United States
Change
|
All Microsoft Sites
Search
Select option:
Microsoft Learning
Microsoft
Bing
Enter search terms
Home
Training
Certification
Career
Blogs & Community
Programs for Businesses
Help
About Us
Who We Are & What We Do
Our Newsroom
Follow Us
Latest News and Announcements
Special Offers
Member Sites
Microsoft Learning Partners
MCP Site
MCT Site
MOS Site
Related Sites
Microsoft IT Academy
Microsoft Education
Microsoft DreamSpark
Imagine Cup
Developer Academic Alliance
Microsoft Digital Literacy Curriculum
Microsoft Education Competencies
Worldwide Learning Sites
By Format
Overview
Classroom Training
E-Learning (Online Training)
Books Overview
E-Reference Overview
Learning Games
By Product/Technology
Overview
Cloud Services
Dynamics
Exchange Server
FAST University
Forefront
Lync Server
Office
SharePoint
SQL Server
System Center
Virtualization
Visual Studio
Windows
Windows Azure
Windows Phone
Windows Server
Windows Small Business Server
More ...
Find Training & Classes Near You
Training Catalog
Retired Courses
Discontinued Exams
Create Your Own Training
Create Online Courses & Learning Snacks (LCDS)
Courseware Library Community Authoring
Academic Programs
Learning Partners
Overview
E-Learning Universal Vouchers
Certification Overview
Overview
Getting Started with Certification (FAQ)
Benefits
Program Benefits and Membership
MCP Career Center
Benefits to Employers
Take an Exam
Overview
Find an Exam
Earn College Credit
Prepare for and Take a Certification Exam (FAQ)
Exam Development and Release Cycle (FAQ)
Exam Policies
Exam Development
By Product/Technology
Overview
Cloud Services
Exchange Server
Lync Server & OCS
Office 365
Private Cloud
SharePoint Server
SQL Server
Virtualization
Visual Studio
Windows Client (Windows 7)
Windows Phone
Windows Server
All Products and Technologies
By Name
Overview
MCITP (IT Professional)
MCTS (Technology Specialist)
MCPD (Professional Developer)
MCAD (Application Developer)
MCDBA (Database Administrator)
MCDST (Desktop Support Technician)
MCSA (Systems Administrator)
MCSD (Solution Developer)
MCSE (Systems Engineer)
MOS (Office Specialist)
Microsoft Dynamics
MTA (Technology Associate)
MCM (Certified Master)
MCA (Certified Architect)
MCT (Certified Trainer)
Overview
Career Offers
IT Manager
Professional
Student
Overview
Blogs & Forums
Webcasts & Videos
Overview
Volume Licensing
Software Assurance
Frequently Asked Questions
Support
Overview
Regional Service Centers – North America
Regional Service Centers – Latin America
Regional Service Centers - Asia/Pacific
Regional Service Centers - Europe/Africa
Learning Books Index
Microsoft.com
>
Microsoft Learning
>
Training Catalog
>
Books
The Security Development Lifecycle
Published:
May 31, 2006
Accompanying Media:
1 Companion CD(s)
Author:
Michael Howard and Steve Lipner
Language:
English
Length:
352 Pages
Level:
Intermediate, Advanced
ISBN 13:
9780735622142
Technology:
Security
ISBN 10:
0-7356-2214-0
Format:
Paperback
List Price:
$ 34.99
Overview
About the Author
Community
Give Feedback
About The Book
Your in-depth, expert guide to the proven process that helps reduce security bugs.
Your customers demand and deserve better security and privacy in their software. This book is the first to detail a rigorous, proven methodology that measurably minimizes security bugs—the Security Development Lifecycle (SDL). In this long-awaited book, security experts Michael Howard and Steve Lipner from the Microsoft Security Engineering Team guide you through each stage of the SDL—from education and design to testing and post-release. You get their first-hand insights, best practices, a practical history of the SDL, and lessons to help you implement the SDL in any development organization.
Discover how to:
Use a streamlined risk-analysis process to find security design issues before code is committed
Apply secure-coding best practices and a proven testing process
Conduct a final security review before a product ships
Arm customers with prescriptive guidance to configure and deploy your product more securely
Establish a plan to respond to new security vulnerabilities
Integrate security discipline into agile methods and processes, such as Extreme Programming and Scrum
Includes a CD featuring:
A six-part security class video conducted by the authors and other Microsoft security experts
Sample SDL documents and fuzz testing tool
PLUS—Get book updates on the Web.
About Michael Howard and Steve Lipner
Michael Howard, CISSP, is a leading security expert. He is a senior security program manager at Microsoft and the coauthor of 19 Deadly Sins of Software Security and the award-winning Writing Secure Code. Michael has worked on Microsoft Windows security since 1992 and now focuses on secure design, programming, and testing techniques. He is the consulting editor for the Secure Software Development Series of books by Microsoft Press.
Steve Lipner, CISSP, is the senior director of Security Engineering Strategy for Microsoft. He is responsible for defining and updating the Security Development Lifecycle and has pioneered numerous security techniques. Steve has over 35 years’ experience as a researcher, development manager, and general manager in IT security.
Other Books By Michael Howard
Writing Secure Code for Windows Vista®
Writing Secure Code, Second Edition
Have Questions?
For advice about training and certification, connect with peers:
Visit the training and certification forum
For questions about a specific certification, chat with a Microsoft Certified Professional (MCP):
Visit our MCP newsgroups
To find out about recommended blogs, Web sites, and upcoming Live Meetings on popular topics, visit our community site:
Visit the Microsoft Learning community
What do you think of this book?
Your feedback is important in helping us create books that serve your needs and meet your expectations.
Please take our survey at
www.microsoft.com/learning/booksurvey
Note: You will need this book's 13-digit International Standard Book Number (ISBN) to take the survey. The ISBN 13 can be found above.
To report or search for corrections in this book or companion content,
please go to
www.microsoft.com/learning/support/books/
Book index
Buy This Book
Related Courses
Collection 80338: Public Sector - Financials in Microsoft Dynamics AX 2012
Collection 80442: Introduction to Microsoft Dynamics CRM 2011
More Courses >>
Related Books
Programming Windows Identity Foundation
Microsoft Exchange Server 2010 Best Practices
More Books >>
Other Best Practices Series Books
Software Change Management: Case Studies and Practical Advice
I. M. Wright’s “Hard Code”: A Decade of Hard-Won Lessons from Microsoft®, Second Edition
Solid Code
More Books >>
Related Services
E-Reference Libraries
Microsoft Press Online Developer Tools
Microsoft Press Online Windows Server & Client
Print This Page
E-mail this page to a friend
Rate this page and submit feedback
Please tell us why you rated the content this way. (optional)
Please choose a rating value for this content.
Please limit comments to 256 characters.
Tweet
Share