Steve Lipner — The Past, Present, and Future of SDL episode artwork

EPISODE · Dec 20, 2019 · 33 MIN

Steve Lipner — The Past, Present, and Future of SDL

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How did Microsoft's Security Development Lifecycle become a repeatable engineering practice rather than a one-time security push? Steve Lipner joins Chris and Robert to trace that history from early computer security work through security response, Trustworthy Computing, and the formalization of SDL. He explains why reviewing software at the end cannot scale, how threat modeling and testing became development activities, and what organizations learned as tooling and expectations evolved. The discussion connects that history to teams starting their own programs: establish a way to receive and respond to security reports, use the protections already available in development tools, and build from there. Steve closes with guidance for mature programs that need to keep learning instead of treating yesterday's process as finished.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steve Lipner:→ Steve's website→ SAFECodeMentioned in this episode:→ Microsoft Security Development Lifecycle→ Microsoft Security Response CenterFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Introduction02:36 Early computer security at MITRE04:32 A career spanning security products and practice06:28 Joining Microsoft security response08:40 Trustworthy Computing and the security push14:29 Defining and sharing SDL16:46 Why end-of-cycle audits do not scale18:32 Formalizing the lifecycle in 200421:12 Threat modeling, tools, and security testing25:12 How secure development keeps evolving28:35 Advice for starting a security program32:12 What mature programs should remember

Episode metadata supplied by the publisher feed · Published Dec 20, 2019

Embed this episode

How did Microsoft's Security Development Lifecycle become a repeatable engineering practice rather than a one-time security push? Steve Lipner joins Chris and Robert to trace that history from early computer security work through security response, Trustworthy Computing, and the formalization of SDL. He explains why reviewing software at the end cannot scale, how threat modeling and testing became development activities, and what organizations learned as tooling and expectations evolved. The ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Steve Lipner — The Past, Present, and Future of SDL

0:00 33:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 33 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on December 20, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!