Re: [SC-L] Hiring folks that are familar with SC practices

2006-06-05 Thread Peter G. Neumann
Nice discussion. It arose years ago when software development managers typically had NO experience in software development, but were thought to be good managers. Many disasters ensued. The other side of the coin is that good developers are often TERRIBLE managers. I once wrote Psychosocial Im

Re: [SC-L] Hiring folks that are familar with SC practices

2006-06-05 Thread George Capehart
McGovern, James F (HTSC, IT) wrote: > Figured I would ask the list a question that I haven't figured out the answer > to. How have other enterprises that seek architects and developers > knowleedgable in secure coding software development practices articulated it > to their internal HR recruitin

Re: [SC-L] Hiring folks that are familar with SC practices

2006-06-04 Thread Gunnar Peterson
One of my colleagues referred to the current hiring situation for app sec folks as being analogous to looking for Apache webmasters in 1994. In his movie "He Got Game", Spike Lee cast NBA player Ray Allen in the lead role because he said that it was easier to teach basketball players to act than t

Re: [SC-L] Hiring folks that are familar with SC practices

2006-06-04 Thread ljknews
At 10:38 AM -0400 6/2/06, McGovern, James F (HTSC, IT) wrote: > Figured I would ask the list a question that I haven't figured out the >answer to. How have other enterprises that seek architects and developers >knowleedgable in secure coding software development practices articulated >it to their

[SC-L] Hiring folks that are familar with SC practices

2006-06-04 Thread McGovern, James F (HTSC, IT)
Title: Hiring folks that are familar with SC practices Figured I would ask the list a question that I haven't figured out the answer to. How have other enterprises that seek architects and developers knowleedgable in secure coding software development practices articulated it to their interna