On Tue, 13 Mar 2007, Michael Silk wrote:

> no. my feeling is that it focuses management on unimportant things like
> meeting checkpoints rather then actually doing useful things.

While I understand the sentiment, one thing I don't know is:  how could
you measure "doing useful things" in any repeatable, cost-effective
fashion that does not ultimately boil down to checklists of one form or
another?

- Steve
_______________________________________________
Secure Coding mailing list (SC-L) SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
_______________________________________________

Reply via email to