<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Security in the SDLC is not just code review</title>
	<link>http://www.tssci-security.com/archives/2008/03/24/security-in-the-sdlc-is-not-just-code-review/</link>
	<description>top secret/secure computing information</description>
	<pubDate>Fri, 08 Aug 2008 18:16:05 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: roodee</title>
		<link>http://www.tssci-security.com/archives/2008/03/24/security-in-the-sdlc-is-not-just-code-review/#comment-5276</link>
		<dc:creator>roodee</dc:creator>
		<pubDate>Tue, 25 Mar 2008 15:17:27 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2008/03/24/security-in-the-sdlc-is-not-just-code-review/#comment-5276</guid>
		<description>It is a sad state of affairs when the PCI DSS requirements become the litmus test for "Security in the SDLC". Like you, I've tried to inform well-intentioned people and groups that code review is a only a component in an overall application security program . After the blank stares subside I reflect on the many applications I have reviewed that are fundamentally flawed in their approach or design. In my opinion, if code-review is the only security checkpoint in the design and construction of an application then there are implicit assumptions, many times hidden, about the quality of a design. This is a dangerous assumption to bet on.</description>
		<content:encoded><![CDATA[<p>It is a sad state of affairs when the PCI DSS requirements become the litmus test for &#8220;Security in the SDLC&#8221;. Like you, I&#8217;ve tried to inform well-intentioned people and groups that code review is a only a component in an overall application security program . After the blank stares subside I reflect on the many applications I have reviewed that are fundamentally flawed in their approach or design. In my opinion, if code-review is the only security checkpoint in the design and construction of an application then there are implicit assumptions, many times hidden, about the quality of a design. This is a dangerous assumption to bet on.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.170 seconds -->
