<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Roger Halbheer on Security &#187; Threat Modeling</title>
	<atom:link href="http://www.halbheer.ch/security/tag/threat-modeling/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.halbheer.ch/security</link>
	<description>Information Security Discussion by Microsoft&#039;s Worldwide Chief Security Advisor.</description>
	<lastBuildDate>Thu, 12 Jan 2012 19:53:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security Development Lifecycle &#8211; Website!</title>
		<link>http://www.halbheer.ch/security/2010/03/08/security-development-lifecycle-website/</link>
		<comments>http://www.halbheer.ch/security/2010/03/08/security-development-lifecycle-website/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 08:30:13 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Development Lifecycle]]></category>
		<category><![CDATA[Ecosystem]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Threat Modeling]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website</guid>
		<description><![CDATA[<p>I often talk about how we learned to engineer security into the products and the results prove that we are on the right track. One of the challenges we always have is how to help the ecosystem to improve as well. One of the ways is to communicate through our website. Not, that this is <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2010/03/08/security-development-lifecycle-website/">Security Development Lifecycle &#8211; Website!</a></span>]]></description>
			<content:encoded><![CDATA[<p>I often talk about how we learned to engineer security into the products and the results prove that we are on the right track. One of the challenges we always have is how to help the ecosystem to improve as well. One of the ways is to communicate through our website. Not, that this is really new news – it is actually a few weeks old but still… We renewed our <a href="http://www.microsoft.com/security/sdl/default.aspx" target="_blank">Security Development Lifecycle site</a>. </p>
<p>If you are developing software internally you should definitely look at the site and think how to implement SDL in your organization. If you want help, there is the <a href="http://www.microsoft.com/security/sdl/getstarted/pronetwork.aspx" target="_blank">SDL Pro Network</a> here to help you to implement SDL. Or <a href="http://www.microsoft.com/security/sdl/getstarted/tools.aspx" target="_blank">leverage the tools</a> we make available. Or much more…</p>
<p>If you are “just” buying software, look at the lifecycle and start to ask your vendors a few questions like:</p>
<ul>
<li>How do you engineer security into the products? (I am not talking about the classical software engineering processes – I am talking about security…) </li>
<li>How do you do Threat Modeling (to me a key piece of the engineering process) </li>
<li>… </li>
</ul>
<p>Roger   </p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2010/03/08/security-development-lifecycle-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

