Assessing and managing Security risks unique to Java and .net
Sebastian C. Holst · 2009
Reverse engineering and modification of managed code (most notably .NET and Java applications) are well-understood and common practices. Legitimate scenarios include software debugging, technical support, and developer training. However, these same practices can present material organizational risk, including intellectual property theft, operational disruption, software piracy, and data loss. This article enumerates specific risks unique to managed code, guidance on assessing organizational materiality of these risks, and an inventory of broadly recognized risk-mitigation technologies and practices. t he rise of managed code – most everyone uses it somewhere