Software security has come a long way in the last decade, moving from the original bug parade to integrated SDLC touchpoints. We've learned many lessons the hard way (the software security "zombies") as we have transitioned from faith-based software security to science. This session considers all that software security has accomplished along the way, up to and including the BSIMM. - See more at: http://www.rsaconference.com/events/eu13/agenda/sessions/550/bug-parades-zombies-and-the-bsimm-a-decade-of#sthash.tWlSLvNG.dpuf