Microsoft Security Development Lifecycle (SDL)
A forum for discussing the Microsoft SDL Process and guidance.
Announcements
- Link
Workaround for MSF-Agile+SDL v5.0 install error
SDL Team Friday, June 24, 2011 7:05 PMAnnouncement originially posted Tuesday, August 03, 2010 9:59 PM
Hi everyone,
We've talked with some people experiencing problems when trying to install the MSF-Agile+SDL v5.0 process template. We believe these problems are a result of an incompatibility with certain configurations of Sharepoint, and we are working to correct the issue for the next release of the MSF-Agile+SDL template. In the meantime, you should be able to work around the problem by following these instructions to disable the Sharepoint features of the template:
- Uninstall the template if you've already installed it.
- Reinstall the template files, and uncheck the Additional Sharepoint Components feature during the installation process.
- Using your XML editor of choice, open the file <template install dir>\Process Template\Windows SharePoint Services\wsstasks.xml.
- Near the bottom of the file, you will see the lines:
<!--TfsDashboardSDLAgile -->
<feature featureId="3F6F501A-5DFF-4359-8ED8-232784DFF47E" />
5. Comment out the second line, ie:
<!--TfsDashboardSDLAgile -->
<!-- <feature featureId="3F6F501A-5DFF-4359-8ED8-232784DFF47E" /> -->
6. Save the file and close
7. Open the Process Template Manager in Visual Studio
8. Delete the existing "MSF for Agile Software Development plus Security Development Lifecycle (SDL) v5.0" process template.
9. Upload the process template again, browse for <template install dir>\Process Template\process template.xml.
10. Close the Process Template Manager.
You should now be able to create MSF-A+SDL projects. If you're experiencing the install bug, please let us know if this helps workaround the problem (or if it doesn't).
Thanks,
Bryan
- Link
Announcing the templates for SDL Practices
SDL Team Friday, April 29, 2011 5:46 PMDownload the templates for SDL practices, a library of templates to help you get started with the more thought-based SDL practices or activities: Defining Security Requirements, Creating a Security Bug Bar, Performing a Security Risk Assessment, Conducting a basic threat model, Managing SDL Exception Requests, Performing a Final Security Review.
- Link
Tools updates: SDL Threat Modeling Tool, MiniFuzz File Fuzzer, SDL Regex Fuzzer
SDL Team Friday, September 16, 2011 10:37 PMThe SDL team has recently announced updated versions of three SDL tools:
SDL Threat Modeling Tool v3.1.8
Check them out and feel free to provide comments and feedback.
- Link
Announcing SDL Process Guidance Version 5.2
SDL Team Wednesday, May 23, 2012 9:10 PM - Link
Follow @MSFTsdl on Twitter
SDL Team Friday, June 24, 2011 7:12 PMFollow @MSFTsdl on Twitter to stay informed about the latest news, events and releases of the Microsoft Security Development Lifecycle.
Filtering and SortingUse these options to narrow down the question and discussion list.
- 1515366

Submitting bugs for SDL Threat Modeling Tool
Matthew Theobald Tuesday, January 19, 2010 1:57 PM - 114685

Selling SDL when selling is unnecessary
Kasajian Wednesday, September 29, 2010 4:50 AM - 1513664

Tool Crashes when you choose to "Include in next layer". What's the fix?
Allen Hall Monday, January 11, 2010 4:14 AM - 113199

Hierarchical Diagrams
Liz_ Thursday, October 01, 2009 9:50 AM - 211980

Cannot install MSF-Agile+SDL Process Template v5.0 to TFS 2010
Tianfei Wednesday, July 07, 2010 7:37 AM - 411620

Agile + SDL templates unable to create project
Morten Petteroe Monday, August 09, 2010 11:20 AM - 311527

Disabling auto generation of threats in Hierarchical Diagrams
Matthew Theobald Monday, January 04, 2010 10:49 PM - 111357

Spy ware, Spam Blocker lock-up
Sasha34 Friday, July 17, 2009 3:40 PM - 211334

BinScope: GSFunctionOptimizeCheck
Christian Haefner Thursday, March 24, 2011 1:14 PM - 111153

Where is private key stored when we generate certificate by makecert.exe ?
swapnil kamble Friday, December 18, 2009 11:39 AM - 211060

time limit with Visio Demo version?
SRichardson Tuesday, February 03, 2009 8:08 AM - 511003

Microsoft SDL Pro Network Member
leeniks Wednesday, June 30, 2010 12:36 PM - 210820

ISA 2004 GPO for Windows 7
Crakdkorn Sunday, October 18, 2009 1:38 PM - 510636

Visio 2010 not detected
jkuemerle Friday, February 25, 2011 4:36 PM - 310576

SDL in PRINCE2
lcUK Wednesday, May 12, 2010 9:23 AM - 110483

Running a Process before login into the system
Ezhillmaran Wednesday, June 03, 2009 5:26 AM - 210463

SDLC
Sheen Ismhael Lim Saturday, March 13, 2010 2:17 AM - 510215

SDL Copyrights
david meltzer Wednesday, March 31, 2010 6:41 PM - 410208

Thesis about Threat Modeling
Gus G Tuesday, June 09, 2009 9:07 PM - 29882

Help With DFD Creation - Making Sense of the Diagram Validation
Eric B Tuesday, November 30, 2010 5:43 PM

