Secure software means threat modeling, code review, penetration testing, and a plethora of other activities we take for granted. Right? Starting with Saltzer and Schroeder, this talk explores the origins, evolution, and use of these activities and others. Throughout, we share deployment experience and relate the discussion to living standards, such as Microsoft SDL, OWASP Top 10, and PCI DSS. Subscribe to our YouTube Channel / rsaconference Find us on Facebook / rsaconference Follow us on Twitter / rsaconference Visit our website at http://www.rsaconference.com