<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Secure By Default</title>
	<link>http://www.securebydefault.info</link>
	<description>Designing, building and testing software for better security</description>
	<pubDate>Mon, 18 Feb 2008 10:56:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
	<language>en</language>
			<item>
		<title>Integrating security into QA testing</title>
		<link>http://www.securebydefault.info/2008/02/18/integrating-security-into-qa-testing/</link>
		<comments>http://www.securebydefault.info/2008/02/18/integrating-security-into-qa-testing/#comments</comments>
		<pubDate>Mon, 18 Feb 2008 10:56:25 +0000</pubDate>
		<dc:creator>stephendv</dc:creator>
		
		<category><![CDATA[Testing]]></category>

		<guid isPermaLink="false">http://www.securebydefault.info/2008/02/18/integrating-security-into-qa-testing/</guid>
		<description><![CDATA[I wrote about this some time ago.  
Fortify are now doing a webinar on this topic.]]></description>
		<wfw:commentRss>http://www.securebydefault.info/2008/02/18/integrating-security-into-qa-testing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Security Testing with Watij</title>
		<link>http://www.securebydefault.info/2008/02/15/testing-with-watij/</link>
		<comments>http://www.securebydefault.info/2008/02/15/testing-with-watij/#comments</comments>
		<pubDate>Fri, 15 Feb 2008 20:07:21 +0000</pubDate>
		<dc:creator>stephendv</dc:creator>
		
		<category><![CDATA[Testing]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[security testing]]></category>

		<category><![CDATA[unit tests]]></category>

		<category><![CDATA[watij]]></category>

		<guid isPermaLink="false">http://www.securebydefault.info/2008/02/15/testing-with-watij/</guid>
		<description><![CDATA[Watij is a tool designed for functional web testing. It&#8217;s effectively a Java API which drives an instance of Internet Explorer. You can then use your favourite unit testing framework to structure tests and make assertions of the results. Like similar functional testing tools, watij can be used to script security defects in web applications. [...]]]></description>
		<wfw:commentRss>http://www.securebydefault.info/2008/02/15/testing-with-watij/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Defining security requirements</title>
		<link>http://www.securebydefault.info/2008/01/12/defining-security-requirements/</link>
		<comments>http://www.securebydefault.info/2008/01/12/defining-security-requirements/#comments</comments>
		<pubDate>Sat, 12 Jan 2008 21:02:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Design]]></category>

		<category><![CDATA[Secure SDLC]]></category>

		<category><![CDATA[security requirements]]></category>

		<category><![CDATA[security standards]]></category>

		<guid isPermaLink="false">http://www.twisteddelight.org/security-testing/2008/01/12/defining-security-requirements/</guid>
		<description><![CDATA[The vast majority of security assessments I&#8217;ve worked on have used &#8220;best practice&#8221; to define the security requirements of the application under test.  Clients are content to rely on security assessment firms to decide what should and shouldn&#8217;t be tested, and this is usually OK for bug hunting.  But apart from the well known [...]]]></description>
		<wfw:commentRss>http://www.securebydefault.info/2008/01/12/defining-security-requirements/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
