Speaking at Microsoft's Security Development Conference in San Francisco this week, Scott Charney, corporate vice president for Trustworthy Computing at Microsoft, detailed Microsoft's journey from just issuing patches when problems occurred to following its own SDL (Security Development Lifecycle) processes, which made security intrinsic to development. "Back in the early days, it was all about whack-a-mole. Problems would occur, patches would issue," said Charney, a former prosecutor.
|