June 2006
Intermediate to advanced
352 pages
11h 27m
English
In this chapter:
You can’t test quality into a product, and you also can’t test security into it. If the product is written in an insecure manner, uses many insecure coding practices, or has a large attack surface, no amount of testing is going to make the product secure.
That said, you should provide a testing “sanity check” of the code before release. Testing is, of course, a necessary task, and anecdotal evidence indicates that as product groups at Microsoft release a subsequent product version covered by Security Development Lifecycle (SDL), engineers tend ...
Read now
Unlock full access