Sign in
The Security Development Lifecycle
Tags
Application Security
Attack Surface Analyzer
Authentication
BITS
Cloud Security
Code Analysis
Common Criteria
Crawl Walk Run
Critical Infrastructure
Elevation of Privilege
events
Forrester
HIPAA
neat
PA-DSS
Pages
PCI DSS
Privacy
Process Guidance
QSR
registration
ROI
SAFECode
SDC 2012
SDC 2013
SDL
SDL Chronicles
SDL Fuzzing
SDL Pro Network
SDL Progress Report
SDL-Agile
Security Assurance
Security Blackhat SDL
security development conference
Security Development Lifecycle
Security Tools
Simplified SDL
threat modeling
TwCNext
usable security
Visual Studio 11
Visual Studio 2012 RC
Browse by Tags
MSDN Blogs
>
The Security Development Lifecycle
>
All Tags
>
security assurance
Tagged Content List
Blog Post:
SDL and Compliance: New Blog Series at Security Blogs
SDL Team
Arjuna Shunn here. Our friends over on the security blog have done up a series of posts about SDL and compliance which are worth reading. Using data from numerous sources, ranging from our SDL and HIPAA whitepaper, our SDL and PCI DSS/PA-DSS whitepaper, and from our SDL Chronicles among others, they’ve...
on
7 Dec 2012
Blog Post:
Software Assurance: How can you tell?
SDL Team
We’ve posted before on the work of SAFECode, a non-profit organization of software vendors who seek to share their approaches to improving the security and assurance of software. In a pair of recent blog posts on the SAFECode blog, Eric Baize of EMC and I discuss effective ways for software acquirers...
on
11 Sep 2012
Blog Post:
Financial Services Industry Publishes Software Assurance Framework
SDL Team
More and more enterprises are realizing the importance of proactive security practices and those involved in critical infrastructure are no exception. One of the most effective ways to drive security improvements in critical infrastructure is through industry consensus. Microsoft has been deeply involved...
on
1 Feb 2012
Blog Post:
Evolving Secure Code at Microsoft and Beyond
SDL Team
Steve Lipner here… Over the past few weeks, Microsoft has been reflecting on the ten year anniversary of the Trustworthy Computing initiative; thinking about the things that have led us to this point in our history and speculating about the future. Obviously a big part of our work has been...
on
1 Feb 2012
Blog Post:
Application Security: 2011 & Beyond – A Forrester Research Report
SDL Team
Hi All. Doug here, In April 2011 Forrester Research wrote a new study on Application Security. This study, titled Application Security: 2011 & Beyond led by Dr Chenxi Wang, Lead Analyst at Forrester Research, provides valuable research, insights and recommendations for security and risk professionals...
on
12 Jul 2011
Blog Post:
ISV adoption of mitigation technologies
Michael Howard
Hi, Michael here, Over the last few weeks, Matt Miller, Matt Thomlinson, John Lambert and I worked on a paper that describes the various buffer overrun defenses we offer in Windows Vista and later and Windows Server 2008 and later. I’d like to introduce a guest SDL blogger, Matt Miller...
on
21 Sep 2010
Blog Post:
Secure Coding Secrets?
SDL Team
Hi, Michael here. A recent article titled "NSA posts secrets to writing secure code" caught my eye in part because the words " writing secure code " always get my attention! But also because anything that can advance the science of securing software is of interest to me. There is another reason...
on
18 Nov 2008
Blog Post:
Common Criteria and answering the question 'Is it Safe'
SDL Team
Hi all, Eric Bidstrup here. One of the areas that our group is also involved is in industry standards regarding security assurance, and Common Criteria ( aka ISO 15408) is the standard internationally recognized by 24 governments (including the US, UK, Germany, Japan, and others). It’s interesting...
on
20 Dec 2007
Page 1 of 1 (8 items)