icon-carat-right menu search cmu-wordmark

Updating Risk Assessment in the CERT Secure Coding Standard

Podcast
This podcast explores proposed risk assessment updates to the CERT Secure Coding Standard.
Publisher

Software Engineering Institute

DOI (Digital Object Identifier)
10.58012/vbr5-wz95

Listen

Watch

Abstract

Evaluating source code to ensure secure coding qualities costs time and effort and often involves static analysis. But those who are familiar with static analysis tools know that the alerts are not always reliable and produce false positives that must be detected and disregarded. This year, we plan on making some exciting updates to the SEI CERT C Coding Standard to better harmonize with the current state of the art for static analysis tools as well as simplify the process of source code security auditing. In this SEI podcast, David Svobodaand Joseph Sible, both engineers in CERT’s Applied Systems Group and primary developers and maintainers of the standard, sit down with Robert Schiela, deputy technical director of the Cybersecurity Foundations Directorate in CERT, to discuss the proposed changes, specifically in the area of risk assessment.

About the Speaker

Headshot of David Svoboda.

David Svoboda

David Svoboda is a software security engineer at the CERT Division of the Software Engineering Institute. He co-authored or contributed to four books, including The SEI CERT C Coding Standard and The CERT Oracle Secure Coding Standard for Java. He also maintains the SEI CERT Coding Standards wiki and has …

Read more
Headshot of Joseph Sible

Joe Sible

Joe Sible is an associate software engineer in the Cybersecurity Foundations Directorate of the CERT Division at the SEI. He specializes in coding and Linux system administration. He has worked with DoD customers to ensure that secure coding rules are being followed and to implement DevSecOps practices. He also maintains …

Read more
Headshot of Robert Schiela

Robert Schiela

Robert Schiela is a technical manager, leading the Secure Coding group in the Cyber Security Foundations Directorate of the SEI CERT Division. In this role, he helps the Secure Coding team define and execute research and transition knowledge that improves the state of the art and practice in secure software …

Read more