<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Akshay on the business of security : SDL</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx</link><description>Tags: SDL</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Shrinking Budgets: Application Security Tools vs Process Tradeoff</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2009/04/29/shrinking-budgets-application-security-tools-vs-process-tradeoff.aspx</link><pubDate>Thu, 30 Apr 2009 08:25:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9578566</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/9578566.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=9578566</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=9578566</wfw:comment><description>An all too familiar scene repeated itself two weeks ago. My good friend &amp;amp; CISO of a mid-sized technology company, lets call him Alok, went into a budget planning meeting and came out as a shadow of his former self. To be more precise a 85% version...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2009/04/29/shrinking-budgets-application-security-tools-vs-process-tradeoff.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9578566" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Tools/default.aspx">Tools</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Baking Security In: A Comic Strip View of SDL</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2009/02/20/baking-security-in-a-comic-strip-view-of-sdl.aspx</link><pubDate>Fri, 20 Feb 2009 21:07:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9435196</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/9435196.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=9435196</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=9435196</wfw:comment><description>So how do you t ake your average developer who scoffs at security from the careless and brash aka Kevin,&amp;#160; to the poster child&amp;#160; for good development practices aka&amp;#160; Kevlarr. Well, the Microsoft SDL team has the answer for you. The team recently...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2009/02/20/baking-security-in-a-comic-strip-view-of-sdl.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9435196" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Threat+Modeling/default.aspx">Threat Modeling</category></item><item><title>Application Security Development Lifecycle 5A: Is Threat Modeling Right For You?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx</link><pubDate>Wed, 11 Jun 2008 18:06:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8590916</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>6</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8590916.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8590916</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8590916</wfw:comment><description>Several enterprises are increasingly investing time and money in building application security tasks into their existing SDLCs. Some of them have also reached the conclusion that proactive approaches , like threat modeling, have more ROI than reactive...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8590916" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Business/default.aspx">Business</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Governance+Series/default.aspx">Governance Series</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security development Lifecycle 4: Finding the right security talent</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/01/application-security-development-lifecycle-4-finding-the-right-security-talent.aspx</link><pubDate>Sun, 01 Jun 2008 22:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8551936</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8551936.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8551936</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8551936</wfw:comment><description>After about an hour of nodding his head vigorously in agreement with some of our lessons learnt, my customer jumped up and exclaimed, " Great!! Now where do I find another 20 people like these?" (pointing to my team)... I thought about it a while and...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/01/application-security-development-lifecycle-4-finding-the-right-security-talent.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8551936" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Education/default.aspx">Education</category></item><item><title>How Microsoft IT does Secure Application Development: Webcast</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/27/how-microsoft-it-does-secure-application-development-webcast.aspx</link><pubDate>Tue, 27 May 2008 19:20:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8554014</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8554014.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8554014</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8554014</wfw:comment><description>Technorati Tags: Conference , SDLC , SDL , IT , ISV I will be discussing Microsoft IT's approach to secure application development, with a special focus on how we integrate security into the IT line-of-business SDLC, in a webcast this Thursday May 29th....(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/27/how-microsoft-it-does-secure-application-development-webcast.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8554014" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Conference/default.aspx">Conference</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Speaking/default.aspx">Speaking</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security Development Lifecycle 3: Funding Models</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/08/application-security-governance-3-funding-models.aspx</link><pubDate>Thu, 08 May 2008 21:48:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8469533</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8469533.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8469533</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8469533</wfw:comment><description>Now that you've decided (or battled) to set up an application security program you realize that it actually needs to get funded. You must master the art of delicately drinking from the fire hydrant of line of business applications. In my experience helping...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/05/08/application-security-governance-3-funding-models.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8469533" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security Development Lifecycle 2: Mandatory or Not?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/22/application-security-governance-2-mandatory-or-not.aspx</link><pubDate>Tue, 22 Apr 2008 10:36:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8416189</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/8416189.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=8416189</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=8416189</wfw:comment><description>Large enterprises tend to have a number of line of business (LOB) applications supporting business operations. It becomes key for an application security program to help the organization manage the risk posed by each of these applications. Applications...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/22/application-security-governance-2-mandatory-or-not.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8416189" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security Development Lifecycle 1: Understanding your portfolio</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/07/application-security-governance-1-understanding-your-portfolio.aspx</link><pubDate>Mon, 07 Apr 2008 19:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6397859</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/6397859.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=6397859</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=6397859</wfw:comment><description>"How many applications do you have and what do they do?" It seems simple enough yet this questions seems to perplex many a smart mind. Having posed it to over a hundred and fifty CSO/CIOs over the last year, I have rarely received a clear answer that...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/07/application-security-governance-1-understanding-your-portfolio.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=6397859" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item><item><title>Application Security Development Lifecycle Series</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/02/application-security-governance-series.aspx</link><pubDate>Thu, 03 Apr 2008 09:54:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6395326</guid><dc:creator>Akshay Aggarwal</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/akshay_aggarwal/comments/6395326.aspx</comments><wfw:commentRss>http://blogs.msdn.com/akshay_aggarwal/commentrss.aspx?PostID=6395326</wfw:commentRss><wfw:comment>http://blogs.msdn.com/akshay_aggarwal/rsscomments.aspx?PostID=6395326</wfw:comment><description>After several requests from customers about information on how enterprise class application security programs are set up, I am writing a series of blogs about my experience helping some large enterprises set up application security teams similar to the...(&lt;a href="http://blogs.msdn.com/akshay_aggarwal/archive/2008/04/02/application-security-governance-series.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=6395326" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Application+Security/default.aspx">Application Security</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Process/default.aspx">Process</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Strategy/default.aspx">Strategy</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/Management/default.aspx">Management</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDLC/default.aspx">SDLC</category><category domain="http://blogs.msdn.com/akshay_aggarwal/archive/tags/SDL/default.aspx">SDL</category></item></channel></rss>