Dr. Tom Shinder’s Blog RSS

All Blogs  »  Dr. Tom Shinder's Blog  »  Microsoft Security Space  »  Blog article: The Microsoft ACE Team

The Microsoft ACE Team

I’ve written a bit on how important a Security Development Lifecycle is to creating secure software. Without an SDL, software is designed for functionality first, and then security is “bolted on” at the end of the development process. This can lead to software with more security bugs then you’d care to think about. With an SDL, those bugs never find their way into the software, because the SDL process forces security issues to be considered from the initial inception of the software to the final code release. For any software purchase you make, you need to ask the vendor how they implement an SDL in their own software development process. If they can’t provide you this information, then you should reconsider the software purchase and look to a vendor that can provide you details of their SDL.

But what if you’re a software development house and you don’t have the knowledge or the talent in house to implement an effective SDL? There are a lot of options, but one of the best is to bring in some experts who can perform fast and effective knowledge transfer to bring your developers and project managers up to speed. Which experts should you choose? I think that you can’t do much better than the Microsoft ACE Team. The Microsoft Application Consulting and Engineering Team can do code reviews and train your staff in secure application development. I’ve had the chance to work with this team and they are top notch secure application development professionals.

For more information about Microsoft ACE, check out their blog at:

http://blogs.msdn.com/ace_team/default.aspx

HTH,

Tom

Thomas W Shinder, M.D., MCSE
Microsoft Security Architect / Technical Writer
Prowess Consulting www.prowessconsulting.com

PROWESS CONSULTING documentation | integration | virtualization
Email: tshinder@isaserver.org
MVP — Forefront Edge Security (ISA/TMG/UAG)

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 6 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center