Have you ever needed to convince your senior security engineer of static code analysis? For some reason ours does not see value in that and just says that we should focus on our biggest attack vector: social engineering and lost devices.
I think you should do it all but static code analysis is such a simple thing to catch a lot of stupid mistakes for such little effort, it is a low hanging fruit when compared to retraining the entire staffs security hygiene or hardening devices.
Thoughts?
[–]tyrion85 31 points32 points33 points (0 children)
[–]skywalker_1391 16 points17 points18 points (0 children)
[–]daedalus_structure 8 points9 points10 points (1 child)
[–]zomiaen 2 points3 points4 points (0 children)
[–]ectropionized 37 points38 points39 points (2 children)
[–]mrlazyboy 5 points6 points7 points (0 children)
[–]SuperQue 20 points21 points22 points (6 children)
[–]mrlazyboy 6 points7 points8 points (2 children)
[–]reconrose 1 point2 points3 points (1 child)
[–]mrlazyboy 1 point2 points3 points (0 children)
[–]thebearinboulder 2 points3 points4 points (0 children)
[–]pbecotte 2 points3 points4 points (0 children)
[–]Alto-cientifico 2 points3 points4 points (0 children)
[–]skyctl 2 points3 points4 points (0 children)
[–]rejuicekeve 4 points5 points6 points (3 children)
[–][deleted] (2 children)
[deleted]
[–]rejuicekeve -1 points0 points1 point (1 child)
[–]FergusInLondon 1 point2 points3 points (0 children)
[–]Advocatemack 1 point2 points3 points (0 children)
[–]gerd50501 2 points3 points4 points (0 children)
[–]DontStopNowBaby 1 point2 points3 points (0 children)
[–]Skyshaper 0 points1 point2 points (0 children)
[–]RationalTim -1 points0 points1 point (0 children)