« Microsoft Security Intelligence Report | Main | Opinion on the veto of AB779 »

SFDC - AppExchange Certification Process

I was chatting to a techie from SalesForce.com a couple of evenings ago and questioning him about the processes in place for ensuring the security of applications posted on their AppExchange. It's a pretty comprehensive process and one that might be useful to adapt for your own development work. The questionnaires used in the assessment process are available online here and well worth a look.

The associated spreadsheets are comprehensive enough although I will level a couple of criticisms: they look sloppy in the way they are presented and are not easy to follow. I'd also apply weightings to the various sections and use the questions responses to calculate a risk score based on the risk profile of the application in question (similar to the process used within my own organisation). For instance, for some applications, some questions might be more necessary to answer yes to than others. Because the assessment is going to potentially be used against thousands of applications, some benchmarking and scoring system could be useful - both to SFDC and to the developer.

Perhaps then SFDC could keep a league table based on assessment scores. Just a thought...

TrackBack

TrackBack URL for this entry:
http://www.computerweekly.com/cgi-bin/mt/mt-tb.cgi/13687

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on October 25, 2007 6:15 AM.

The previous post in this blog was Microsoft Security Intelligence Report.

The next post in this blog is Opinion on the veto of AB779.

Many more can be found on the main index page or by looking through the archives.