EPISODE · Nov 2, 2016 · 49 MIN
Glenn Leifheit -- An Inner Glimpse of the Microsoft SDL
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How do you keep a secure development lifecycle useful as products, teams, and delivery methods change? Glenn Leifheit joins Chris and Robert to share lessons from Microsoft’s SDL and its evolution beyond a rigid sequence of security tasks. He explains the importance of adapting the program to a product’s context, treating developers as customers, and making security help easy to access. The conversation covers community, practical learning, constraints that encourage creative solutions, and the need to evolve alongside development practices. Glenn also describes mentoring across roles and seeking ideas outside the security industry. His central message is that a sustainable SDL depends on partnership and repeatable habits, with processes simple enough to survive staffing changes and the pressures of everyday delivery.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Glenn Leifheit:→ Glenn Leifheit on LinkedInMentioned in this episode:→ Microsoft Security Development Lifecycle (SDL)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Inside the Microsoft SDL with Glenn Leifheit02:48 Where the SDL came from10:54 Adapting security to the product and business13:55 Making developers want to ask for help23:35 Evolving the SDL with development practices31:36 Learning from constraints and outside influences34:54 Treating developers as customers35:30 Building a learning community38:56 Mentoring across roles and experience levels42:42 Learning from organizations outside security46:28 Making security processes sustainable47:07 Partnership, adaptability, and practical next steps
Embed this episode
What this episode covers
How do you keep a secure development lifecycle useful as products, teams, and delivery methods change? Glenn Leifheit joins Chris and Robert to share lessons from Microsoft’s SDL and its evolution beyond a rigid sequence of security tasks. He explains the importance of adapting the program to a product’s context, treating developers as customers, and making security help easy to access. The conversation covers community, practical learning, constraints that encourage creative solutions, and t...
Ready to play
Glenn Leifheit -- An Inner Glimpse of the Microsoft SDL
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.