Michael Howard: I'm always asked "How can you claim the SDL is working when Microsoft still issues security updates?" So I want to make sure people understand the goals of the SDL and perhaps more importantly, the non-goals.
There are three major security-related disciplines here at Microsoft and people outside the company often confuse the three.
- 1. Security feature development
- 2. Security response
- 3. Secure software engineering
The first is all about building security features such as authentication technologies, firewalls and such. This is not SDL. At Microsoft the SDL obviously impacts the design and code that goes into these security features, however.