<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>"Crawling" Toward SDL</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx</link><description>Hey everyone, Jeremy Dallman here. 
 
 One of the phrases I often hear during vision and strategy planning meetings at Microsoft is "What is the crawl, walk, run?" We use this phrase to differentiate the initial activities that will get us quickly moving</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>A szoftver minőségbiztosítási eszközök valós lehetőségei és korlátai</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#9394604</link><pubDate>Wed, 04 Feb 2009 08:04:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9394604</guid><dc:creator>Termékinformációk fejlesztőknek</dc:creator><description>&lt;p&gt;[Nacsa S&amp;#225;ndor, 2009. janu&amp;#225;r 13. – febru&amp;#225;r 3.]&amp;amp;#160; A minős&amp;#233;gbiztos&amp;#237;t&amp;#225;s k&amp;#233;rd&amp;#233;sk&amp;#246;re szinte alig ismert&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9394604" width="1" height="1"&gt;</description></item><item><title>re: "Crawling" Toward SDL</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#9386648</link><pubDate>Sat, 31 Jan 2009 20:54:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9386648</guid><dc:creator>Philip.Agcaoili</dc:creator><description>&lt;p&gt;Thanks for the info.These are the examples that Michael Howard forwarded to me as well. Go figure.&lt;/p&gt;
&lt;p&gt;We're driving SOA security standards, so anything that you have to assist us here as well would be appreciated.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9386648" width="1" height="1"&gt;</description></item><item><title>re: "Crawling" Toward SDL</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#8870707</link><pubDate>Sat, 16 Aug 2008 00:01:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8870707</guid><dc:creator>SDL Team</dc:creator><description>&lt;p&gt;Phil, to your other question about good references, I would point you to the below links. Please also watch the new SDL website for more information:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/sdl"&gt;http://www.microsoft.com/sdl&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Compiler defenses: &lt;a rel="nofollow" target="_new" href="http://msdn.microsoft.com/en-us/magazine/cc337897.aspx"&gt;http://msdn.microsoft.com/en-us/magazine/cc337897.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Banned APIs: &lt;a rel="nofollow" target="_new" href="http://msdn.microsoft.com/en-us/library/bb288454.aspx"&gt;http://msdn.microsoft.com/en-us/library/bb288454.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Secure libraries: &lt;a rel="nofollow" target="_new" href="http://msdn.microsoft.com/en-us/library/e942ksxt.aspx"&gt;http://msdn.microsoft.com/en-us/library/e942ksxt.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8870707" width="1" height="1"&gt;</description></item><item><title>re: "Crawling" Toward SDL</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#8870695</link><pubDate>Fri, 15 Aug 2008 23:57:51 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8870695</guid><dc:creator>jdallman</dc:creator><description>&lt;p&gt;Phil, my apologies for the delayed response. Thank you for taking the time and please feel free to keep up the conversation!&lt;/p&gt;
&lt;p&gt;You make some good points about raising awareness through training and education. Based on what I've seen, that is typically quite a challenge for a company (or small group of people within a company) to get going... so I left it as an informal component until &amp;quot;Walking&amp;quot;.&lt;/p&gt;
&lt;p&gt;Although Fuzzing and Threat Modeling may be perceived as more advanced practices, I think that Threat Modeling in particular is one of the most effective ways to raise awareness of security risks in your products. I would encourage anyone crawling to perform threat modeling as a way to educate themselves in security practices as well as the practical security of their own product. &lt;/p&gt;
&lt;p&gt;At &amp;quot;crawl&amp;quot;, I suspect any fuzzing would need to be either outsourced or basic and manual. However, any amount of fuzzing that can be done will likely find bugs to fix. These bugs in turn becomes your evidence for broader fuzzing efforts as you mature.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8870695" width="1" height="1"&gt;</description></item><item><title>re: "Crawling" Toward SDL</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#8789506</link><pubDate>Tue, 29 Jul 2008 20:50:41 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8789506</guid><dc:creator>Philip.Agcaoili</dc:creator><description>&lt;p&gt;Do you have good references for compiler defenses, banned APIs, and secure, reusable libraries?&lt;/p&gt;
&lt;p&gt;A basic, publicly available reference wil help many in the Crawling phase.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Phil Agcaoili&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8789506" width="1" height="1"&gt;</description></item><item><title>re: "Crawling" Toward SDL</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#8789504</link><pubDate>Tue, 29 Jul 2008 20:48:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8789504</guid><dc:creator>Philip.Agcaoili</dc:creator><description>&lt;p&gt;Fizzing and Threat Modeling are little advance for Crawling.&lt;/p&gt;
&lt;p&gt;I'd also add that Awareness, Training, and Education are necessary in this phase.&lt;/p&gt;
&lt;p&gt;The adoption of tools to Verify what was trained is a great idea for this phase. Many folks are still evolving from Blackbox, application security testing tools, so the move to source code analysis is &amp;nbsp;major hurdle and an organizational shift.&lt;/p&gt;
&lt;p&gt;There is a huge element that is resistant to this shift, so good luck Crawling!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8789504" width="1" height="1"&gt;</description></item><item><title>"Walking" with the SDL - Part 1</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#8750222</link><pubDate>Fri, 18 Jul 2008 20:03:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8750222</guid><dc:creator>The Security Development Lifecycle</dc:creator><description>&lt;p&gt;Jeremy Dallman here. Back in March I wrote a post about “Crawling” Toward SDL . I used the imagery of&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8750222" width="1" height="1"&gt;</description></item><item><title>Security Thoughts from TechEd 2008</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#8657073</link><pubDate>Thu, 26 Jun 2008 18:16:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8657073</guid><dc:creator>The Security Development Lifecycle</dc:creator><description>&lt;p&gt;Hi, this week is a post from Michael Howard and Laura Machado de Wright, who both attended and presented&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8657073" width="1" height="1"&gt;</description></item><item><title>Microsoft SDL Process – in detail</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#8373349</link><pubDate>Thu, 10 Apr 2008 00:45:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8373349</guid><dc:creator>The Security Development Lifecycle</dc:creator><description>&lt;p&gt;Hello all – Dave here… I am currently at RSA and decided to take a few moments to blog about some updates&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8373349" width="1" height="1"&gt;</description></item><item><title>&amp;quot;Crawling&amp;quot; Toward SDL | Secure Software Engineering Blog</title><link>http://blogs.msdn.com/b/sdl/archive/2008/03/06/crawling-toward-sdl.aspx#8084293</link><pubDate>Fri, 07 Mar 2008 05:32:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8084293</guid><dc:creator>"Crawling" Toward SDL | Secure Software Engineering Blog</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.secure-software-engineering.com/2008/03/06/crawling-toward-sdl/"&gt;http://www.secure-software-engineering.com/2008/03/06/crawling-toward-sdl/&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8084293" width="1" height="1"&gt;</description></item></channel></rss>