We know that many development teams, especially small teams following Agile development practices, do a poor job of developing secure software. But is it Agile development specifically that is the problem? Many application security experts, especially those working in or for enterprises, think it is. I think they are wrong.
Read my latest post at the SANS AppSec Street Fighter blog on how Agile development teams CAN build secure software.