Chapter 17

Security Development Lifecycle

Security development lifecycle (SDL) can help enterprises improve the safety of their products with minimal cost. It conforms to the idea secure at the source. Proper implementation of SDL can have a positive effect on the development of the enterprise’s security.

17.1 Introduction

SDL was first proposed by Microsoft in software engineering to help with software security solutions. SDL is a security process that focuses on software development, with the principles of security and privacy in all stages of development. Since 2004, SDL has been a mandatory policy in the business of Microsoft. The steps involved in the SDL process are given in Figure 17.1.

Figure 17.1

Steps involved in the SDL process. ...

Get Web Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.