After several requests from customers about information on how enterprise class application security programs are set up, I am writing a series of blogs about my experience helping some large enterprises set up application security teams similar to the ACE team at Microsoft. This series will share lessons learnt at Microsoft IT and other large enterprises.

Application Security Development Lifecycle 1: Understanding your portfolio

Application Security Development Lifecycle 2: Mandatory or not?

Application Security Development Lifecycle 3: Funding Models