Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    SAFECode Advances Secure Code Development with New Leadership

    Written by

    Sean Michael Kerner
    Published December 9, 2016
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      SAFECode is getting new leadership with the appointment of Steven Lipner as Executive Director. Lipner officially took the top job at SAFEcode on December 1, succeeding former U.S federal government cybersecurity co-ordinator Howard Schmidt. In his new role, Lipner will bring his expertise as one of the founders of the Secure Development Lifecycle (SDL) methodology at Microsoft, to SAFECode.

      The Software Assurance Forum for Excellence in Code (SAFECode) is a non-profit effort, supported by multiple organizations, in an effort to help identify and advance best practices for secure software development.

      “The members are under a mutual non-disclosure agreement which enables them to share some internal techniques and documents from time to time,” Lipner told eWEEK. “Basically members work together to collaborate on secure development.”

      SAFEcode members include Adobe Systems Incorporated, CA Technologies, Dell EMC, Intel Corporation, Microsoft Corp., SAP AG, Siemens AG and Symantec Corp.

      Additionally, Lipner said that SAFEcode also works to share best practices externally as well, with free secure development training material as well as documents about security best practices.

      Lipner had previously worked at Microsoft from 1999 until his retirement in April 2015. From 2011 until he retired from Microsoft, he also served as a board member at SAFEcode. Lipner is known for his security work at Microsoft where he helped to create and lead the company’s Security Development Lifecycle (SDL) team. The SDL effort was first implemented by Microsoft in 2004, with the basic idea being to have integrated security by default in both the design and deployment of software. It’s an approach that also led Microsoft to develop a regular patching system as part of a new lifecycle for keeping its customers and its software secure.

      As to why Lipner is joining SAFEcode, he said that he sees it as a way to continue his commitment to secure development and make an impact across the industry.

      “Secure development is as important today, if not more-so, than it was 10 or 15 years ago,” Lipner said.

      There are a number of things that Lipner sees missing in IT security today. Among the big challenges, according to Lipner, is that new developers often are unaware of the importance of secure development. The other item that is an ongoing concern is the level of education among organizations about how to build a secure development program.

      While software development frameworks that directly integrate security are helpful, Lipner emphasized that developers still have to be responsible for their own code.

      “The more that tools can do for developers, with built-in security mechanisms that help developers from making mistakes, the better off code will be,” Lipner said. “That said, there is always still the need for developers to be paying attention, to make sure that what he or she is developing is secure code.”

      Building secure code isn’t about simply lifting the Microsoft SDL model that Lipner helped to pioneer and bringing it to other organizations. He noted that every organization has its own development style and preferences for which tools are used.

      “SDL is not a one size fits all approach,” Lipner said. “Though there are common elements across secure development processes and SAFEcode has released the fundamental practices for security development document and updated it over the years, tracking the things that are common.”

      “Organizations can start with the fundamentals, but they still have to adapt to the needs of their own developers,” he said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.