Shostack + Friends Blog

 

Conway's Law and Software Security

[no description provided]

In "Conway's Law: does your organization’s structure make software security even harder?," Steve Lipner mixes history and wisdom:

As a result, the developers understood pretty quickly that product security was their job rather than ours. And instead of having twenty or thirty security engineers trying to “inspect (or test) security in” to the code, we had 30 or 40 thousand software engineers trying to create secure code. It made a big difference.