[SC-L] implementable process level secure development thoughts

2008-03-11 Thread Andy Murren
I have been working on developing a series of documents to turn the ideas encompassed on this list and in what I can find in books articles. I am not finding, and it may just be I am looking in the wrong places, for any information on how people are actually implementing the concepts. I have

Re: [SC-L] implementable process level secure development thoughts

2008-03-11 Thread Gary McGraw
Hi Andy, We build and then execute plans to do that kind of activity all the time at Cigital. Unfortunately, the plans are all highly tailored to the politics and operations of our specific customers, and they are proprietary. Basically they do involve several aspects in common if you step

Re: [SC-L] implementable process level secure development thoughts

2008-03-11 Thread Wall, Kevin
Andy, You wrote... I have been working on developing a series of documents to turn the ideas encompassed on this list and in what I can find in books articles. I am not finding, and it may just be I am looking in the wrong places, for any information on how people are actually