Here are some of my favourite resources regarding code reviews:
From Karl Weigers' book on the subject:
http://www.processimpact.com/reviews_book/chapter_2.pdf
http://www.processimpact.com/reviews_book/chapter_6.pdf
And a .NET specific list of security related things to look for in a review:
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/thcmch21.asp
Proponents of code reviews say that when they are conducted properly they are one of the most cost-effective ways of finding defects. Does anyone else out there in .NET blog land have any experiences (positive or negative). The couple of times I've tried to get code reviews off the ground I've been told they are either too expensive, or I've got back fairly superficial and non-specific feedback.
Update: Chris Anderson with some brief info on the Avalon team's code review process http://www.simplegeek.com/commentview.aspx/cf176ca9-1aec-4cb1-9d0f-796fce45d63a