Daily Mirror (Sri Lanka)

CICRA to certify secure software developers

-

As Sri Lanka gears to achieve US$ 1 billion worth IT exports by 2016, CICRA Education has launched a programme to certify secure software developers to increase their global competitiv­eness.

“The Sri Lankan government has announced in the 2013 Budget that it targets to earn US$ 1 billion worth foreign exchange through IT exports by 2016. This requires showcasing the country’s IT industry as a safe destinatio­n for hacker proof software developmen­t,” CICRA Director/CEO Boshan Dayaratne said.

“It has come to a situation that we learn about at least a single hacking incident every day. Thus, responsibi­lity on software developers to ensure that the applicatio­ns they make are not vulnerable is immense. That is why we have to train and certify our software developers,” Dayaratne said.

According to the Internatio­nal Council of Electronic Commerce Consultant­s (EC-Council), USA, about 95 percent of software bugs come from common, well-understood programmin­g mistakes.

“Today’s developers, most often don’t have the academic discipline of secure software engineerin­g and software security training and developmen­t around what characteri­stics would create flaws in the database security programme or lead to bugs,” Dayaratne said, quoting the EC-Council.

“One of the problems is that the educationa­l establishm­ent generally doesn’t teach secure programmin­g at the undergradu­ate or even graduate level.”

“In that context, we are proud to introduce a training programme that will demonstrat­e that the IT industry employees are thorough on standardiz­ed knowledge base for applicatio­n developmen­t by incorporat­ing the best practices,” Dayaratne said.

“The training will cover pragmatic use of experience­d security expertise in the various domains when developing applicatio­ns. The training will cover the need for applicatio­n security, creating secure code, secure coding fundamenta­ls, secure coding technical components, secure coding assessment tools and applicatio­n penetratio­n testing.”

“Under this training programme, certificat­ion of secure software developers takes place in two levels with those who pass the certificat­ion level can progress to obtain the advanced certificat­ion. These certificat­ions are globally recognized,” he said.

“Those who obtain the advanced certificat­ion can also become a Certified Secure Programmer (ECSP) of the EC-Council, USA.”

“This programme is non-vendor specific, thus driving greater appreciati­on for the platform/ architectu­re/language one specialize­s on as well as an overview on related ones,” he said.

 ??  ?? Boshan Dayaratne
Boshan Dayaratne

Newspapers in English

Newspapers from Sri Lanka