Hi all,

I'm wondering if anyone has seen any case-studies or references from
companies who have implemented a secure development process (eg, SDL
or similar) around the cost/effort involved, that they could direct me
to?

Obviously each development department is likely to be a unique case,
but that doesn't tend to stop management asking roughly what the costs
of a programme would be before spending a lot of time on scoping, so
any information would be useful.

So far, the only recent reference I've seen is this an Aberdeen Group
study 
http://download.microsoft.com/download/9/D/4/9D403333-C4F6-4700-A330-89661BE545CF/Aberdeen_SecureSource.pdf
so any more pointers would be gratefully received

Regards

Rory McCune
_______________________________________________
Secure Coding mailing list (SC-L) [email protected]
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates
_______________________________________________

Reply via email to