Security Development Lifecycle still just a concept to many

Analysis
Apr 2, 20103 mins

Vendor survey shows limited awareness, adoption of the process

As a reporter for a publication focused on software development two years ago, I wrote a couple stories about how first software was developed so it did what it was designed to do, then they’d worry about security. So learning since then that security is being built into the development lifecycle from the beginning is encouraging, though it seems like it’s still just a concept.

The firm Errata Security released a survey this week providing some insight into how well security development lifecycle (SDL) planning, including Microsoft’s Security Development Lifecycle initiative, has been embraced. While adoption of SDL generally is small, the SDL methodology with the highest level of “awareness” among survey participants was Microsoft’s, at 23 percent, which should be expected because it’s, you know, Microsoft.

The survey was promoted at the RSA Conference 2010 in San Francisco, at which I was able to sit in on a presentation about Microsoft’s SDL initiative. Participants were given two weeks to take the survey online or in person during RSA. While the survey only drew 46 responses, a small sample in my view given the number of people at RSA, it can still reveal some trends. And as any direct marketer will tell you, a 3 percent response is considered a resounding success.

After Microsoft SDL, the next best known security methodology at just under 18 percent was Microsoft SDL-Agile, for development environments in which software requirements and code building intended to satisfy them are developed in an iterative and collaborative process. Microsoft’s Jeremy Dallman, in a blog post, said the company is “very encouraged by the awareness and implementation” of Microsoft’s methodologies.

However, when asked what methodology companies have actually implemented, Microsoft SDL and SDL-Agile, while the most used of name brand methodologies (at about 6 percent market share each), still were in the back of the field. When asked which methodology is being “implemented” in their organization, more than 18 percent responded “none,” and just under 13 percent answered “ad hoc,” which I take to mean “we make it up as we go along.”

Errata said that the reasons respondents haven’t yet adopted security development lifecycle planning are that it’s too time-consuming (about 11 percent), lack of awareness (9 percent), requires too many resources (less than 8 percent) or is too expensive (less than 3 percent).

This survey is just a start, both in terms of the volume of responses, but also the awareness in the industry of what security development lifecycle planning is and how it can help build more secure software. I’d be interested to see what Errata’s next survey shows us.