Microsoft Security Development Lifecycle (SDL)
A forum for discussing the Microsoft SDL Process and guidance.
Announcements
- Link
Workaround for MSF-Agile+SDL v5.0 install error
SDL Team Friday, June 24, 2011 7:05 PMAnnouncement originially posted Tuesday, August 03, 2010 9:59 PM
Hi everyone,
We've talked with some people experiencing problems when trying to install the MSF-Agile+SDL v5.0 process template. We believe these problems are a result of an incompatibility with certain configurations of Sharepoint, and we are working to correct the issue for the next release of the MSF-Agile+SDL template. In the meantime, you should be able to work around the problem by following these instructions to disable the Sharepoint features of the template:
- Uninstall the template if you've already installed it.
- Reinstall the template files, and uncheck the Additional Sharepoint Components feature during the installation process.
- Using your XML editor of choice, open the file <template install dir>\Process Template\Windows SharePoint Services\wsstasks.xml.
- Near the bottom of the file, you will see the lines:
<!--TfsDashboardSDLAgile -->
<feature featureId="3F6F501A-5DFF-4359-8ED8-232784DFF47E" />
5. Comment out the second line, ie:
<!--TfsDashboardSDLAgile -->
<!-- <feature featureId="3F6F501A-5DFF-4359-8ED8-232784DFF47E" /> -->
6. Save the file and close
7. Open the Process Template Manager in Visual Studio
8. Delete the existing "MSF for Agile Software Development plus Security Development Lifecycle (SDL) v5.0" process template.
9. Upload the process template again, browse for <template install dir>\Process Template\process template.xml.
10. Close the Process Template Manager.
You should now be able to create MSF-A+SDL projects. If you're experiencing the install bug, please let us know if this helps workaround the problem (or if it doesn't).
Thanks,
Bryan
- Link
Announcing the templates for SDL Practices
SDL Team Friday, April 29, 2011 5:46 PMDownload the templates for SDL practices, a library of templates to help you get started with the more thought-based SDL practices or activities: Defining Security Requirements, Creating a Security Bug Bar, Performing a Security Risk Assessment, Conducting a basic threat model, Managing SDL Exception Requests, Performing a Final Security Review.
- Link
Tools updates: SDL Threat Modeling Tool, MiniFuzz File Fuzzer, SDL Regex Fuzzer
SDL Team Friday, September 16, 2011 10:37 PMThe SDL team has recently announced updated versions of three SDL tools:
SDL Threat Modeling Tool v3.1.8
Check them out and feel free to provide comments and feedback.
- Link
Announcing SDL Process Guidance Version 5.2
SDL Team Wednesday, May 23, 2012 9:10 PM - Link
Follow @MSFTsdl on Twitter
SDL Team Friday, June 24, 2011 7:12 PMFollow @MSFTsdl on Twitter to stay informed about the latest news, events and releases of the Microsoft Security Development Lifecycle.
Filtering and SortingUse these options to narrow down the question and discussion list.
- 1755

BinScope :GSFriendlyInitCheck failure
Jagadish Hadimani Thursday, February 14, 2013 9:30 AM - 11497

Strange problem - objects in Threat Modeling Tool lose focus
Bryan_Celyn Tuesday, October 23, 2012 8:09 PM - 01207

FYI, new Multi-OS/CPU aware "virus" broke through running virtualbox. Destroying host and guest. Obviously for a reason. new methods used,
Permutate-0x Friday, November 30, 2012 5:57 AM - 11549

SDLTM.exe Error: 0 : Exception: System.IO.FileNotFoundException: Could not load file or assembly 'Microsoft.Office.Interop.Visio...
carlthulhu Tuesday, October 23, 2012 11:37 PM - 52681

Real time Vulnerability Scanning using Cat.Net and Roslyn (outside VisualStudio)
Dinis Cruz Thursday, June 07, 2012 10:51 PM - 24525

MS Security development lifecycle Pros/Cons
CrushedOnion Monday, September 26, 2011 1:25 PM - 24435

Old Mircosoft Essentials Definitions....Can I Delete Them?
Maverick Hawk 5 Monday, July 25, 2011 9:28 PM - 13462

my account is lockout...need help seriously
ilawa Friday, September 09, 2011 4:25 PM - 04599

Concatenation()/?
akela_p501usa Friday, June 17, 2011 1:55 AM - 19368

SDL for Base OS
at2oo1 Tuesday, October 26, 2010 10:00 AM - 07217

Welcome to the SDL Process Forum
Arjuna Shunn Thursday, June 17, 2010 7:26 PM - 29725

AutoSave in SDL TMT ?
Roy Davis [Sogeti] Wednesday, May 20, 2009 4:15 PM - 29051

Interested in learning more about threat modeling and the SDL process? Please read this.
Dana Epp [Security MVP]MVPTuesday, May 26, 2009 9:12 PM - 07519

Want to explore your threat models with the SDL TM tool? Come have Coffee and Code with me tomorrow
Dana Epp [Security MVP]MVPTuesday, April 07, 2009 5:37 PM - 47489

Would love input on a suggestion for a future release
Dana Epp [Security MVP]MVPThursday, March 05, 2009 6:51 AM - 07516

Thank you!
Adam ShostackMicrosoft EmployeeMonday, February 23, 2009 6:35 PM - 17211

Small feedback related to Threat Modelling Beta
sdocherty Tuesday, November 25, 2008 1:10 PM - 37784

Diploma thesis regarding Threat Modeling
David Elze Monday, November 17, 2008 2:27 PM - 17298

Security University is already teaching Microsoft SDL & Threat Modeling Methodology !
MikeMcMinn Tuesday, November 11, 2008 9:23 PM - 26949

Welcome to the SDL Threat Modeling Forum
Dana Epp [Security MVP]MVPFriday, November 07, 2008 11:18 PM

