Berkeley CSUA MOTD:Entry 25796
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2024/11/23 [General] UID:1000 Activity:popular
11/23   

2002/9/7-8 [Computer/SW/Languages/Web] UID:25796 Activity:nil
9/6     I need to write a Highly Secure (like banking/gambling level security)
        web application.
        Is Java any more secure than php (ceteris paribus).
        And what is the best way to go about getting an outside agency that
        will do a thorough audit when i'm done.  I don't need some h0zer to
        run a nessus/SAINT scan and throw it on some letterhead.
        \_ i'd trust java a bit more than php.  it's actually a main dev
           concern, where with php it seems like it's been an afterthought.
           take it with a grain of salt.  i'm a sysadmin, not a developer.
        \_ Concerning audits, I would do two types;  first of all, don't
           underestimate h0zers with nessus/SAINT.  Peer review is a Good
           Thing (tm).  Don't hesitate to ask people you know to hammer away
           at it.  You'll also, for the suits, want a (mainly pro-forma)
           formal audit--depending on your level of funding, you might want
           either a consultancy that does a lot of security work, like kpmg
           (ugh, disclaimer, I think they're all pretty worthless, but this
           is for the suits, remember), or one of any number of smaller
           outfits to have a go at it.  Otherwise, you can probably find
           someone CISA certified through ISACA (http://www.isaca.org with
           strong application audit clue.  If that's no good, mail me and
           I can probably help you find someone, obBlatantPlug.  -John
Cache (468 bytes)
www.isaca.org
Search, build, customize, download, interact, benchmark, evolve, govern. Based on COBIT control objectives, the authors have designed this publication primarily as an educational resource for IT control professionals, but CIOs, IT management and assurance professionals will find the information vitally important and beneficial as well. Find out about 56 other ISACA conferences and educational events. Topics include IS auditing standards, guidelines and procedures.