Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Steve Lipner — The Past, Present, and Future of SDL

34 min20 december 2019

Om avsnittet

How did Microsoft's Security Development Lifecycle become a repeatable engineering practice rather than a one-time security push? Steve Lipner joins Chris and Robert to trace that history from early computer security work through security response, Trustworthy Computing, and the formalization of SDL. He explains why reviewing software at the end cannot scale, how threat modeling and testing became development activities, and what organizations learned as tooling and expectations evolved. The discussion connects that history to teams starting their own programs: establish a way to receive and respond to security reports, use the protections already available in development tools, and build from there. Steve closes with guidance for mature programs that need to keep learning instead of treating yesterday's process as finished.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Steve Lipner:
Steve's website
SAFECode

Mentioned in this episode:
Microsoft Security Development Lifecycle
Microsoft Security Response Center

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Introduction
02:36 Early computer security at MITRE
04:32 A career spanning security products and practice
06:28 Joining Microsoft security response
08:40 Trustworthy Computing and the security push
14:29 Defining and sharing SDL
16:46 Why end-of-cycle audits do not scale
18:32 Formalizing the lifecycle in 2004
21:12 Threat modeling, tools, and security testing
25:12 How secure development keeps evolving
28:35 Advice for starting a security program
32:12 What mature programs should remember

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.