Microsoft will release on Tuesday guidelines for developers building online applications and for those utilizing the Agile code-development process.
The Agile guidelines apply principles from Microsoft's Security Development Lifecycle (SDL) to Agile, an umbrella term for a development model frequently used for Web-based applications released under short deadlines, called "sprints."
Microsoft adopted the SDL following the company's pledge in 2002 to build more secure code after several high-profile worms and other malicious software posed dangerous risks to its customers.
But the original SDL doesn't fit the Agile process. Agile differs in that developers have a set time in which to develop certain features, after which the application is immediately released in order to get customer feedback, said Bryan Sullivan, security program manager for Microsoft.
The SDL was originally designed for products, such as the Windows OS, that are non-iterative, meaning that there aren't frequent releases of the product that add just a feature or two.
However, all of the SDL requirements have been adopted for the Agile process, but implemented differently, Sullivan said. Agile is used by 85 percent of technology industry professionals, according to Forrester.
Microsoft breaks the SDL down into three requirements: one-time only tasks, those that need to be done for every sprint, and finally "bucket" tasks, which need to be repeated periodically -- such as every six months -- but not for every sprint, Sullivan said.
The Agile guidelines will be available on Tuesday on www.microsoft.com.
Microsoft is also releasing a white paper on security for online Web applications.
As those applications are increasingly interacting and exchanging information, security is paramount, said Steve Lipner, senior director of security engineering at Microsoft's Trustworthy Computing Group.
The white paper outlines key security issues that developers should consider for Web applications, Lipner said.
It also discusses security issues that developers should think about when choosing a hosting provider, such as data and physical security.
References
Latest on Project Management
- The number cruncher's guide to delivering IT value
- Try project management for a 'fun' career
- Carl Zeiss sees clear vision in Project 2010
- Project management carreers on the rise: PMI
- Microsoft releases security guidelines for Agile
- New Epicor program seeks to hold down ERP project costs
- Zoho links project management tool with Google Apps
- 5 open source project management apps to watch
- Oracle looks to planning apps for next billions
- The Open Group offers enterprise architecture tool
IT Services Essentials
- After the Open, Tennis Australia CIO shoots for winning IT
- Gartner: Top 30 offshore locations for 2008
- HP integrates EDS into technology operations
- IBM Q3 revenue rises, but signs of downturn loom
- HP chief Hurd fields questions about EDS buy
- IBM to open services centre in Ballarat
- The 5 quickest returns on your green investment
- HP buys EDS for US$13.9 billion
- Fujitsu taps hydrogen power to fuel energy savings
- Data center mushrooming? Why not get rid of it?
- Graduate .NET IT Software Developer - Step up a Gear!21/03/2010
Information Technology and Internet
I.T. & T
Golden Opportunity to get into the workforce! Multiple Firms, Multiple Vacancies. Contract/Perm available! READ ON - Senior Business Analyst - Equity Trading Systems21/03/2010
Other
I.T. & T
Senior Business Analyst - Equity Trading Systems - Technical Project Consultant - Financial trading technology21/03/2010
Other
I.T. & T
Technical Project Consultant - Financial trading technology - Test Manager21/03/2010
Other
I.T. & T
Test Manager - Senior C++ Software Engineer/Tech Lead21/03/2010
Other
I.T. & T
Senior C++ Software Engineer/Tech Lead - C++ Software Engineer - Trading Systems21/03/2010
Other
I.T. & T
C++ Software Engineer - Trading Systems - C++ Software Engineer - Learn Financial Markets21/03/2010
Other
I.T. & T
C++ Software Engineer - Learn Financial Markets
Whitepapers
-
Operational Responsiveness | An Executive Guide -
PRESCRIPTIVE GUIDE | Information Security and Multi-Compliance: Avoiding Audit Fatigue with a Single IT Compliance Strategy -
Enterprise Management | A Computerworld Strategy Guide -
Computerworld On-Demand Webcast | Winning and retaining customers through better web application performance -
Business Continuity: A Guide to Choosing the Right Technology Solution
TechWorld Blogs
Recent blog posts
- Tim Bray joins Google, slams iPhone ecosystem
- Following social networking privacy
- All aboard the Avatar Economy
- Facebook, PayPal tie up ad payments
- Google goes for more markets: too much too quickly?
- Talk about mobile computing
- iPad arrives: can Apple crack the tablet?
- Linux.conf.au 2010 kicks off in New Zealand
- VMware jumps further into SaaS with Zimbra
- Amarok 2.2.2 released – rock on!
Recent comments
- Pax for Peace!
5 hours 3 min ago - Netbook under 10 inches
12 hours 21 sec ago - Thanks for informative blog
1 day 1 hour ago - Good Day to You all,
I am
2 days 4 hours ago - Play on reliable sites
2 days 4 hours ago - ipad preorder sells
2 days 5 hours ago - Ajax is the more powerful
2 days 7 hours ago - I can see that whole seconds of research were lavished on this.
2 days 15 hours ago - Andorid phone are one that runs google android opereting system
2 days 16 hours ago - Other apps not available
3 days 7 hours ago - To be honest I think I might
3 days 11 hours ago - How much is Microsoft paying you?
3 days 12 hours ago - Free to be Fools Vs Forced to be Fools
3 days 13 hours ago - pointless
3 days 14 hours ago - hp: a lack of customer service. learn from Apple.
3 days 16 hours ago - Touch Screen
3 days 22 hours ago - Kindle and the iPad
4 days 15 hours ago - Asset Management Software
5 days 5 hours ago - 3D TV with glasses set to fail !
6 days 3 hours ago - govt a bunch of wowsers
6 days 14 hours ago





Comments
Post new comment