Re: [SC-L] Darkreading: Secure Coding Certification

2007-05-16 Thread McGovern, James F (HTSC, IT)
As someone who has read your books, I am in full agreement that we should use much of the material contained to create an exam around design. Instead of making it a later thing, what would it take for folks on this list to have some sense of urgency and blast SANS to do it sooner? If any

Re: [SC-L] Darkreading: Secure Coding Certification

2007-05-16 Thread Gary McGraw
Hi all, I like this idea. There is plenty of non-code material to master in our field. I think a bunch of it is covered in detail in Software Security...but I am biased. I would like to see coverage of common attack patterns, coverage of risk analysis basics, and coverage of both positive