On 28/09/2011 19:51, Keith Edmunds wrote: > As usual, there are three parameters. The requester can have this: > > - done quickly > - done cheaply > - done properly > > The catch is, they only get to pick two of the above. > > Which two do they want? Can I mention that there are some very good guidelines from the OWASP lot. Jacqui