Microsoft Security slide deck
From Dana Epp...
Microsoft has released a slide deck and white paper on their Application Security Assurance Program.
Microsoft founded the Application Security Assurance Program (ASAP) to inventory, assess, and-when necessary-ensure resolution of security vulnerability issues found in line-of-business applications. Topics include the program's criteria for assessing applications, the participants in the review process, the requirements for a secure application environment, lessons learned while evaluating applications at Microsoft, and best practices for enhancing the security of applications in development.
This stuff is from the Microsoft IT group, which is the group that runs Microsoft's network infrastructure. The slide deck contains lots of good practical actions.