Product Watch: Microsoft Releases 'Agile' Security Development Lifecycle (SDL) Guide

Software giant also issues white paper detailing how SDL addresses cloud security

Dark Reading logo in a gray background | Dark Reading

Microsoft has rolled out the latest offering in its effort to spread the use of its own secure software development program, with a version of its Security Development Lifecycle (SDL) template for developers using an Agile development model.

Agile is a rapidly growing method of writing software that's collaborative and efficient, known for turning around software shorter time frames of 15 to 60 days.

"Forrester says 85 percent of the technology industry has adopted or is midway through adopting Agile development methods," says David Ladd, principal security program manager for Microsoft. "This is the wave of the future."

Microsoft now offers SDL for Agile Development Version 4.1a, a model for Agile developers to integrate SDL into their development processes. Ladd says Microsoft basically modified SDL to meet Agile requirements. The guidelines explain the frequency of threat modeling, static analysis, upgrading compilers, and fuzzing, for example. "Some items need to be performed on a regular basis for the lifetime of the [development] project," Ladd says. "And others only need to be done [occasionally]," as is the case with fuzzing.

"We'd like to have developers and testers begin incorporating SDL into their development life cycles," Ladd says. "Up to this point, we had been focused on traditional SDL and traditional development practices...Now we'd like to see Agile developers look at this guidance."

Microsoft also published a new white paper this week titled "Security Considerations for Client and Cloud Applications," which details the security issues surrounding the client and cloud computing, and what Microsoft has done to advance SDL to address them.

"With the cloud you should think about SDL and not just application development security, but also the operational security issues atop that," Ladd says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

About the Author

Kelly Jackson Higgins, Editor-in-Chief, Dark Reading

Kelly Jackson Higgins is the Editor-in-Chief of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise Magazine, Virginia Business magazine, and other major media properties. Jackson Higgins was recently selected as one of the Top 10 Cybersecurity Journalists in the US, and named as one of Folio's 2019 Top Women in Media. She began her career as a sports writer in the Washington, DC metropolitan area, and earned her BA at William & Mary. Follow her on Twitter @kjhiggins.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights