Re: [SC-L] Agile (Scrum) best security practices and experiences?

2010-09-14 Thread Antti Vähä-Sipilä
Dave said: I then did a reprise/updated version at OWASP AppSec US in NY in 2008. The slides and a video of the presentation are available here: http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference I did see Dave's OWASP slides earlier, but for some reason I never found or watched

Re: [SC-L] Agile (Scrum) best security practices and experiences?

2010-09-09 Thread Rohit Sethi
Agile shops tend to put a premium on lightweight processes that minimize impact on iteration timelines. Some of the key differences we've seen work in agile shops rather than waterfall include: * Aversion to documentation * Heavy reliance on collaborative tools, such as bug tracking and wikis

Re: [SC-L] Agile (Scrum) best security practices and experiences?

2010-09-08 Thread Jari Pirhonen
8.9.2010 11:37, Martin Gilje Jaatun kirjoitti: I may have mentioned before on this list that my dream is to do an in-depth comparative study of traditional and agile development organizations to determine which produces the best (i.e., most secure) code? The first challenge would be to figure