Introduction To The Microsoft Security Development Lifecycle (SDL) .PPSX
Introduction To The Microsoft Security Development Lifecycle (SDL) .PPSX
Security Development
Lifecycle (SDL)
Secure software made easier
Agenda
• Applications under attack
• Origins of the Microsoft SDL
• What is Microsoft doing about the threat?
• Measurable improvements at Microsoft
Cybercrime Evolution
1986–1995 1995–2003 2004+ 2006+
• Requirements defined by
frequency, not phase
– Every-Sprint (most critical)
– One-Time (non-repeating)
– Bucket (all others)
157
119
66
Source: Windows Vista One Year Vulnerability Report, Microsoft Security Blog 23 Jan 2008
Microsoft SDL and SQL Server
187
Total Vulnerabilities Disclosed
36 Months After Release
34
3
SDL Blog
http://blogs.msdn.com/sdl/