Microsoft shares its SDL tools and expertise with the developer community

02 February 2010
According to Microsoft Security Intelligence Report, in the last six months of 2009, 81% of reported vulnerabilities were in application software products. Increasingly crime-motivated cyber threats and the competitive marketplace means that application developers are being challenged to engineer more secure products. Developers want to do the right thing but have been put off by difficulties in acquiring specialist security expertise and assumptions of huge additional cost and resource.

The Security Development Lifecycle (SDL), a security assurance process designed to reduce the number and severity of security vulnerabilities in software, was developed by Microsoft and managed by the Trustworthy Computing group, became mandatory for all Microsoft products in 2004.

Based on a belief that more secure code benefits everyone, Microsoft is committed to sharing its SDL tools, expertise and guidance with the broader developer community. To date more than 48,000 developers have downloaded four free SDL tools and 78,000 have downloaded free SDL guidance.

At Black Hat DC in Washington DC, Microsoft’s Trustworthy Computing group is making three further announcements designed to share its SDL expertise:

Simplified Implementation of the Microsoft SDL

Many developers avoid secure development practices because they think it will cost too much and require huge resources. They are also put off adopting Microsoft’s SDL because they believe it is exclusively for the Microsoft platform. This white paper explains how the SDL can be implemented with limited resources and applied to other platforms.

MSF Agile + SDL

Microsoft will release Microsoft Solutions Framework for Agile Software Development plus Security Development Lifecycle (MSF Agile + SDL) Process Template for Visual Studio Team System (VSTS) 2008 beta (planned for release at the end of Q2). It will also announce that the MSF Agile + SDL process template for Visual Studio 2010 will be released shortly after Microsoft releases Visual Studio 2010 (currently scheduled for April 2010).

With the MSF-Agile+SDL template, any code checked into the VSTS source repository by the developer is analyzed to ensure that it complies with SDL secure development practices. The template also automatically creates workflow tracking items for manual SDL processes such as threat modelling to ensure that these important security activities are not accidentally skipped or forgotten. Finally, they integrate with the other SDL tools, including the SDL Threat Modelling Tool, the Binscope Binary Analyzer, and Minifuzz.

Expansion of SDL Pro Network

Microsoft will expand the SDL Pro Network, which was set up in November 2008. SDL Pro Network members are specialist security organizations that offer services to help organizations adopt the SDL.

At Black Hat D.C. Microsoft will announce the creation of a Tools membership category to complement the Consulting and Training categories. Tools members are companies that are able to deploy a range of security tools, such as static analysis tools for the Implementation Phase and dynamic and binary analysis tools for the Verification phase.

Finally, Microsoft will announce seven new members of the SDL Pro Network:
· Fortify (Tool Member)
· Veracode (Tool Member)
· Codenomicon (Tool Member)
· Booz-Allen Hamilton(Consulting Member)
· Casaba Security (Consulting Member)
· Consult2Comply (Consulting Member)
· Safelight Security Advisors (Training Member)

More information about the Microsoft SDL Pro Network and tools available through the SDL portal

 

Latest public sector security articles

 Passwords are past their sell-by-date

 Misconfigured networks are the easiest IT resource hackers exploit

 The Return of Ransomware and Do-it-Yourself Botnets

 Hikvision mobile surveillance solution deployed on 3,600 buses in Ningbo, China

 Hikvision cameras keep watch on World Expo 2010 in Shanghai

 Data protection laws are too relaxed and require revision

 Northshore Utility District deploys IndigoVision's IP Video surveillance system to prevent terrorism and improve public and staff safety

 The challenge of protecting multiple and increasingly disparate end user environments

 The USA continues to be the number one spam polluter whle Europe becomes the most prolific continent for spamming

 New Mobile CCTV service for Northern Ireland

...[view more articles on public sector security]...

 

Other security websites:

Public Sector security links

Public sector banks need to hire more: BCG A report by The Boston Consulting Group notes the human resource challenge for public sector banks due to large-scale retirement.

Unions suspend public sector strike South African public sector workers suspended a pay strike yesterday as it entered its fourth week. The strike by 1.3 million workers has hit schools, state hospitals and the judiciary. Strikers have demanded a pay rise of 8.6 per cent, twice the inflation rate, and a R1,000 (£90) a month housing allowance.

South African public workers suspend 20-day strike South African public sector unions announced the suspension Monday of a three-week-old strike that has crippled the health service and forced widespread school closures.

S.African public sector strike suspended -unions S.African public sector strike suspended -unions

Labour focus shifts from private to public sector While the private sector bore the brunt of the economic downturn, union leaders are turning their attention to the public sector this Labour Day as deficit-obsessed governments put the squeeze on their workers.

Survey: IT job opportunities slump in UK public sector LONDON: Public sector job opportunities in IT in Britain have fallen markedly since the start of the year, a survey showed today, in a sign that the government's austerity drive is already affecting the labour market. Only four in every hundred new IT jobs are being created in the public sector, down from about 30 out of 100 at the start of the year, according to research by business and ...

Public workers given mental health training in Austin Public workers given mental health training in Austin

directory of Public Sector security suppliers
Search directory Register your company
Public Sector Security books:

SEARCH NEWS
DIRECTORY
Google