Security and Application Development in SharePoint: First Steps
In case you have subscribed to the msdn security newsletter , you may have noticed that I had an article in this month’s issue.
Security and Application Development in SharePoint: First Steps
Security principles in the world of programming using the SharePoint object model usually boil down to two key principles at design and development stages: know your threat model and know what security context your code runs on behalf of. Read this article for detailed security best practices that you can implement during the design and development stages of building business solutions on the SharePoint platform.
http://www.microsoft.com/technet/community/columns/secmvp/sv0408.mspx