Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

2/25/2013
05:36 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

SAFECode Names Howard Schmidt Executive Director

The former White House cybersecurity adviser brings to SAFECode more than 40 years of information security experience

San Francisco (RSA Conference) – February 25, 2013 – The Software Assurance Forum for Excellence in Code (SAFECode), a non-profit organization dedicated to increasing trust in information and communications technology products and services through the advancement of effective security assurance methods, today announced it has named former White House cybersecurity advisor Howard A. Schmidt as its Executive Director.

Schmidt brings to SAFECode more than 40 years of information security experience, spanning defense, law enforcement, and corporate security. Most recently, Schmidt served as Special Assistant to the President and the Cybersecurity Coordinator for the U.S. government from 2009 to 2012. In this role, he was responsible for coordinating interagency cybersecurity policy development and implementation, and for coordinating engagement with federal, state, local, international and private sector cybersecurity partners.

"SAFECode has always been focused on a technical mission – identifying and promoting the most effective methods for increasing trust in commercial technology products and services. However, we can't do this work in a bubble," said Steve Lipner, Chairman of the SAFECode Board of Directors and Partner Director of Program Management, Trustworthy Computing Security for Microsoft Corporation. "We must work together with customers and governments to foster a dialogue on software assurance, and ensure that our technical efforts have the most positive impact possible on the security challenges we all face. Howard's unmatched experience in bringing technical experts together with defense, law enforcement and business leaders will help SAFECode to not only execute its technical mission, but also increase our global reach."

Schmidt has had significant experience leading international security associations and forums throughout his career. He has served as President of both the Information Security Forum (ISF) and Information Systems Security Association (ISSA). Schmidt also was the co-founder and first president of the Information Technology Information Sharing and Analysis Center (IT-ISAC). He was the Vice-Chair of, and Security Strategist for, the Board of Directors for (ISC)2. He is a former executive board member of the International Organization of Computer Evidence, and served as the Co-chairman of the Federal Computer Investigations Committee.

"With more headlines everyday, cybersecurity has caught the attention of business leaders and governments worldwide. Though software assurance is rarely the subject of those stories, there are experts in product security doing important work to reduce vulnerabilities in our technology infrastructure and improve its resistance to attack," said Howard Schmidt, executive director of SAFECode. "SAFECode brings together many of our most experienced software security professionals in a unique global collaboration that can have a real impact on the security of our technology infrastructure. As its Executive Director, I look forward to working with the members to advance and promote the practice of software assurance."

About SAFECode


The Software Assurance Forum for Excellence in Code (SAFECode) is a non-profit organization exclusively dedicated to increasing trust in information and communications technology products and services through the advancement of effective software assurance methods. SAFECode is a global, industry-led effort to identify and promote best practices for developing and delivering more secure and reliable software, hardware and services. Its members include Adobe Systems Incorporated, EMC Corporation, Intel Corporation, Microsoft Corp., SAP AG, Siemens AG and Symantec Corp. For more information, please visit www.safecode.org.

Membership in SAFECode is open to commercial technology providers with significant global business activity in hardware, software and/or services and that have demonstrated a commitment, and dedicated resources, to software assurance. For more information, please visit www.safecode.org.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Human Nature vs. AI: A False Dichotomy?
John McClurg, Sr. VP & CISO, BlackBerry,  11/18/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: -when I told you that our cyber-defense was from another age
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-3350
PUBLISHED: 2019-11-19
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
CVE-2011-3352
PUBLISHED: 2019-11-19
Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context ...
CVE-2011-3349
PUBLISHED: 2019-11-19
lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.
CVE-2019-10080
PUBLISHED: 2019-11-19
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI ...
CVE-2019-10083
PUBLISHED: 2019-11-19
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.