<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The Security Development Lifecycle : SDL Pro Network</title><link>http://blogs.msdn.com/sdl/archive/tags/SDL+Pro+Network/default.aspx</link><description>Tags: SDL Pro Network</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>New SDL Pro Network Members: SANS and SAIC</title><link>http://blogs.msdn.com/sdl/archive/2009/05/21/new-sdl-pro-network-members-sans-and-saic.aspx</link><pubDate>Thu, 21 May 2009 18:50:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9633926</guid><dc:creator>sdl</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/sdl/comments/9633926.aspx</comments><wfw:commentRss>http://blogs.msdn.com/sdl/commentrss.aspx?PostID=9633926</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;When &lt;A href="http://blogs.msdn.com/sdl/archive/2008/09/11/new-addition-to-the-starting-line-up.aspx" mce_href="http://blogs.msdn.com/sdl/archive/2008/09/11/new-addition-to-the-starting-line-up.aspx"&gt;I joined the SDL team&lt;/A&gt; last fall, the &lt;A href="http://msdn.microsoft.com/en-us/security/dd219581.aspx" mce_href="http://msdn.microsoft.com/en-us/security/dd219581.aspx"&gt;SDL Pro Network&lt;/A&gt; had launched as a &lt;A href="http://blogs.msdn.com/sdl/archive/2008/09/18/about-the-sdl-pro-network.aspx" mce_href="http://blogs.msdn.com/sdl/archive/2008/09/18/about-the-sdl-pro-network.aspx"&gt;one-year pilot program&lt;/A&gt;.&amp;nbsp; Upon returning from maternity leave, I took over management of the SDL Pro Network.&amp;nbsp; I have been working on formalizing the program in order to bring it from pilot phase into a full blown partner program, to launch after November 2009.&amp;nbsp; I have also been working on bringing new consulting services and training members into the fold, even during this pilot phase of the program.&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;On May 19, the SANS Institute, one of the most trusted and largest sources for information security training, certification &amp;amp; research in the world, and SAIC, a company of over 45,000 employees worldwide with expertise in national security, energy and the environment, critical infrastructure and health, were also added to the SDL Pro Network in an effort to further broaden the SDL’s reach. &lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;In joining forces with these two new SDL Pro Network members, Microsoft’s SDL team is bringing more options for world-renowned security training and consulting services to new developers around the world.&lt;BR&gt;&lt;/P&gt;&lt;/FONT&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Please join me in welcoming &lt;A href="http://www.sans.org/sdl.php" mce_href="http://www.sans.org/sdl.php"&gt;SANS&lt;/A&gt; and &lt;A href="http://www.saic.com/" mce_href="http://www.saic.com/"&gt;SAIC&lt;/A&gt; into the SDL Pro Network.&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;-&lt;A href="http://twitter.com/k8em0" mce_href="http://twitter.com/k8em0"&gt;Katie Moussouris&lt;/A&gt;, Senior Security Strategist, SDL&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9633926" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/sdl/archive/tags/SDL/default.aspx">SDL</category><category domain="http://blogs.msdn.com/sdl/archive/tags/SDL+Pro+Network/default.aspx">SDL Pro Network</category></item><item><title>Gary McGraw's Reality Check Security Podcast</title><link>http://blogs.msdn.com/sdl/archive/2009/01/15/gary-mcgraw-s-reality-check-security-podcast.aspx</link><pubDate>Thu, 15 Jan 2009 21:54:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9321365</guid><dc:creator>sdl</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/sdl/comments/9321365.aspx</comments><wfw:commentRss>http://blogs.msdn.com/sdl/commentrss.aspx?PostID=9321365</wfw:commentRss><description>Hello, Michael here,&amp;nbsp;&amp;nbsp; 
&lt;P&gt;&lt;A href="http://www.cigital.com/~gem/"&gt;Gary McGraw&lt;/A&gt;, CTO at Cigital, recently &lt;A href="http://www.cigital.com/realitycheck/show-001/"&gt;interviewed&lt;/A&gt; Steve Lipner as Gary kicked off his "&lt;A href="http://www.cigital.com/realitycheck/"&gt;Reality Check&lt;/A&gt; Security Podcast" series. I think podcasts like this are important because they help learn from others' experiences. &lt;/P&gt;
&lt;P&gt;For those that don't know Gary, he's been involved in software security for years, and has written plenty of &lt;A href="http://www.amazon.com/Software-Security-Building-Addison-Wesley/dp/0321356705/"&gt;excellent&lt;/A&gt; &lt;A href="http://www.amazon.com/Exploiting-Online-Games-Distributed-Addison-Wesley/dp/0132271915"&gt;books&lt;/A&gt; &lt;A href="http://www.amazon.com/Exploiting-Software-Break-Addison-Wesley-Security/dp/0201786958/"&gt;on&lt;/A&gt; &lt;A href="http://www.amazon.com/Building-Secure-Software-Addison-Wesley-Professional/dp/020172152X"&gt;the&lt;/A&gt; &lt;A href="http://www.amazon.com/Software-Security-Engineering-Project-Managers/dp/032150917X"&gt;subject&lt;/A&gt;. He also plays a &lt;A href="http://www.wheresaubrey.com/"&gt;mean fiddle&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Finally, Cigital is a &lt;A href="http://www.cigital.com/services/sdl/"&gt;member&lt;/A&gt; of the Microsoft SDL Pro Network. &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9321365" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/sdl/archive/tags/SDL+Pro+Network/default.aspx">SDL Pro Network</category></item><item><title>About the SDL Pro Network</title><link>http://blogs.msdn.com/sdl/archive/2008/09/18/about-the-sdl-pro-network.aspx</link><pubDate>Fri, 19 Sep 2008 06:12:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8958114</guid><dc:creator>sdl</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/sdl/comments/8958114.aspx</comments><wfw:commentRss>http://blogs.msdn.com/sdl/commentrss.aspx?PostID=8958114</wfw:commentRss><description>Hello all, Dave here... 
