原文:
It's been a long strange trip toward better security for Microsoft, but
they've made enough progress to have both improvements to their
technique and some highly interesting war stories. The company's got a
new site explaining the past decade's advances, and you have a reson to
read comics at work day.
The process of "baking security in" -- getting developers to think
about security less as "those people who yell at us" and more as an
integral part of any software-construction effort -- lends its name to
Baking Security In. which details Microsoft's progress on the Sccurity
Development Lifecycle, a process involving 14 stages and checkpoints
over the six stages of the software-devlopment cycle (requirments,
design, implement, verification, release, support/service ).
Microsoft has previously estimated that adoption of the SDL strategy
increases lifecycle costs by 20%, If that's a hit the company's willing
to take to build security into their products, building a fairly clever
educational site including "The Amaing Adeventures of Kevlarr", a
developer who requires some convincing (that's him above), is just part
of the effort, But come forthe comics and stay for the videos, as
real-life, non-animated Microsofties like Steve Lipner and Michael
Howard recount their memories of the days before Microsoft got
security-serious.
譯文:
微軟安全開發的旅程奇怪而又漫長,但是他們在技術的進步和有趣的戰略故事上都發展迅速,微軟今天啟動了一個新站點用動畫的形式來解釋過去十年中微軟就安全技術方面所作出的努力和進步,很值得在上班的時候看一看這個連環畫。
“baking sercurity in”
這個過程,是讓開發者不僅僅是考慮那些侵犯系統程序的人,而且要更多將安全作為任何一個軟件開發努力中完整的一部分,將這個過程取名為“Baking
Security in”,
在這個連環畫中詳細介紹了微軟在安全開發周期(SDL)中的進步,其中包括14個階段和檢查要點覆蓋了軟件開發周期的六個步驟(需求,設計,實施,驗證,
發表,支持/服務)。
微軟先前估計如果采用SDL戰略成本將增加20%,但是如果這是必要的,那么公司愿意去為其產品建立安全體系,并且建立一個很有教育意義的網站包含
“Kevlarr的傳奇經歷”,一個開發者很有說服力,其為安全開發周期做出了努力。但是他來自動畫,停留在視頻上,而作為現實中非動畫虛構的人物像
Steve Lipner和Michael Howard回憶了在微軟有意識安全問題嚴重性以前的那段日子。
posted on 2009-02-20 09:48
zoyi 閱讀(194)
評論(0) 編輯 收藏 引用 所屬分類:
技術雜文