We’ve talked at length before regarding software security assurance and the role static analysis can play in ensuring code is written securely. We’ve got a bunch of great resources for anyone looking to dive into this particular aspect of software security:
- Summary of various secure coding standards, including links to specific checkers supported by Klocwork
- Free secure coding e-learning courses, including an intro to Microsoft’s secure development lifecycle
- A ‘buyer’s guide’ to selecting a static analysis tool as part of a secure coding program authored by a major payment software company
To build on this, next month our CTO Gwyn Fisher and the CTO of Security Innovation, Jason Taylor will be hosting a talk that expands the discussion beyond secure coding strategies alone. Jason will be talking at length on how to build a threat model for software, in particular embedded software. Gwyn will then walk through how customers should be building their software with this threat model in mind – everything from code reviews to static analysis and testing strategies. I urge you to register for the webinar and check it out – there will be lots of good information being discussed.
I'm Klocwork's VP of Marketing and responsible for all of the company's product and channel marketing, communications, press relations, and demand generation activities. I've been in the development tools space for almost a decade, so will try to post interesting content related to industry or technology trends that I'm seeing. 
Hi there! I know this is somewhat off topic but I was wondering which blog platform are you using for this site? I’m getting fed up of WordPress because I’ve had issues with hackers and I’m looking at options for another platform. I would be fantastic if you could point me in the direction of a good platform.
Hi Dominic. We’re using WordPress for the main blog. For spam filtering, we’re currently using Akismet, which works to cut out most of the spam. A great platform I would recommend other than WordPress is Drupal because it’s modular and very powerful. All the best with finding a platform that works for you.
Yes, there will be an archived version of the webinar available.
This webinar conflicts with the Embedded Systems Conference. Will it be available for download or archived viewing?