Microsoft builds SDL process into Visual Studio



Email    print   
May 19, 2009 —  (Page 1 of 2)
Microsoft is attempting to demystify its Security Development Lifecycle by transforming it from a written process into a template for automation in Visual Studio.

The SDL is a mandatory process used internally at Microsoft during the development of its products, and Microsoft began to share its SDL expertise and tooling with customers last year to help secure applications further down the Windows stack.

Today, a free download for Visual Studio 2008 Team System called the SDL Process Template became available on Microsoft's MSDN website. Microsoft is also working toward a release of the template for Visual Studio 2010.

Microsoft's objective is to help developers bootstrap internal security efforts, said David Ladd, principal security program manager of Microsoft’s SDL team.

Ladd's team also announced an expansion of the SDL Pro Network, a pilot program that trains security experts in tools and guidance associated with the SDL. The new participants are from Science Applications International Corp., a U.S. government contractor for cyber security initiatives, and the SANS Institute.

The template follows version 4.1 of the SDL document, providing auditable security requirements and project status information, as well as demonstrating a security return on investment, Ladd said. It is designed to provide guidance for customizing the SDL process for individual projects, and it includes an XML schema to import data from testing tools.

The schema is primarily designed for automating the integration of Microsoft's threat-modeling tool, but it also works with third-party tools that can format content for Team Foundation Server, said Ladd.

SDL 4.1 documentation was published today on MSDN. It includes updates to prior requirements and documentation, new guidance for online services and line-of-business application development, and closer alignment to traditional software development life-cycle phases.

"We made [the SDL] more complicated than it actually was," Ladd acknowledged. "Now, we've reduced the SDL to discreet steps. Organizations can make security gains without being security experts." Links are available to SDL documentation online.

A final security review demonstrates the progress that is being made toward completing all SDL tasks and how a team is doing against requirements, Ladd said.



Related Search Term(s): Microsoft, security, Visual Studio

Pages 1 2 


Share this link: http://sdt.bz/33493
 
Most Read Latest News Blog Resources

Add comment


Name*
Email*  
Country     


  • Comment
Loading




close
NEXT ARTICLE
Microsoft adds runtime intelligence, anti-tampering features to VS 2010
Working with PreEmptive Solutions and its Dotfuscator product, Visual Studio 2010 will see more instrumentation capabilities and improvements to its code security. Developers can also take advantage of a new runtime intelligence streaming service Read More...
 
 
 
 
News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 

Download Current Issue
FEBRUARY 2012 PDF ISSUE

Need Back Issues?
DOWNLOAD HERE

Want to subscribe?


 
blogs tab
Agility, mom, and apple pie
If we're to evaluate the state-of-the-art in software development, we should start with the values espoused in the Agile Manifesto.
02/07/2012 11:57 AM EST

RIM woos developers with free tablet
How do you get more apps ported to the BlackBerry PlayBook? By giving every developer a free tablet, of course!
02/04/2012 01:57 PM EST

GitHire: Use Headhunters to Find Your Perfect Programmer
Are you a hiring manager tired of scouring the job boards? Check out this new service that will find 5 people interested in your jobs.
02/03/2012 12:17 PM EST

Facebook claims hacker cred
Facebook's SEC S-1 filing form includes a short essay on the Hacker Way by Mark Zuckerberg himself.
02/02/2012 08:26 AM EST

Ryan Dahl steps down
Ryan Dahl, creator of Node.js, steps back from his position as gatekeeper for the project.
02/01/2012 04:58 PM EST

Bloomberg opens its API
Bloomberg's APIs could lead to a future standard for accessing market data.
02/01/2012 04:41 PM EST

 
Events calendar tab
2/13/2012 to 2/16/2012
Santa Clara
TechWeb

2/26/2012 to 2/29/2012
San Francisco
BZ Media

2/27/2012 to 3/2/2012
San Francisco
RSA

3/4/2012 to 3/7/2012
Las Vegas
IBM Tivoli

3/5/2012 to 3/9/2012
San Francisco
TechWeb