NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Security

Security


The Security Development Lifecycle Is Not Just for Microsoft

Says the company

By Marius Oiaga, Technology News Editor

29th of May 2009, 09:56 GMT

Adjust text size:


Security
Enlarge picture
Following comprehensive in-house efforts to bulletproof its software products as much as possible, in 2008 Microsoft made a move designed to share the Security Development Lifecycle process with third-party developers. At that time, the Redmond company chose to make available SDL 3.2 resources to the developer community. A year later, the SDL 4.1 process release followed, with Microsoft steadfast on the path of Trustworthy Computing. But fact is that the SDL can ultimately benefit end users only if the process is adopted in the development of not only Microsoft products, but also that of third-party applications. In this regard, David Ladd, senior security program manager on
the Security Engineering Strategy Team, squashed the myth that the SDL "only works for Microsoft" or "is only suitable for development on Microsoft platforms."

“Honestly, that's a bit of a shocker for me. Security training, threat modeling, static code analysis, fuzz testing and other security actions performed as part of the SDL are not proprietary to Microsoft or the SDL. While the 4.1 documentation is focused on how the SDL is applied at MS, it doesn't require a Nobel Laureate to see that many of the things that make up the SDL are simply good security practices. So, I'd encourage people to take a look at the requirements and recommendations that are listed in the document and form your own conclusions,” Ladd explained.

At this point in time, developers can access a variety of resources from Microsoft, designed to help them boost the level of security for their code. The Redmond company is offering SDL Optimization Model, the SDL Threat Modeling Tool, and the SDL Pro Network all for free to devs looking to achieve a standard of security on par with what products like Windows Vista and Office 2007 bring to the table.

“We've illustrated the changes that one would expect of a living process – the expected fine tuning of our SDL requirements and recommendations to reflect changes in the security space. In addition, we have included information on how the SDL is applied to online services (i.e. Microsoft publicly available websites) and how we use the SDL to build line-of-business (LOB) applications for internal use at Microsoft. The changes specific to online services and LOB are called out in the text for easier review,” Ladd added.

TAGS:

Security Development Lifecycle | SDL | Microsoft
Read by 794 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Excellent (5.0/5) 2 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Warns of Increase in Gamburl Attacks

Comodo Software Removed from Softpedia [UPDATE 3]

Microsoft: Software as a Service Is a Must-Have for Businesses

ADMT 3.1 Doesn't Install on Windows Server 2008 R2

Get an Insight into the Windows 7 OEM Pre-installation Kit

Microsoft Online Customers in the Thousands

Microsoft Cleans Password Stealer Malware from 860,000 PCs

Leaked Office 2010 Technical Preview Infected Just as Windows 7 RC

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM