Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Management
[Top] [All Lists]

Re: Code Promotion/Release Management Practices

Subject: Re: Code Promotion/Release Management Practices
Date: Sat, 14 Jan 2006 11:56:30 -0800
This is part of the overall issue of change management. I wrote a pretty good article on it for Burton Group under "Change Management for the Enterprise" but unless your company subscribes I cannot get you a copy. It took the approach of change control ala several of the books I have written over the years including "A Short Course on Computer Viruses". If you look up:
"sound change control"


on Google you should get a lot of useful information - keep the "quotes" or you will get lots of irrelevant stuff.

Early on the list will be:
        http://all.net/CID/Defense/Defense121.html
which is very basic...

FC

On Jan 11, 2006, at 7:13 PM, Brad Bemis wrote:

I am looking for process resources that address code promotion/ release management from the time that an application has been developed and is ready for testing, to the point at which it is actually fully deployed in a production environment (not looking for the whole lifecycle right now). Something that talks about all of the ins and outs of controlling this particular portion of the overall software delivery process.

What I am interested in are good examples or white papers that address the issue. Please note that I am already drawing from the following:
COBIT
ISO 17799
ITIL
CMM/SSE-CMM/CMMI
ISF Standard of Good Practice
FFIEC IT Examiners Handbook
NIST 800 Series
A few other odds and ends
Am I missing something that speaks more directly to this subject?


Thanks in advance,
Brad Bemis, CISSP, CISA

-- This communication is confidential to the parties it is intended to serve --
Security Posture securityposture.com tel/fax
University of New Haven unhca.com 925-454-0171
Fred Cohen & Associates all.net 572 Leona Drive
ASP Press asp-presss.com Livermore, CA 94550



<Prev in Thread] Current Thread [Next in Thread>