Re: [SC-L] Security as a part of code quality (Was: Re: Where Does Secure Coding Belong In the Curriculum?)

2009-08-21 Thread Gary McGraw
Actually CJC, it's often even worse than that. In many cases, the customer or consumer has an implicit requirement for security that remains unstated. Only when the system fails and is successfully attacked does that requirement shift from implicit to explicit. "You mean it wasn't secure?? Y

Re: [SC-L] Security as a part of code quality (Was: Re: Where Does Secure Coding Belong In the Curriculum?)

2009-08-21 Thread Cassidy, Colin (GE Infra, Energy)
Martin Gilje Jaatun wrote: > Karen, Matt & all, > > Goertzel, Karen [USA] wrote: > > I'm more devious. I think what needs to happen is that we > need to redefine what we mean by "functionally correct" or > "quality" code. If determination of functional correctness > were extended from "must o

[SC-L] Security as a part of code quality (Was: Re: Where Does Secure Coding Belong In the Curriculum?)

2009-08-21 Thread Martin Gilje Jaatun
Karen, Matt & all, Goertzel, Karen [USA] wrote: > I'm more devious. I think what needs to happen is that we need to redefine > what we mean by "functionally correct" or "quality" code. If determination of > functional correctness were extended from "must operate as specified under > expected co