hi sc-l, In the 4the episode of Reality Check, I interview Brad Arkin who runs the Software Security Group at Adobe. Brad worked for Cigital a million years ago and helped me found Cigital's SSG in 1997 (along with John Viega). He also worked for @stake and Symantec focusing on all aspects of software security with a special emphasis on training. His knowledge of software security, especially from an operational perspective is second to none. Among other things, we touch on the BSIMM.
http://www.cigital.com/realitycheck/show-004/ Reality Check is a podcast series devoted entirely to practitioners running real software security initiatives. Previous victims include Steve Lipner (Microsoft), Jim Routh (DTCC), and Eric Baise (EMC). The series is syndicated by CSO Online. Your feedback is welcome. gem http://www.cigital.com/~gem _______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. _______________________________________________