book

The Myths of Security

by John Viega
June 2009
Beginner
260 pages
5h 40m
English
O'Reilly Media, Inc.
Content preview from The Myths of Security

Chapter 29. Application Security on a Budget

This chapter was coauthored with David Coffey, Director of SiteAdvisor and Product Security at McAfee.

A few big companies like Microsoft and Oracle have had enough security problems in their products that they’ve made massive investments in application security. For instance, the two of us frequently hear that Microsoft has invested at least $2 billion on the problem since about 2001.

Most companies aren’t so lucky (or, should we say, unlucky?). It’s tough to argue for budget, because, in most cases, it’s difficult to determine the value of product security activities. Here are the most important factors that will get people to spend time and resources on security:

Compliance

Some standards, like PCI (the payment card industry standard maintained by Visa), do require some product security activities in order to be compliant. Similarly, some customers, particularly parts of the U.S. government, may have requirements that software security work be done, such as external audits.

Brand

Frankly, software users are desensitized to security flaws. Most companies can handle a lot of security flaws without any real consequences for the public. Microsoft, Oracle, and big security companies are the exceptions, not the rule.

Customer demand

Sometimes customers do expect some security, particularly security features. For example, customers may occasionally ask for SSL support in an application.

Feature parity

If another product has a feature like SSL, competing ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Security Policies and Implementation Issues, 3rd Edition

Security Policies and Implementation Issues, 3rd Edition

Robert Johnson, Chuck Easttom
A Leader's Guide to Cybersecurity

A Leader's Guide to Cybersecurity

Thomas J. Parenty, Jack J. Domet
The Human Factor in AI-Based Decision-Making

The Human Factor in AI-Based Decision-Making

Philip Meissner, Christoph Keding

Publisher Resources

ISBN: 9780596803957Errata Page