December 2007 - Posts

Four Stages of Market Maturity
You can tell the maturity of a market by the consumer patterns. If you know the life cycle stages of a market you can better anticipate what level of "needs" your product needs to match to be successful. (I always think of needs in stages like Maslow's Read More...
Love Your Dogs
I read an interesting article on behavioral economics by Harry Quarls, Thomas Pernsteine, and Kasturi Rangan, in "strategy+business" magazine. According to the authors, behavioral finance supports a counter-intuitive strategy of loving your market "dogs" Read More...
Kano, Satisfiers, and Dissatisfiers
If you're looking for yet another way to help you prioritize your backlog or to help you shape your product's design, consider the Kano model . One concept in the Kano model is satisfiers and dissatisfiers. You can think of satisfiers as features you Read More...
Rituals for Results
Routines help build efficiency and effectiveness. Consistent action over time is the key to real results. If you add continuous improvement or Kaizen to the picture, you have an unbeatable recipe for success. The following are some of my rituals for results: Read More...
Forcing Functions
Do you have a favorite set of forcing functions? In patterns & practices, one of our forcing functions is building a slide deck. Building a deck is a forcing function because it forces us to distill the points, close down on issues, identify what Read More...
Kaizen
Kaizen is a Japanese term for continuous improvement. A little Kaizen goes a long way over time. From a personal development standoint, it's key for overcoming resistance . Read More...
Building Books in patterns and practices
Book building is art and science. I've built a few books over the years at patterns & practices. In this post, I'll share a behind the scenes look at what it takes to do so. I'll save the project management piece for another day, and focus on the Read More...
CodePlex, GE, and MSDN
One of the questions I get is how we build and publish our guides and what's the relationship of CodePlex , GE and MSDN . At a high-level, we build reusable guidance nuggets for customer questions and tasks. We then build a larger guide to bring the nuggets Read More...
SDL for Apps and Verticals
What's one path the SDL (Security Development Life Cycle) can take to amplify impact? From my perspective, I think the key is specialization for app types and verticals. I base this on lessons learned from shaping prescriptive guidance over the years, Read More...
Posted 21 December 07 01:29 by J.D. Meier | 1 Comments   
Filed under
Getting Started with Threat Modeling
Threat Modeling is a way to identify potential security issues to help you shape your application's security design. If you need to create a threat model, and you aren't sure how, here's some links to get you started. (Note that our patterns & practices Read More...
Posted 20 December 07 03:17 by J.D. Meier | 4 Comments   
Filed under
Video: Proven Practices for Security Engineering
This is an oldie but a goodie. Alex (from our original team) walks through our patterns & practices Security Engineering Approach. I knew the video exists, but I had a hard time finding it again so I'm posting the link here. Video MSDN Architecture Read More...
Posted 20 December 07 02:39 by J.D. Meier | 3 Comments   
Filed under ,
Three keys of a business case
If you have to compete for resources or budget or sell an idea, one of the keys is a business case. One way to think of a business case is "how big is the pie" and "what's your slice." You use the business case either to argue for your project or in argument Read More...
The Five P's
How do you design an org? While there's lots of approaches, one of my mentors shared the 5 Ps approach with me. To think about the org, you need to enumerate the 5 Ps to define the organization, the type of talent you need, overall organizational competencies, Read More...
Framing Results
It's one thing to get results. It's another to articulate them. Having a way to frame results can help both for personal learning, as well as review time when you have to reflect on accomplishments. Commitment, Results, How, Evidence, Analysis I've found Read More...
Iterate More, Plan Less
I'm always on the prowl for useful insights. Alik sent me a link to Dustin Andrew's post, Learn to Get Traction in Your Team . I like the collection of tips, and I found myself using the phrase, iterate more, plan less a few times. When I joined Microsoft, Read More...
How To Use Guidance Explorer to do a Security Code Inspection
One of the key experiences you get with Guidance Explorer (GE) is support for manual security inspections. We call them inspections versus reviews because we inspect against specific criteria. We supply you with a starter set of inspection questions, Read More...
New Release: Guidance Explorer is Now on MSDN
This is a significant release for Guidance Explorer (GE). Our online "guidance store" is now hosted on MSDN. To take advantage of this, you need to download the new version of Guidance Explorer (release 20071206) What Is the Guidance Store Our guidance Read More...
Outlook Reminder for Leadership Practices
I created a recurring appointment in Outlook for Fridays. It's a checklist of key leadership practices from The Leadership Challenge . Each Friday, I scan this checklist and reflect on how well I've demonstrated the practices and where I need to tune Read More...
Now on Amazon: Performance Testing Guidance for Web Applications
Our patterns & practices Performance Testing Guidance for Web Applications book is now available on Amazon. Buy the Book on Amazon Download the PDF Browse the HTML Read More...
Now on Amazon: Team Development with Visual Studio Team Foundation Server
Our patterns & practices Team Development with Visual Studio Team Foundation Server book is now available on Amazon. Buy the Book on Amazon Download the PDF Browse the HTML Read More...

Search

This Blog

Syndication

Page view tracker