Security Checklist

Intent

This checklist is intended to be a starting point for the ApplicationReviewBoard to use when evaluating applications for PostReleaseApps. It is very important that while this checklist presents several items to think about, it should not be considered complete. Furthermore, this is not intended to catch malicious code (but may help in this regard). Malicious code can only be caught through detailed analysis and auditing, but can largely be prevented through social means (see below).

Checklist

Some thoughts on implementation

These aren't meant to be comprehensive by any means, but are included here since some of these techniques came up during our discussion

Other concerns

PostReleaseApps/SecurityChecklist (last edited 2010-11-18 23:11:17 by pool-71-114-246-100)