Top 25 Software Programming Errors
Many IT security issues, from software patching to cyberespionage and cybercrime, can be traced to the top 25 software programming errors.
In software procurements, the Top 25 could well become a factor requiring software vendors to certify their software does not include these problems, Paller says. If it turns out software has such flaws, the vendor will have to take on extra work, without cost to the software buyer, to fix them.
Some users say the Top 25 will prove a boon.
"The CWE/SANS Top 25 effort is extremely valuable and will provide many organizations with a tangible way to begin addressing software security problems," said Michael Klosterman, SCADA operations, Western Area Power Association, U.S. Dept. of Energy, in prepared remarks.
MITRE



