Tag Archives: SDL

What’s Wrong With Secure Software Development?

Despite a wealth of security knowledge and developers’ access to advanced tools, many software security risks remain. Analysts say that vulnerabilities arise because many software developers do not understand how to build security into their code… Continue reading

Share
Posted in Secure Programming | Tagged , , , , | 1 Comment

Windows Server 2008 Security Guide

Windows Server 2008 has been shipped and Security Guide for this server is here. In guide, Microsoft stated: Microsoft engineering teams, consultants, support engineers, partners, and customers have reviewed and approved this prescriptive guidance to make it: Proven. Based on … Continue reading

Share
Posted in Operating Systems and Application Security | Tagged , , | 2 Comments

Michael Howard from Microsoft Analyzes Recent Symantec and IBM Vulnerabilities

One of main persons behind Microsoft SDL, Michael Howard analyzes recent Symantec and IBM Vulnerabilities in his post on MSDN SDL blog. Michael says: The vulnerabilities are not in Symantec code, yet Symantec customers are still open to attack. The … Continue reading

Share
Posted in Software Security, Threats, Vulnerabilities, Attacks | Tagged , , , , , | Leave a comment

Is It Safe?

Eric Bidstrup has posted interesting and a thought provoking commentary about the Common Criteria on MSDN blog. He concludes: If customers expect a real-world answer to the question “Is it Safe?” to be answered by Common Criteria, then Common Criteria … Continue reading

Share
Posted in Security | Tagged , , , | Leave a comment