<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Sherif Koussa</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Q&amp;A. Should Startups Care about Application Security?</style></title><secondary-title><style face="normal" font="default" size="100%">Technology Innovation Management Review</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">application security</style></keyword><keyword><style  face="normal" font="default" size="100%">architecture</style></keyword><keyword><style  face="normal" font="default" size="100%">checklists</style></keyword><keyword><style  face="normal" font="default" size="100%">code reviews</style></keyword><keyword><style  face="normal" font="default" size="100%">cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">design</style></keyword><keyword><style  face="normal" font="default" size="100%">detection</style></keyword><keyword><style  face="normal" font="default" size="100%">prevention</style></keyword><keyword><style  face="normal" font="default" size="100%">software security</style></keyword><keyword><style  face="normal" font="default" size="100%">startups</style></keyword><keyword><style  face="normal" font="default" size="100%">training</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2013</style></year><pub-dates><date><style  face="normal" font="default" size="100%">07/2013</style></date></pub-dates></dates><urls><web-urls><url><style face="normal" font="default" size="100%">http://timreview.ca/article/706</style></url></web-urls></urls><publisher><style face="normal" font="default" size="100%">Talent First Network</style></publisher><pub-location><style face="normal" font="default" size="100%">Ottawa</style></pub-location><volume><style face="normal" font="default" size="100%">3</style></volume><pages><style face="normal" font="default" size="100%">50-52</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><issue><style face="normal" font="default" size="100%">7</style></issue><custom1><style face="normal" font="default" size="100%">Software Secured
Sherif Koussa is Principal Application Security Consultant and founder of Software Secured, an application security firm. He has spent 14 years in the software development industry, with the last six years focused on testing application security, assessing security, and teaching developers to write secure code. He worked on the OWASP security teaching tool WebGoat 5.0, helped SANS launch their GSSP-JAVA and GSSP-NET programs, and wrote the blueprints of the Dev-544 and Dev-541 courses. In addition, he authored courseware for SANS SEC-540: VOIP Security. Sherif leads both the OWASP Ottawa Chapter and the Static Analysis Code Evaluation Criteria for WASC. He has performed security code reviews for three of the five largest banks in the United States. Before starting Software Secured, Sherif worked on architecting, designing, implementing, and leading large-scale software projects for Fortune 500 companies, including United Technologies, and other leading organizations such as Nortel Networks, March Healthcare, Carrier, Otis Elevators, and NEC Unified Communications.</style></custom1></record></records></xml>