Re: Charging customers on security
[email protected] Wed, 29 Sep 2004 09:25:59 -0500
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <OF22A29074.5036807C-ON86256F1E.004E85DB-86256F1E.004F489D@kohls.com> |
Let me try to sum up...please correct me if I am wrong. "We want to charge the customer for delivering secure code." If that, in fact, is a valid summation, then I think your organization is completely off base. Saying you want to charge for security is analogous to charging for functionality. Of course your customers have a right to functional, secure code. In what environment would they not? If it is going to take X additional FTEs to deliver secure code and you need to push out a delivery date, that's one thing...but to then say to your customer "OH! You wanted 'secure' code? Well, that's going to cost you an additional X thousand dollars." is just plain wrong. What are you going to do, offer two versions of your software? I can see it now: "Brand X Solutions Suite, Secure, $175,000" or for our budget conscious clients "Brand X Solutions Suite, We Didn't Care When We Wrote It, $100,000" Great business model...good luck. Bart Lansing Manager, Desktop Services/Lotus Notes/Incident Response Kohl's IT King Pang <[email protected]> wrote on 09/23/2004 12:16:40 PM: > Hello, > > Our company developers Microsoft Solutions and I am responsible for > leading the security initiative in the corporation. I have spent a > lot of time and effort on how we should apply security guidance to our > product life cycle, such as adding threat modeling and doing security > review. But after I have convinced them that security is important, > we brought up a discussion on how we should charge our customers. > > Many of you have customer experience. They want to pay the minimum > and have all the features. If they can choose not to pay, they won't. > If we tell them threat modeling will add x human-weeks of development > and we have to charge them x thousand dollars more, they won't pay. > Moreover, they expect the system to be secure enough and if there is > anything wrong, they would think that is our fault. > > If any of you have any experience on dealing security with customers > and how you would deal with this issue, please throw in two cents. Any > comments or related articles would help too. > > Warm Regards.