Where does product security fit at your company?
jet <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <p06100414bcadc8f0fa37@[192.168.23.88]> |
This has come up in a couple of offline discussions with friends, thought I'd see what this group's experience is. Where does product security fit in your company's product development process? - integrated into everyone's workflow. Engineering and QE treat security as a product feature. - QA process only. QA verifies that a product is secure via test plan or hiring security QA specialists and files bugs against the product - security group within engineering. product development and QE develop products as they normally would, the security group is involved at various points to verify the product is secure - security group external to engineering. As above, but the group reports to Legal, Finance, IT, &tc. - outside consultants. at various points in the development process, consultants come in and find/fix security problems. - customers/hackers: wait until someone external reports a problem, then fix it. - other -- J. Eric Townsend -- jet spies com buy stuff, damnit: http://www.spies.com/jet/store.html