Corporation waits until the software flaw trends on Twitter

They Wait Until the Software Flaw Trends on Twitter

May 03, 2013
By Derek Weeks

2 minute read time

Here is another post on my favorite quotes from the Security at the Speed of Development webinar with Wendy Nather, Research Director, Security for 451 Research and Ryan Berg, Sonatype CSO. Wendy was talking about how inertia makes it difficult to justify fixing security flaws later in the SDLC:

Wendy also noted the need to protect the entire supply chain, including assets sourced from third parties. Her Twitter reference implied that some suppliers will not address security flaws until negative publicity forces them to act.

There are multiple reasons flaws are not fixed: lack of budget, poor project planning, shifting resources, etc. Another factor is that today's security tools focus on discovery, they don't help you fix problems. Ryan went on to say:

We took this challenge into account when we designed the Sonatype CLM. Not only does the CLM help you identify security, licensing and quality flaws, it helps you prioritize and fix the problems directly in the IDE.

To see how you can fix flaws with the Sonatype CLM, check out the "Quickly identify your exposure and remediate flaws" section of the product tour.

Make sure you read Wendy's research Mission Impossible: securing the open source software supply chain with Sonatype.

Written by Derek Weeks
Derek serves as vice president and DevOps advocate at Sonatype and is the co-founder of All Day DevOps, an online community of 65,000 IT professionals.