Secure Offshore Development
Diana Kelley from Burton Group recently published a great article on what you should consider when outsourcing. She mentions application outsourcing. Normally organizations use NDA and threat of sudits to secure their code when outsourcing. From a security perspective there are ways to enhance protection of your organization’s IP resident within software when using off shore development resources. Rather then just providing source code, you could distribute the really sensitive components in complied form and still allow development around these. Of course if the risk of piracy or competitor access to code is high then software protection technology can be utilized to reduce these risks.
Vic