Another note on code quality and security
A colleague sent me some welcome feedback on a recent post
(http://www.jwsecure.com/dan/2008/04/02/on-recent-press-coverage-and-cod
e-quality/).
Namely, that the effects of project and team dynamics can’t be ignored
when it comes to creating an environment that encourages the production
of high-quality, and highly secure, code. In other words, it’s not just
training and it’s not just having the latest tools. For example,
customer expectations and pressures, real or imagined, are transmitted
by sales and marketing, sometimes in negative ways, to the technical
team (PM/Dev/Test). Stress leads to mistakes, and aggressive timelines
mean that shortcuts get taken. This adversely affects code quality.
The feedback between external-facing and internal/technical teams must
be continuous and bidirectional.


Leave a Reply