A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.
read more
Stephen Withers
Wednesday, 26 May 2010 09:29
Microsoft today released a new version of its MSF Agile + SDL Process (MSF-A+SDL) template that is compatible with Visual Studio 2010.
The template checks that code complies with SDL practices before allowing it to be checked into a Visual Studio Team System repository, and creates appropriate security workflow tracking items for manual processes such as treat modelling.
For example, the template generates different workflow items depending on whether the developer checks in C++ or .NET code. And when a developer creates a new sprint, new work items are created.
It also helps integration with other tools including Microsoft's SDL Threat Modeling Tool, the Binscope binary analyser and the MiniFuzz file fuzzer, simplifying the task of recording which tools are uncovering the most bugs.
Another feature of the template is the provision of a 'scope' field that makes it easier for the developer to describe the importance of the issue. It is used in conjunction with the 'bug bar rating' to help determine which issues must be fixed before release, explained Bryan Sullivan, senior security program manager at Microsoft.
Microsoft offers a separate template for organisations using CMMI rather than Agile.
Stephen Withers travelled to Seattle as a guest of Microsoft.
Think again. Most businesses only have PART of a DR plan - and this spells business disaster in the event of an IT disaster.
Download The Seven Sins of Disaster Recovery White Paper now and find out how you can prevent this happening to you.