[SC-L] Really dumb questions?

2007-08-29 Thread McGovern, James F (HTSC, IT)
Most recently, we have met with a variety of vendors including but not limited to: Coverity, Ounce Labs, Fortify, Klocwork, HP and so on. In the conversation they all used interesting phrases to describe they classify their competitors value proposition. At some level, this has managed to confuse m

Re: [SC-L] Software process improvement produces secure software?

2007-08-29 Thread McGovern, James F (HTSC, IT)
One thing that I am firm in my belief is that process is not a substitute for competence. Imagine taking lots of overweight IT guys and training them to ride a horse. That doesn't mean that they will go on to become successful horse jockeys and you would be dumb to bet on them. In terms of CMM