Advertisement
Promo

Become a member of the ZDNet UK community

Andrew Donoghue

View blog's RSS Feed

Triplesourced

Reporting, musing and not to mention some random scribbling on tech issues from green/sustainable IT to security. (http://adonoghue.wordpress.com/)

Tuesday 23 October 2007, 11:04 AM

RSA Europe: Microsoft discusses securing applications

Posted by Andrew Donoghue

It may comes as a surprise to some of you but Microsoft claims to have a very sophisticated system for making sure its products are as secure as they can be before they ship.

Speaking at the RSA Conference Europe event in London's docklands, Ben Fathi, corporate vice president of development, Windows, Microsoft, said, "The single biggest thing that has changed at Microsoft is the security development lifecycle – how to develop secure software – every single product goes through this cycle."

The cycle is made up of the following stages: Requirements, design, implementation, verification, release, response.

The firt stage involves security program managers who examine how a product or feature can be attacked. Does it have APIs that are public – does it have web services – what are the ways a hacker could use those interfaces?

Microsoft also uses white hat hackers to try and break into the products – and find the bugs and fix them before they are released.

Fahi adds: "Last year 300 products that went through this cycle, they go through this process multiple times and if they do not pass then they don't ship. Three products were not released which affected the release cycle but was the right thing to do for our customers"

Comments on this post

Andrew Donoghue

This member is ranked #26 in our top 100

  • Andrew Donoghue
  • London
  • Member since: October 2006

Site Activity Rating 4

Contacts' Latest Discussions

Number of Tracked Discussions: 2,517

ator1940 ator1940

Chrome-OS download

Monday 30 November 2009, 12:59 AM

6 comments
ator1940 ator1940

Chrome-OS download

Friday 27 November 2009, 3:30 PM

6 comments
ator1940 ator1940

The real Chrome-OS

Friday 27 November 2009, 2:06 AM

6 comments
ator1940 ator1940

Chrome OS

Thursday 26 November 2009, 3:36 PM

6 comments

Contacts' Latest Blogs

Number of Contacts Blogs: 12

Avatar Jonathan Bennett

Did Microsoft violate the GPL?

Wednesday 11 November 2009, 10:19 AM

0 comments

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters