

Gary McGraw
Building Security In
Software security as a discipline, and BSIMM
Rating
86Impact score
Domains
Software securitySecure designMeasurement
Scouting report
Wrote Building Secure Software, Exploiting Software and Software Security, making the case that you cannot test defects out of a system you designed insecurely. Co-created BSIMM, which measures what security programmes actually do rather than what a standard says they should, and has run a long-standing interview series documenting the field’s own history.
Curator’s note
Moved the argument from “scan it later” to “design it right”.
Sources
- 01Gary McGraw en.wikipedia.org
- 02BSIMM bsimm.com