^^ ill check out the github. i have some topics on the CISSP covering software security. only dipped into to it a bit so far. but i learned about architecture diagrams... pretty cool... do a reduction analysis of a system or program (break it down logically to see how data reacts with everything) and draw up an architecture diagram of a small network. label all systems (after their reduction analyses) with version numbers, OSs, apps installed, all that crap, label all connections between them, all protocols used.... and then come up with a list off all threats and vulnerabilities in all systems, applications, and connections.
i'll have a whole couple chapters on application security and i can't wait to get to it. it's towards the end of my textbook though. i suck at programming but i find app security very interesting.
adarqui what do you do for a living? secure coders make a ton of freaking money... i would do that if i were a software engineer. i mean A LOT of money! (ICS)2 CSSLP is a good cert. So is GIAC GSSP.