OWASP / www-project-proactive-controls

OWASP Foundation Web Respository
Creative Commons Attribution Share Alike 4.0 International
129 stars 71 forks source link

Security patterns are not useful #30

Closed adamshostack closed 4 months ago

adamshostack commented 7 months ago

security patterns seem to be one of those ideas that are more theory than practice. (No one I've spoken with uses a set of patterns as part of their processes.) Why that, versus say 'security review', 'architecture review' or 'threat model'?

andreashappe commented 7 months ago

maybe discuss this in the context of #32