All the latest UK technology news, reviews and analysis

Microsoft to share in-house security lessons

by Shaun Nichols

17 Sep 2008

Be the first to comment

  • Tweet this
Microsoft HQ
Microsoft is planning a public version of its Secure Development Lifecycle programme

Microsoft is offering to supply developers with the same tools it uses to secure the latest versions of Office and Windows.

The company said on Tuesday that it will be releasing the details on several of its in-house Secure Development Lifecycle (SDL) concepts as freely available tools.

The effort will initially consist of three programmes, each designed to bring Microsoft's newly-developed security policies to other vendors.

The first will be an auditing system known as the SDL Optimisation Model. The system will allow developers to obtain a general security overview on their products and find possible holes in the development process.

The second will be the formation of a security consultant network. The Pro Network will aim to connect software developers with security firms in order to build software which is better able to withstand attack.

Initially, this will be limited to a small test network, although the company hopes eventually to open registration to outside firms.

The third part of the programme will be a piece of software known as the SDL Threat Modeling Tool which models a developer's code and points out potential security holes within an application.

Each of the three programmes is based on Microsoft's SDL system launched in 2004. The system was Microsoft's attempt to improve its overall product security by implementing security measures in every facet of the development process, and was used to develop Vista and Office 2007.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

44%

3%

12%

41%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Security Assurance Consultant

Security Assurance Consultant ( CLAS ) with HMG and Information...

Solution Design Architect

Solutions Design Architect - Oracle - Exadata - Dataguard...

Project Manager

My Client is a tier one investment bank based in Edinbugh...

Analyst Programmer

Analyst Programmer Web Developer required to work for...

To send to more than one email address, simply separate each address with a comma.