Microsoft To Expand Security Lifecycle Expertise

Microsoft is crossing the aisles to see the security process through from start to finish--not just internally, but for outside software developers too. The company plans to export its Security Development Lifecycle (SDL) process to a greater extent by releasing tools and support to IT pros later this fall, Redmond said this week.

The software giant wants to support developers in building fortified apps, starting at the design and development phase with SDL.

SDL is a "software security assurance process" that has been in place as part of Microsoft's internal architectural policy, going as far back as 2004, explained Steve Lipner, Microsoft's senior director of security engineering strategy for the Trustworthy Computing Group, in a Microsoft-published Q&A.

The SDL methodology, he said, has led to security improvements in flagship products such as Windows Vista and SQL Server. In recent months, hackers have favored attacks on SQL Server solutions via the Internet, although Microsoft has explained the vulnerability as due to insecure Web pages and Web applications.

SDL allows development managers and IT policy-makers to "assess the state of their secure software development practices and to create a vision and road map for reducing customer risk," Lipner explained.

In an effort to broaden its SDL practices, Microsoft is planning a three-pronged rollout, beginning in November.

First, Microsoft plans to make its SDL optimization model (PDF) freely available via a download on MSDN.

Second, if IT pros want to consult security experts, Redmond is forming a "SDL Pro Network," which will be available in November. The network will include trained independent channel partners and Microsoft staff members in the United States and Europe.

Microsoft also generally plans to share its SDL concepts with independent software vendors, partners and customers as a means to achieving security and privacy throughout the "entire computing ecosystem."

Finally, Microsoft plans to release an SDL Threat Modeling Tool 3.0 (PDF) in November. The tool is similar to risk assessment and analysis solutions used to map enterprise IT security.

Microsoft's SDL announcement is part of the company's broader outreach on security. In August at the Black Hat Conference, Microsoft promoted a more collaborative effort on security issues. It also promised for greater transparency during its security patch release cycles.

About the Author

Jabulani Leffall is a business consultant and an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others. He consulted for Deloitte & Touche LLP and was a business and world affairs commentator on ABC and CNN.

Featured

  • The AI Show

    Register for Free to Attend the World's Greatest Show for All Things AI in EDU

    The AI Show @ ASU+GSV, held April 5–7, 2025, at the San Diego Convention Center, is a free event designed to help educators, students, and parents navigate AI's role in education. Featuring hands-on workshops, AI-powered networking, live demos from 125+ EdTech exhibitors, and keynote speakers like Colin Kaepernick and Stevie Van Zandt, the event offers practical insights into AI-driven teaching, learning, and career opportunities. Attendees will gain actionable strategies to integrate AI into classrooms while exploring innovations that promote equity, accessibility, and student success.

  • chart with ascending bars and two silhouetted figures observing it, set against a light background with blue and purple tones

    Report: Enterprises Embracing Agentic AI

    According to research by SnapLogic, 50% of enterprises are already deploying AI agents, and another 32% plan to do so within the next 12 months..

  • laptop screen displays an

    Crafting Thoughtful AI Policy in Higher Education: A Guide for Institutional Leaders

    Here's how to develop and implement an AI framework that not only aligns with an institution's unique mission, but also addresses the diverse needs of its stakeholders, including faculty, students, staff, and administration.

  • minimalist digital network with glowing interconnected lines and nodes

    Integration Brings Cerebras Inference Capabilities to Hugging Face Hub

    AI hardware company Cerebras has teamed up with Hugging Face, the open source platform and community for machine learning, to integrate its inference capabilities into the Hugging Face Hub.