Where does product security fit at your company?

jet <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <p06100414bcadc8f0fa37@[192.168.23.88]>
This has come up in a couple of offline discussions with friends, thought I'd see what this group's experience is.

Where does product security fit in your company's product development process?

- integrated into everyone's workflow.  Engineering and QE treat security as a product feature.

- QA process only.  QA verifies that a product is secure  via test plan or hiring security QA specialists and files bugs against the product

- security group within engineering.  product development and QE develop products as they normally would, the security group is involved at various points to verify the product is secure

- security group external to engineering.  As above, but the group reports to Legal, Finance, IT, &tc.

- outside consultants.  at various points in the development process, consultants come in and find/fix security problems.

- customers/hackers:  wait until someone external reports a problem, then fix it.

- other
-- 
J. Eric Townsend -- jet spies com
buy stuff, damnit: http://www.spies.com/jet/store.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.