Microsoft Security Development Lifecycle (SDL) announcement
-
Link
Announcement originially posted Tuesday, August 03, 2010 9:59 PM
Hi everyone,
We've talked with some people experiencing problems when trying to install the MSF-Agile+SDL v5.0 process template. We believe these problems are a result of an incompatibility with certain configurations of Sharepoint, and we are working to correct the issue for the next release of the MSF-Agile+SDL template. In the meantime, you should be able to work around the problem by following these instructions to disable the Sharepoint features of the template:
- Uninstall the template if you've already installed it.
- Reinstall the template files, and uncheck the Additional Sharepoint Components feature during the installation process.
- Using your XML editor of choice, open the file <template install dir>\Process Template\Windows SharePoint Services\wsstasks.xml.
- Near the bottom of the file, you will see the lines:
<!--TfsDashboardSDLAgile -->
<feature featureId="3F6F501A-5DFF-4359-8ED8-232784DFF47E" />
5. Comment out the second line, ie:
<!--TfsDashboardSDLAgile -->
<!-- <feature featureId="3F6F501A-5DFF-4359-8ED8-232784DFF47E" /> -->
6. Save the file and close
7. Open the Process Template Manager in Visual Studio
8. Delete the existing "MSF for Agile Software Development plus Security Development Lifecycle (SDL) v5.0" process template.
9. Upload the process template again, browse for <template install dir>\Process Template\process template.xml.
10. Close the Process Template Manager.
You should now be able to create MSF-A+SDL projects. If you're experiencing the install bug, please let us know if this helps workaround the problem (or if it doesn't).
Thanks,
Bryan
-
Link
Download the templates for SDL practices, a library of templates to help you get started with the more thought-based SDL practices or activities: Defining Security Requirements, Creating a Security Bug Bar, Performing a Security Risk Assessment, Conducting a basic threat model, Managing SDL Exception Requests, Performing a Final Security Review.
-
Link
The SDL team has recently announced updated versions of three SDL tools:
SDL Threat Modeling Tool v3.1.8
Check them out and feel free to provide comments and feedback.
- Link
- Link
-
Unanswered0Votescuenta bloqueada
Buenas noches, se ha bloqueado mi cuenta como empresa y me es muy urgente recuperarla para ver los correos que me envian mis clientes y he enviado varias veces con las respuestas que me indican pero ... -
Proposed0VotesUpdate to MSF-Agile+SDL Process Template for TFS 2012
Is there an update to the MSF-Agile+SDL process template for TFS 2012? -
Proposed0VotesSDL templates for TFS online
Are there any plans for including SDL templates on TFS online (http://tfs.visualstudio.com/)? If so, when can we expect it? -
Answered0VotesBlue Screen of Death Appears After Running Microsoft Windows Malware Removal Tool
I have tried to use the Microsoft Windows Malware Removal Tool three times now. Every time that I let the program run overnight to thoroughly investigate for maliscious files I always wake the next ... -
Answered0VotesHow do i uninstall system doctor 2014,
It came in a e-mail and was virus scaned but still opened and infected system. -
Unanswered0VotesCrash on loading SDL Tool
I've used this tool extensively but since 1 month ago it now fails to start. I am just opening the tool, not opening a specific model. "SDLTM.exe ... -
Unanswered0VotesAdditional code generation
according to documentation here http://msdn.microsoft.com/en-us/library/vstudio/jj161081.aspx "These include enabling additional secure code generation features ... -
Unanswered0VotesCan't get back my account
Hi guys, my account i've been blocked and there's no way that i can get it back by using the regular formula with my old passwords and my secret question ... i've no idea what is the right answer ... -
Unanswered0VotesBinScope GSFunctionOptimizeCheck fails for MFC functions
I try to pass BinScope tests for my VS 2012 C++ MFC application and I see that GSFunctionOptimizeCheck fails for MFC ... -
Unanswered0VotesSurface Attack Analyzer - No Security Issues
I ran ASA v1.0 against a new application and there is nothing displayed in the "Security Issues" page. The "Report Summary" and "Attack Surface" pages are populated ... -
Unanswered0VotesSDL Threat Modelling Tool Error
Running on Win 7 64bit with Visio 2010 installed. (Also tried on a 32 bit Win 7 machine with similar results) Install runs fine, but when opening the program and try clicking on ... -
Unanswered0VotesMicrosoft Threat Modeling Tool and Visio problem
Hi, I am trying to install Threat modeling tool and no success. I have windows 7, and Microsoft Visio 2007 is installed on my computer. During installation I get the error that ... -
Answered0VotesSDL Threat Model Has Issues Starting up
When I load the model I created either after start up or by clicking on the stored file the SDL Threat Model tool has intermittent start up issues. When its starts and runs it seems stable but many ... -
Answered0VotesSDL Threat Modeling Tool 3.1.8 Error "The tool encountered a serious problem and needs to close"
Installed Software: Microsoft Windows 8 (64 bit - German) Microsoft Office 2010 Professional Plus (32 bit - German) Microsoft Visio Premium ... -
Unanswered0VotesIntegrate binscope into visual studio 2012
hi, Is there a way to integrate binscope tool into visual studio 2012? it was working on visual studio 2010 but now i can see it in visual studio ... -
Unanswered0VotesMicrosoft Visual Studio 2012 SAST Magic Quadrant
Hello, Has an analysis been performed against the new SDL tools integrated into Visual Studio against common commercial tools such as Fortify, AppScan Source, Klocwork, etc? If so, ... -
Answered0VotesMicrosoft Threat Modeling Tool + Threat Mitigation Completion Bar
Greetings -- During the analysis phase, where you're reviewing potential threats (using STRIDE), I was wondering if it was possible to fully satisfy the completion bar (e.g. all 4 ... -
Answered0VotesMicrosoft Threat Modeling Tool (Deep Copy)
Greetings -- I was hoping someone might be able to tell me if it's possible to perform a 'deep copy' using the Microsoft Threat Modeling tool. My problem: ... -
Proposed1VotesThreat Model Tool compatible with Visio 2013
I have Visio 2013 installed and the Threat Model Tool is throwing an error dialog stating that it is incompatible with this version. When will a release or beta of a Visio 2013 ... -
Discussion0VotesBinScope :GSFriendlyInitCheck failure
Hello All, I am running binscope on one of my DLL and i get the only one error ... - Items 1 to 20 of 198 Next ›


