Top 10 Secure Coding Practices
securecoding.cert.org
securecoding.cert.org
(the original version of this is attributed to Gene Spafford)
The reason is simple: it's Hard to bulletproof any one security control, and the cost of getting controls even slightly wrong is the same as not doing it at all.
It can be tricky to come up with an example of a system that met a real-world security requirement only because a stack of security controls held together despite breaks the individual controls. Windows XP SP2 is a famous anti-example. Secure runtime: good! Security development lifecycle: better! Memory corruption vulnerability: often still game-over!
For assessors of applications (I'm one), the words "defense in depth" are usually blood in the water. It's code for, "we made a bunch of assumptions here, but that's OK because use modsecurity".
In that context, if a supposed "hacker" wants to gain access to files on machine X, they may be able to penetrate gateway A, router B and firewall C, but they still will be blocked by NIDS D or end up in honeypot E.
it doesn't help that coding style in nearly every PHP book I've seen is insecure and unmaintainable.