Secure Coding mailing list archives

Re: Let's get the ball rolling -- secure application design tools/processes


From: Jerry Connolly <jerry () nologin net>
Date: Wed, 03 Dec 2003 17:35:12 +0000

George Capehart said the following on Tue, Dec 02, 2003 at 04:24:33PM -0500, 
Don't see much on the SSE-CMM, the relationship between the SDLC and 
the risk management process, or even how to make "The Process" more 
secure . . . That's what interested me . . .
 
On the subject of taking risks into account, it seems to be a tricky
adjustment for developers to make to start to do this.  However, they'll
rarely be able to justify spending time reading the risks digest or any
literature devoted to engineering failures.  Tutoring and/or guiding through
some examples seems like a good start, but are there any other activities or
guidelines that the readers of this list would recommend?

Thanks.

-- 
ejrry^[bxpZZ








Current thread: