| Security Development Lifecycle |
| Feb. 20, 2006 | ||
|
As a key part of its Trustworthy Computing Initiative, Microsoft reassessed and updated each phase of its internal development life-cycle to add security-focused activities and deliverables. These activities and deliverables, collectively known as the Security Development Lifecycle (SDL) include the following:
Three products, Visual Studio 2005, SQL Server 2005, and BizTalk Server 2006 Beta 2, all of which shipped in Nov. 2005, used the SDL throughout their lifecycle from design to release. All new major enterprise products and products for the Internet, such as Internet Explorer and the Internet Information Service, must use the SDL process. Although it is still collecting data, Microsoft says that the early quality and security metrics for products that have used the SDL are encouraging. For example, Windows Server 2003, which implemented large portions of the SDL, has had substantially fewer security bulletins issued within the first year of its release.
|