Cloud Computing
Microsoft offers guidance for cloud application security

Microsoft supports secure cloud and agile programming

Microsoft releases SDL guidlines for cloud-based service providers and agile development

Written by Dave Bailey

Microsoft’s Trustworthy Computing Group (TCG) has published guidance on how to enhance the security development lifecycle (SDL) process for cloud computing applications and services. The guidelines are released just ahead of the launch of Microsoft's web version of its Office tools.

SDL is a software security assurance process and it is applied to everything from a new Windows version to a release of SQL Server or Office.

The company also published a guide to agile programming methodologies - a rapid way of delivering high quality applications.

“This guidance is primarily focused on web service application development,” said Steve Lipner, Microsoft TCG senior director of security engineering strategy.

“The guidance aims to show how security interfaces with cloud computing. For example, if you’re building an application that’s hosted in the cloud, SDL is key to the build of such applications."

Lipner said that the three stakeholders in cloud computing were customers - comprising businesses and government - who wanted secure access to secured data; application providers who create the cloud services; and the cloud providers who set up secure infrastructures for the application providers.

Lipner also emphasised the importance of compliance to Microsoft's cloud provision.

“At Microsoft we were given ISO 27001 certification for our operational and infrastructure cloud processes – this is an important international standard,” he said.

SDL was an outgrowth of Microsoft’s TCG. It was launched in 2002 and formalised in 2004, with a set of specific requirements for the TCG teams with regard to the software development process. SDL has seen six releases since launch.

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

GartnerCommunications

Software-as-a-service failing to impress

Gartner survey finds 'lukewarm' satisfaction levels among enterprises 08 Jul 2009

 

Case study: Bolton Wanderers FC

Bolton Wanderers transfers security to the cloud 10 Nov 2009

Local authorities should not outsource in bulk, says Deloitte

Retaining in-house staff will allow for a more effective IT strategy 06 Nov 2009

Are you actively considering using cloud computing services?

06 Nov 2009

Google releases Closure developer tools

Tools used to build Gmail, Maps and Docs given to public 06 Nov 2009

Exploring the cloud's potential

Intel CTO Justin Rattner and SAP head of research Lutz Heuser explain how their firms are collaborating to make the cloud truly fit for enterprise purposes 05 Nov 2009

Microsoft bids to boost Agile security

SDL extended to include popular development methodology 10 Nov 2009

Microsoft takes Security Development Lifecycle to all developers

Software giant hopes for a more secure software ecosystem 19 May 2009

Open Text reveals 2010 roadmap

ECM firm plans new content and asset management tools 29 Oct 2009

related whitepapers

today's top stories

Face facts: social media is the future

No organisation can afford to ignore the way business communications are changing 18 Mar 2010

Is the data watchdog about to pounce?

Experts believe the Information Commissioner’s Office is itching to use its new power to impose hefty fines for data breaches. Martin Courtney reports 18 Mar 2010

Lloyd’s of London gears up for regulation

CIO Peter Hambling tells Angelica Mari about how the insurance market has updated its IT infrastructure to comply with new regulations 18 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

Smiths Group CIO Brian JonesAnalysis

Q&A: Brian Jones, CIO, Smiths Group

How should conglomerates be looking at the new IT technologies coming through? Brian Jones explains. 19 Mar 2010

Analysis

What security strategy should enterprises adopt after the recession?

Act now to put your your firm on higher growth path advise CISOs 19 Mar 2010

Primary Navigation