Which Secure Software Development Practices do you Employ?
- by Michael Howard-MSFT
I work on a project known as the Security Development Lifecycle (SDL) project at Microsoft (http://microsoft.com/sdl) - in short it's a set of practices that must be used by product groups before they ship products to help improve security.
Over the last couple of years, we have published a great deal of SDL documentation, as customers ask for more information about what we're doing.
But what I'd like to know is:
1) What are you doing within your organization to help improve the security of your product?
2) What works? What doesn't work?
3) How did you get management to agree to this work?
Thanks.