Welcome to TechNet Blogs Sign in | Join | Help

William Wong :: Multi Country Americas Application Platform Blog

My perspective - Technology Life Style & More

Tags

No tags have been created or used yet.

News

  • These postings are provided "AS IS" with no warranties, and confer no rights. The opinions expressed here are my own personal opinions and do not represent my employer's view in any way. Locations of visitors to this page

Archives

Security Development Lifecycle

   The SDL is the process that Microsoft has implemented for the development of software that needs to withstand malicious attack. The process encompasses the addition of a series of security-focused activities and deliverables to each of the phases of Microsoft's software development process. These activities and deliverables include the development of threat models during software design, the use of static analysis code-scanning tools during implementation, and the conduct of code reviews and security testing during a focused "security push". Before software developed under the SDL can be released, it must undergo a Final Security Review by a team independent from its development group. When compared to software that has not been subject to the SDL, software that has undergone the SDL has experienced a significantly reduced rate of external discovery of security vulnerabilities. This paper describes the SDL and discusses experience with its implementation across Microsoft software.

The complete document can be found here

Posted: Sunday, April 17, 2005 3:43 AM by wilwong

Comments

Security Development Lifecycle said:

# November 28, 2007 10:09 AM
Anonymous comments are disabled
Page view tracker