Secure Coding mailing list archives
seeking hard numbers of bug fixes...
From: jeremy.j.epstein at gmail.com (Jeremy Epstein)
Date: Mon, 22 Feb 2010 10:45:02 -0500
Take a look at Mary Ann Davidson's keynote at ACSAC in Dec 2009. http://www.acsac.org/2009/program/keynotes/davidson.pdf On Mon, Feb 22, 2010 at 9:17 AM, Benjamin Tomhave <list-spam at secureconsulting.net> wrote:
Howdy, This request is a bit time critical as it's supporting a colleague's upsell up the food chain tomorrow... we're looking for hard research or numbers that covers the cost to catch bugs in code pre-launch and post-launch. The notion being that the organization saves itself money if it does a reasonable amount of QA (and security testing) up front vs trying to chase things down after they've been identified (and possibly exploited). Any help? Thank you, -ben -- Benjamin Tomhave, MS, CISSP tomhave at secureconsulting.net Blog: http://www.secureconsulting.net/ Twitter: http://twitter.com/falconsview LI: http://www.linkedin.com/in/btomhave [ Random Quote: ] "Imagination is everything. It is the preview of life's coming attractions." Albert Einstein _______________________________________________ Secure Coding mailing list (SC-L) SC-L at securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. _______________________________________________
Current thread:
- seeking hard numbers of bug fixes... Benjamin Tomhave (Feb 22)
- seeking hard numbers of bug fixes... Jeremy Epstein (Feb 22)
- seeking hard numbers of bug fixes... Jon McClintock (Feb 23)
- web apps are homogenous? Paco Hope (Feb 24)
- web apps are homogenous? Jon McClintock (Feb 24)
- web apps are homogenous? Benjamin Tomhave (Feb 25)
- web apps are homogenous? Chris Wysopal (Feb 26)
- seeking hard numbers of bug fixes... Jon McClintock (Feb 23)
- seeking hard numbers of bug fixes... Jeremy Epstein (Feb 22)
- seeking hard numbers of bug fixes... Benjamin Tomhave (Feb 22)