Sorry for the deluge of posts today, I have been collecting up these tidbits and finally had a bit of time to post them.
In a past life, i was the Technical Lead for Security for a large corporation. I still think like a secuirty guy (or a hacker, depends on which side of the fence you are on :-) ) and I always try to help people take the security considerations for thier architecture into account.
Microsoft has released some great guidance around threat modeling and has some patterns and prescriptive guidance in mitigating common threat scenario's.
Check out the downloads section, there's a threat modeling tool that the ACE team has released, there's also some great articles on writing secure code, code access security and securing your web or windows application. I know that the more you try to make your application secure, the mor ...