Re: [SC-L] Software process improvement produces secure software?

2007-08-29 Thread McGovern, James F (HTSC, IT)
: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Goertzel, Karen Sent: Tuesday, August 07, 2007 9:39 AM To: sc-l@securecoding.org Subject: Re: [SC-L] Software process improvement produces secure software? I've always had a question about this as well; specifically, what is really meant

Re: [SC-L] Software process improvement produces secure software?

2007-08-09 Thread George Capehart
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Kenneth Van Wyk wrote: On Aug 7, 2007, at 7:01 AM, Francisco Nunes wrote: During our conversation, I made a question to Mr. Hayes similar to this: Is it possible that only software development process improvements can produce secure software?

Re: [SC-L] Software process improvement produces secure software?

2007-08-08 Thread Kenneth Van Wyk
On Aug 7, 2007, at 7:01 AM, Francisco Nunes wrote: During our conversation, I made a question to Mr. Hayes similar to this: Is it possible that only software development process improvements can produce secure software? The scenario was only based on CMMI without security interference. All

[SC-L] Software process improvement produces secure software?

2007-08-07 Thread Francisco Nunes
Dear list members. In june 2007, I had an interesting conversation with Mr. Will Hayes from SEI during the Brazilian Symposium on Software Quality. It was a great experience and I am very grateful for this. During our conversation, I made a question to Mr. Hayes similar to this: Is it possible

Re: [SC-L] Software process improvement produces secure software?

2007-08-07 Thread Goertzel, Karen
] Software process improvement produces secure software? Dear list members. In june 2007, I had an interesting conversation with Mr. Will Hayes from SEI during the Brazilian Symposium on Software Quality. It was a great experience and I am very grateful for this. During our conversation, I made

Re: [SC-L] Software process improvement produces secure software?

2007-08-07 Thread Julie Ryan
A simple way to understand why implementing software development process improvement will not necessarily produce secure software is to read the Common Criteria. yes, I know that it's opaque and hard to understand, but once you have gone through the process of writing a Protection Profile for