Does OpenBSD have a formal process for these audits? Any pointers?
Check out Henning’s slides on Secure coding in C:

