Triplesourced
Reporting, musing and not to mention some random scribbling on tech issues from green/sustainable IT to security. (http://adonoghue.wordpress.com/)
Tuesday 23 October 2007, 11:04 AM
RSA Europe: Microsoft discusses securing applications
Speaking at the RSA Conference Europe event in London's docklands, Ben Fathi, corporate vice president of development, Windows, Microsoft, said, "The single biggest thing that has changed at Microsoft is the security development lifecycle – how to develop secure software – every single product goes through this cycle."
The cycle is made up of the following stages: Requirements, design, implementation, verification, release, response.
The firt stage involves security program managers who examine how a product or feature can be attacked. Does it have APIs that are public – does it have web services – what are the ways a hacker could use those interfaces?
Microsoft also uses white hat hackers to try and break into the products – and find the bugs and fix them before they are released.
Fahi adds: "Last year 300 products that went through this cycle, they go through this process multiple times and if they do not pass then they don't ship. Three products were not released which affected the release cycle but was the right thing to do for our customers"


