The Department of Homeland Security Software Assurance Program's "Enhancing the Development Life Cycle to Produce Secure Software" (which supercedes their previous guidance document on secure software development, "Security in the Software Life Cycle") can be downloaded - after free online registration - from the DoD Data and Analysis Center for Software's website at:
https://www.thedacs.com/techs/enhanced_life_cycles/ -- Karen Mercedes Goertzel, CISSP Booz Allen Hamilton 703.698.7454 [EMAIL PROTECTED]
_______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. _______________________________________________