A Process for Performing Security Code Reviews
So in this month's IEEE Security and Privacy magazine Michael Howard wrote an interesting article on "A Process for Performing Security Code Reviews".
It's worth the read. His insights on how to prioritize what code to review first is something I think we all can learn from. I've never seen a calculation for bug density like that before. I wonder how effective that has been in the Microsoft code base?
Happy reading!
Posted by SilverStr at August 1, 2006 11:58 PM
| TrackBack