Microsoft’s Trustworthy Computing Group (TCG) has published guidance on how to enhance the security development lifecycle (SDL) process for cloud computing applications and services. The guidelines are released just ahead of the launch of Microsoft's web version of its Office tools.
SDL is a software security assurance process and it is applied to everything from a new Windows version to a release of SQL Server or Office.
The company also published a guide to agile programming methodologies - a rapid way of delivering high quality applications.
“This guidance is primarily focused on web service application development,” said Steve Lipner, Microsoft TCG senior director of security engineering strategy.
“The guidance aims to show how security interfaces with cloud computing. For example, if you’re building an application that’s hosted in the cloud, SDL is key to the build of such applications."
Lipner said that the three stakeholders in cloud computing were customers - comprising businesses and government - who wanted secure access to secured data; application providers who create the cloud services; and the cloud providers who set up secure infrastructures for the application providers.
Lipner also emphasised the importance of compliance to Microsoft's cloud provision.
“At Microsoft we were given ISO 27001 certification for our operational and infrastructure cloud processes – this is an important international standard,” he said.
SDL was an outgrowth of Microsoft’s TCG. It was launched in 2002 and formalised in 2004, with a set of specific requirements for the TCG teams with regard to the software development process. SDL has seen six releases since launch.
Have your say on this article
Newsletters
Latest stories from Security Technology
Latest videos
You may also like
Security Technology jobs
Will Google’s new privacy policy impact how you use its services?
Rubbish in... rubbish enterprise. Why proper data management is so important (video, 6 min)
This Forrester report compares the costs and benefits of legacy email and productivity software with Google Apps
Upcoming Events
The implementation of robust, relevant digital strategies is more crucial than ever to the success of insurance businesses
Date: 01 Mar 2012
Time: 09:00am
A showcase of the latest in the information content and management
Date: 20 Mar 2012
Time: 09:00am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?