Agile Security

Even if we completely design our security stuff up front, and even if we manage to get it right, we're still not done. Because the app will continue to grow and change in ways we did not expect. Every feature we add must go through some kind of security review, whether or not we thought we covered it in our up front work. Security is [virtually] always an ongoing process, and [virtually] never a one-time task.
-Kevin Smith [on extremeprogramming]

June 14, 2003 03:46 PM


