Which Secure Software Development Practices do you Employ?
        Posted  
        
            by Michael Howard-MSFT
        on Stack Overflow
        
        See other posts from Stack Overflow
        
            or by Michael Howard-MSFT
        
        
        
        Published on 2010-03-31T16:39:12Z
        Indexed on 
            2010/03/31
            22:13 UTC
        
        
        Read the original article
        Hit count: 490
        
I work on a project known as the Security Development Lifecycle (SDL) project at Microsoft (http://microsoft.com/sdl) - in short it's a set of practices that must be used by product groups before they ship products to help improve security.
Over the last couple of years, we have published a great deal of SDL documentation, as customers ask for more information about what we're doing.
But what I'd like to know is:
1) What are you doing within your organization to help improve the security of your product?
2) What works? What doesn't work?
3) How did you get management to agree to this work?
Thanks.
© Stack Overflow or respective owner