dimanche 11 janvier 2015

Security coding training best approach



To train the development team, there are various options one can take: inhouse presentation with code samples, CBTs so developers do it at their best time, instructor-led courses onsite or inhouse (expensive), using knowledge bases like http://ift.tt/1ATmt4Z


We sent a developer to a very expensive course, he came back, but he is not suddenly an expert, and the rest did not benefit from his knowledge. I bet he has forgotten everything now.


I am wondering, how would you get the best results and engagement from developers? I can imagine if we give them a whole bunch videos and CBT to watch, they will not really take it seriously. Do you think assigning each developer a type of attack and asking them to research and find defense best practices and code samples and present to the rest would engage them or deter them?





Aucun commentaire:

Enregistrer un commentaire