logo

Evolving Microsoft Security Development Lifecycle (SDL): How continuous SDL can help you build more secure software

ID: 620c60a1-ad55-5acb-99c9-90ecbfb2fa41

STIX ID: report--620c60a1-ad55-5acb-99c9-90ecbfb2fa41

Feed Name: Microsoft Security

Date Published: 2024-03-07

Date Updated: 2026-04-28

Author: David Ornstein and Tony Rice

...
...

Microsoft outlines the evolution of its Security Development Lifecycle into a continuous, data-driven model that embeds security throughout cloud-era CI/CD workflows. The approach automates measurement (e.g., via CodeQL), enhances transparency and traceability (including SBOM requirements and a compliance evidence graph), and modernizes practices with threat modeling improvements, memory-safe languages, open-source supply chain security, and AI-focused assurance (e.g., AI Red Team). The paper frames these changes within the Secure Future Initiative to deliver secure-by-design, secure-by-default products and share best practices with the broader developer community.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.