原文:
It's been a long strange trip toward better security for Microsoft, but
they've made enough progress to have both improvements to their
technique and some highly interesting war stories. The company's got a
new site explaining the past decade's advances, and you have a reson to
read comics at work day.
The process of "baking security in" -- getting developers to think
about security less as "those people who yell at us" and more as an
integral part of any software-construction effort -- lends its name to
Baking Security In. which details Microsoft's progress on the Sccurity
Development Lifecycle, a process involving 14 stages and checkpoints
over the six stages of the software-devlopment cycle (requirments,
design, implement, verification, release, support/service ).
Microsoft has previously estimated that adoption of the SDL strategy
increases lifecycle costs by 20%, If that's a hit the company's willing
to take to build security into their products, building a fairly clever
educational site including "The Amaing Adeventures of Kevlarr", a
developer who requires some convincing (that's him above), is just part
of the effort, But come forthe comics and stay for the videos, as
real-life, non-animated Microsofties like Steve Lipner and Michael
Howard recount their memories of the days before Microsoft got
security-serious.
譯文:
微軟安全開發(fā)的旅程奇怪而又漫長(zhǎng),但是他們?cè)诩夹g(shù)的進(jìn)步和有趣的戰(zhàn)略故事上都發(fā)展迅速,微軟今天啟動(dòng)了一個(gè)新站點(diǎn)用動(dòng)畫的形式來解釋過去十年中微軟就安全技術(shù)方面所作出的努力和進(jìn)步,很值得在上班的時(shí)候看一看這個(gè)連環(huán)畫。
“baking sercurity in”
這個(gè)過程,是讓開發(fā)者不僅僅是考慮那些侵犯系統(tǒng)程序的人,而且要更多將安全作為任何一個(gè)軟件開發(fā)努力中完整的一部分,將這個(gè)過程取名為“Baking
Security in”,
在這個(gè)連環(huán)畫中詳細(xì)介紹了微軟在安全開發(fā)周期(SDL)中的進(jìn)步,其中包括14個(gè)階段和檢查要點(diǎn)覆蓋了軟件開發(fā)周期的六個(gè)步驟(需求,設(shè)計(jì),實(shí)施,驗(yàn)證,
發(fā)表,支持/服務(wù))。
微軟先前估計(jì)如果采用SDL戰(zhàn)略成本將增加20%,但是如果這是必要的,那么公司愿意去為其產(chǎn)品建立安全體系,并且建立一個(gè)很有教育意義的網(wǎng)站包含
“Kevlarr的傳奇經(jīng)歷”,一個(gè)開發(fā)者很有說服力,其為安全開發(fā)周期做出了努力。但是他來自動(dòng)畫,停留在視頻上,而作為現(xiàn)實(shí)中非動(dòng)畫虛構(gòu)的人物像
Steve Lipner和Michael Howard回憶了在微軟有意識(shí)安全問題嚴(yán)重性以前的那段日子。