Welcome to MSDN Blogs Sign in | Join | Help

Michael Howard's Web Log

A Simple Software Security Guy at Microsoft!
SDL Evolution

 UPDATED: Added IOActive post

As many of you have seen today, there's been plenty of press about us opening up the SDL for use by other software developers and releasing our threat modeling tool. For those of you who have no clue what the heck I'm talking about, here are a handful of articles about what happened today:

I'm not sure about the "High Priest" moniker, but what the heck :)

Cigital also blogged about the event, most notably the SDL Pro Network, and IOActive posted some comments too.

I'm really excited to see the SDL move forward and most importantly, outward. We have learned a great deal about what it takes to make steps toward securing software. We don't expect perfection, but if more people embrace some of the principles we define in the SDL, and we have experienced and knowledgable partners scale the effort, I think the IT world will be a substantially more secure place.

-Michael

Posted: Tuesday, September 16, 2008 9:02 PM by michael_HOWARD
Filed under:

Comments

blah said:

# September 17, 2008 9:20 AM

michael_HOWARD said:

blah,  thanks - fixed.

# September 17, 2008 4:01 PM
New Comments to this post are disabled
Page view tracker