Building more secure software with improved development processes

Michael Howard · IEEE Security & Privacy · 2004

The author draws on experiences gained as a member of Microsoft's central security team to outline some basic best practices for the software development process. These practices benefitted Microsoft products released since the inception of its Trustworthy Computing initiative in 2002. The points are a subset of the security development lifecycle process implemented at Microsoft.

Read the paper · More papers on PaperTik