Microsoft Security Development Lifecycle (SDL) Design

In response to the Trustworthy Computing (TwC) directive of January 2002, Microsoft defined Secure by Design, Secure by Default, Secure in Deployment, and Communications (SD3+C) to help determine where security and privacy efforts are needed.

The figure shows the Secure software development process model at Microsoft


Windows Vista, Windows Server 2008, Windows 7 and Windows Server 2008 R2 are products of the SDL process.


