Microsoft takes Security Development Lifecycle to all developers

 

Microsoft will launch additions to its Security Development Lifecycle (SDL) programme today, designed to enable all software developers to integrate the SDL more tightly into the development process.

A free Visual Studio process template has been made available to download from MSDN, integrating SDL 4.1 into the software development environment for organisations using Visual Studio Team System.

The template provides guidance on how to implement the SDL into development, offering links to online resources and explaining how to extend it to third-party security tools.

"The template integrates policy, process and tools into software development management projects in a very usable way," said Steve Lipner, senior director of security engineering strategy for Microsoft's Trustworthy Computing initiative.

"Most importantly it is measurable, helping organisations assess the effectiveness of existing tools, visualise how well they're doing in terms of the SDL, and find the problems early in the lifecycle."

The template also takes all of the SDL requirements and populates them into Visual Studio as work items, making it as natural a process as possible, according to Lipner.

"The hackers and security researchers are finding vulnerabilities, and they're not just in Microsoft software," he said. "What we've tried to do is share our ideas with the community, in the hope that all software will be made secure."

Microsoft also announced that the same version of SDL is available as a document for organisations to download and apply in their own environments, even if not using Visual Studio.

Lipner added that the pro-network of third-party training and consulting companies would expand to include storage area networks and the Science Applications International Corporation.

Copyright ©v3.co.uk


Microsoft takes Security Development Lifecycle to all developers
 
 
 
 
 
Top Stories
Vito Forte: A CIO for tough times
Fortescue Metals CIO talks vendor management and innovation.
 
Tech staff spared in ANZ's 1000 job cuts
Cost cutting hits middle management.
 
Telstra shifts BigPond email to Windows Live
All data to be migrated to Microsoft cloud.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Would you be concerned about your business' email data being hosted offshore?

   |   View results
Yes
  83%
 
No
  17%
TOTAL VOTES: 245

Vote