Microsoft shares its SDL tools and expertise with the developer community

02 February 2010
According to Microsoft Security Intelligence Report, in the last six months of 2009, 81% of reported vulnerabilities were in application software products. Increasingly crime-motivated cyber threats and the competitive marketplace means that application developers are being challenged to engineer more secure products. Developers want to do the right thing but have been put off by difficulties in acquiring specialist security expertise and assumptions of huge additional cost and resource.

The Security Development Lifecycle (SDL), a security assurance process designed to reduce the number and severity of security vulnerabilities in software, was developed by Microsoft and managed by the Trustworthy Computing group, became mandatory for all Microsoft products in 2004.

Based on a belief that more secure code benefits everyone, Microsoft is committed to sharing its SDL tools, expertise and guidance with the broader developer community. To date more than 48,000 developers have downloaded four free SDL tools and 78,000 have downloaded free SDL guidance.

At Black Hat DC in Washington DC, Microsoft’s Trustworthy Computing group is making three further announcements designed to share its SDL expertise:

Simplified Implementation of the Microsoft SDL

Many developers avoid secure development practices because they think it will cost too much and require huge resources. They are also put off adopting Microsoft’s SDL because they believe it is exclusively for the Microsoft platform. This white paper explains how the SDL can be implemented with limited resources and applied to other platforms.

MSF Agile + SDL

Microsoft will release Microsoft Solutions Framework for Agile Software Development plus Security Development Lifecycle (MSF Agile + SDL) Process Template for Visual Studio Team System (VSTS) 2008 beta (planned for release at the end of Q2). It will also announce that the MSF Agile + SDL process template for Visual Studio 2010 will be released shortly after Microsoft releases Visual Studio 2010 (currently scheduled for April 2010).

With the MSF-Agile+SDL template, any code checked into the VSTS source repository by the developer is analyzed to ensure that it complies with SDL secure development practices. The template also automatically creates workflow tracking items for manual SDL processes such as threat modelling to ensure that these important security activities are not accidentally skipped or forgotten. Finally, they integrate with the other SDL tools, including the SDL Threat Modelling Tool, the Binscope Binary Analyzer, and Minifuzz.

Expansion of SDL Pro Network

Microsoft will expand the SDL Pro Network, which was set up in November 2008. SDL Pro Network members are specialist security organizations that offer services to help organizations adopt the SDL.

At Black Hat D.C. Microsoft will announce the creation of a Tools membership category to complement the Consulting and Training categories. Tools members are companies that are able to deploy a range of security tools, such as static analysis tools for the Implementation Phase and dynamic and binary analysis tools for the Verification phase.

Finally, Microsoft will announce seven new members of the SDL Pro Network:
· Fortify (Tool Member)
· Veracode (Tool Member)
· Codenomicon (Tool Member)
· Booz-Allen Hamilton(Consulting Member)
· Casaba Security (Consulting Member)
· Consult2Comply (Consulting Member)
· Safelight Security Advisors (Training Member)

More information about the Microsoft SDL Pro Network and tools available through the SDL portal

 

Latest bank and financial services security articles

 Misconfigured networks are the easiest IT resource hackers exploit

 The Return of Ransomware and Do-it-Yourself Botnets

 OmniPerception facial biometric technology can accurately identify a face without the person having to look directly into the camera

 Data protection laws are too relaxed and require revision

 Zeus financial malware targets online banking customers by exploiting Verified by Visa and MasterCard SecureCode security programs

 MITec, FAC and Ukash provide a fully integrated and secure alternative cash payments solution in Mexico

 Imperva's data security suite helps enterprises protect not only web applications and databases but file systems as well

 NVT's integrated hybrid CCTV and alarm system protects Banco de Costa Rica

 Mykonos security appliance stops IT security attacks before the damage is done

 35 percent of companies believe their Intellectual Property has been handed over to competitors

...[view more articles on bank and financial services security]...

 

Other security websites:

Bank and Finance security links

Kabul Bank Security Tight as Afghan Finance Chiefs Plan Response Armed security officers guarded Kabul Bank’s headquarters as finance officials prepared to outline steps to restore confidence in Afghanistan’s biggest private lender after reports of losses triggered withdrawals.

Security guard killed at Ingles identified Security guard killed at Ingles identified

Bank Rakyat expands Ar-Rahnu Xchanges BANK Rakyat is expanding the Ar-Rahnu Islamic pawnbroking by setting up Ar-Rahnu Xchanges at all 124 branches nationwide, says managing director Datuk Kamaruzaman Che Mat. So far, 20 Ar-Rahnu Xchanges are in operation, including 17 operated by the bank itself and three under franchise, he said. Three more Ar-Rahnu Xchanges under franchise will be run by the Wawasan Co-operative in Bandar Sunway ...

Deutsche Bank Names RBS's Kaur as Global Group Audit Head to Succeed Giles Deutsche Bank AG , Germany’s biggest bank, named Royal Bank of Scotland Group Plc’s Pam Kaur global head of group audit to succeed Andrew Giles, who will retire.

Pressure is on Palestinians' West Bank security force to stem anti-settler violence Palestinian security forces, reformed and retrained, have made a strong show of force, arresting hundreds of suspects. But human rights groups accuse them of detaining people without proper cause. Recent Palestinian attacks on West Bank settlers, which are likely to increase in response to relaunched peace talks, pose one of the biggest challenges yet to U.S.-trained Palestinian security forces ...

Security stepped up at Kabul Bank Armed police are posted outside the main branch of Kabul Bank as customers continue to withdraw money amid fears it may collapse.

Bank Muamalat Q1 net profit jumps to RM33.4m BANK Muamalat Malaysia Bhd's net profit more than doubled to RM33.4 million in the first quarter ended June 30 2010 on higher operating income and improved asset quality. The bank's pre-tax profit for the three months rose 117 per cent to RM44.8 million from RM20.7 million in the previous corresponding period. Bank Muamalat's net provisions narrowed considerably to RM16.6 million, a drop of 69 ...

directory of bank and financial security suppliers
Search directory Register your company
Bank Security books:

SEARCH NEWS
DIRECTORY
Google