Take a look at Mary Ann Davidson's keynote at ACSAC in Dec 2009. http://www.acsac.org/2009/program/keynotes/davidson.pdf
On Mon, Feb 22, 2010 at 9:17 AM, Benjamin Tomhave <list-s...@secureconsulting.net> wrote: > Howdy, > > This request is a bit time critical as it's supporting a colleague's > upsell up the food chain tomorrow... we're looking for hard research or > numbers that covers the cost to catch bugs in code pre-launch and > post-launch. The notion being that the organization saves itself money > if it does a reasonable amount of QA (and security testing) up front vs > trying to chase things down after they've been identified (and possibly > exploited). > > Any help? > > Thank you, > > -ben > > -- > Benjamin Tomhave, MS, CISSP > tomh...@secureconsulting.net > Blog: http://www.secureconsulting.net/ > Twitter: http://twitter.com/falconsview > LI: http://www.linkedin.com/in/btomhave > > [ Random Quote: ] > "Imagination is everything. It is the preview of life's coming attractions." > Albert Einstein > _______________________________________________ > Secure Coding mailing list (SC-L) SC-L@securecoding.org > List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l > List charter available at - http://www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) > as a free, non-commercial service to the software security community. > _______________________________________________ > _______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. _______________________________________________