I've Just released an article about how the Quality Assurance phase of the development cycle can incorporate security testing into a standard test plan, and make it part of the regular testing cycle. Writing Software Security Test Cases: Putting security test cases into your test plan http://www.qasec.com/cycle/securitytestcases.shtml - Robert admin_@_cgisecurity_com http://www.cgisecurity.com/ http://www.qasec.com/