&lt;P&gt;I expect that a number of you have seen the &lt;A href="http://www.microsoft.com/presspass/features/2008/sep08/09-16lipnersdl.mspx" mce_href="http://www.microsoft.com/presspass/features/2008/sep08/09-16lipnersdl.mspx"&gt;announcement&lt;/A&gt; and various press articles or &lt;A href="http://blogs.msdn.com/sdl/archive/2008/09/16/sdl-press-tour-announcements.aspx" mce_href="http://blogs.msdn.com/sdl/archive/2008/09/16/sdl-press-tour-announcements.aspx"&gt;Steve Lipner's Tuesday post&lt;/A&gt; about our launch of the SDL Threat Modeling Tool 3.0, the SDL Optimization Model and the &lt;A href="http://download.microsoft.com/download/0/E/9/0E9AC448-30B2-4451-9E23-46244AFABB7F/Microsoft%20SDL%20Pro%20Network%20_Fact%20Sheet.pdf" mce_href="http://download.microsoft.com/download/0/E/9/0E9AC448-30B2-4451-9E23-46244AFABB7F/Microsoft%20SDL%20Pro%20Network%20_Fact%20Sheet.pdf"&gt;SDL Pro Network&lt;/A&gt;.&amp;nbsp; Since I was intimately involved with the creation of the SDL Pro Network, I thought I'd write a few words about our objectives and chat a bit about the thinking behind our partner choices for the pilot phase.&lt;/P&gt;
&lt;P&gt;So, what are we hoping to gain by creating a network of security consulting and training experts to work with customers who want to implement the SDL?&amp;nbsp; Generally speaking, this question has a two-part answer:&amp;nbsp; First, Microsoft is, and always will be a partner-driven company - we rely on the skills and capabilities of our partners to provide specialized services and broad geographic coverage for Microsoft products and services.&amp;nbsp; Second, even though there are talented folks in the &lt;A href="http://www.microsoft.com/services/microsoftservices/default.mspx" mce_href="http://www.microsoft.com/services/microsoftservices/default.mspx"&gt;Microsoft Services&lt;/A&gt; organization, it's clear that we will need help from our partners to scale to meet the demand.&amp;nbsp; I can't tell you how many times the folks on the SDL team have been approached by people - after an executive briefing, or a session at TechEd - asking for guidance in implementing SDL in their own organizations.&amp;nbsp; When we look at the demand and pair it with the geographic diversity of our customer base, it's clear that a partner approach is the right answer.&lt;/P&gt;
&lt;P&gt;Now a few words about the partners who will be participating in the pilot phase...&lt;/P&gt;
&lt;P&gt;After the decision was made to work with partners on SDL delivery, we had two primary criteria that we had to address; partner quality, and manageability of the SDL Pro Network pilot. We have all seen instances where individuals or consulting organizations have represented themselves to the IT community as having security expertise when in reality the "experts for hire" were simply reading a page or two ahead of the customer in whatever security tome was "in vogue" at the time.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Based on those observations, it was clear that partner "quality" was a critical criterion. &amp;nbsp;Fortunately for us, we didn't have to look far to satisfy our quality bar - many of the companies in the SDL Pro Network pilot have direct experience with executing portions of the SDL on &lt;I&gt;our&lt;/I&gt; products, or have delivered services to Microsoft in a security context. Design reviews, code reviews, penetration testing, training&amp;nbsp;and other tasks critical to SDL implementation were (and are) common fare for these folks.&lt;/P&gt;
&lt;P&gt;Despite the customer demand for SDL that I alluded to above, starting with a small pilot was the right thing to do; a small group of trusted consultancies supports our imperative for quality and it allows us to pragmatically grow the SDL Pro Network as the market matures. &amp;nbsp;As we continue to evolve and innovate with the SDL, we'll have a strong core of partners to help drive the software security message. &lt;/P&gt;
&lt;P&gt;Will we grow the SDL Pro Network?&amp;nbsp; The qualified answer is: "When the market demands it..." - there are a number of talented potential partners who meet the quality bar - and clearly, the need for security in software development will grow to demand additional talented specialists. However, it's our plan to begin with a small set of partners of known expertise, and then respond to growing demand as it materializes.&lt;/P&gt;
&lt;P&gt;So there you have it - the nuanced beginning and bright future of the SDL Pro Network...&amp;nbsp; I invite your comments, and encourage you to check in at the &lt;A href="http://www.microsoft.com/sdl" mce_href="http://www.microsoft.com/sdl"&gt;SDL Portal&lt;/A&gt; as we continue to build out the program&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=8958114" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/sdl/archive/tags/SDL+Pro+Network/default.aspx">SDL Pro Network</category></item></channel></rss>