I have a couple of blog posts modeling application vulnerabilities the way you might think of technical debt.
Part I: Application Security Debt and Application Interest Rates http://www.veracode.com/blog/2011/02/application-security-debt-and-application-interest-rates/ Part II: A Financial Model for Application Security Debt http://www.veracode.com/blog/2011/03/a-financial-model-for-application-security-debt/ -Chris
_______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates _______________________________________________