Microsoft Releases Security Dev Lifecycle as Creative Commons

Updated jeffcogswell 0 Tallied Votes 588 Views Share

In a blog posting August 26, Microsoft announced that it is revising the licensing terms of its Security Development Lifecycle, moving parts of it to a Creative Commons license.

Security Development Lifecycle is a methodology that Microsoft developed that incorporates best security practices at every level of the development lifecycle when security is important--such as in secure business environments or where personally identifiable information is vital.

The methodology includes a set of documentation explaining the process and how to follow it, as well as a set of software tools to help in the software development. But there's always been a catch: While Microsoft certainly wanted organizations to use this methodology, companies weren't allowed to create their own internal documentationbased on the methodology's documentation without express written consent from Microsoft (even if the documentation would be internal to the company).

That certainly seems a little silly; every large company creating software creates its own internal documentation, and such documentation often includes their own adaptation of a particular software development methodology. So if a company uses the Microsoft SDL, most likely they would produce their own documentation based on the existing SDL documentation. But up until now that was technically illegal.

Fortunately, Microsoft realized how absurd that was, and today announced that they have modified the license. While the tools are still proprietary, the documentation itself now has a Creative Commons license. The short story is now that companies that based their own internal processes on this existing documentation are no longer breaking the law. And other companies--the ones that might have shied away from adopting the methodology because they couldn't really do much with it besides read the documentation--can now implement it into their own documentation and actually use it.

Here's the exact text from the blog posting :
[INDENT]By changing the license terms, we are now allowing people and organizations to copy, distribute and transmit the documentation to others; this means that you can now incorporate content from the SDL documents we release under Creative Commons into your internal process documentation – subject to the terms specified by the Creative Commons license mentioned above.
[/INDENT]

Dani AI

Generated

Brief summary and practical context: Microsoft announced in 2010 that key Security Development Lifecycle (SDL) documentation would be made available under a Creative Commons license so organizations could copy, distribute, and incorporate the material into their internal process documents — removing the awkward restriction that previously discouraged adaptation. ’s post correctly flagged that practical shift; industry coverage and Microsoft’s own FAQ reflect the change. Microsoft SDL FAQ eWeek coverage. (microsoft.com)

Which Creative Commons license and what it means: Microsoft used the Attribution‑NonCommercial‑ShareAlike (CC BY‑NC‑SA) terms (3.0 on many SDL pages). That lets teams share and adapt the documents, but requires attribution, prohibits commercial use as defined by CC, and requires derivatives to be released under the same license. Read the license deed and check the Microsoft pages for the specific document’s footer before reuse. SDL (example page) showing license in footer CC BY‑NC‑SA 3.0 deed. (learn.microsoft.com)

Important caveat about tools and samples: the SDL documentation and the SDL tooling are distinct. Microsoft stated that the SDL tools remain under Microsoft’s standard license (they were not relicensed to CC), so do not assume binaries, scripts, or tool source are CC‑free to redistribute or relicense. Verify each asset’s license before bundling it into internal or external materials. (eweek.com)

Quick practical checklist for teams adopting SDL content:

  • Confirm which specific SDL document is CC‑licensed (check the page footer).
  • Preserve the original attribution and include the CC BY‑NC‑SA notice in derivatives.
  • Treat the NonCommercial clause cautiously if materials will be sold or used to provide paid services; get permission or a commercial license if needed.
  • Do not relicense or redistribute Microsoft tools without explicit permission.
  • Keep versioning and source records and consult legal for ambiguous commercial uses. For authoritative details, consult Microsoft’s SDL FAQ and the Creative Commons deed. Microsoft SDL FAQ CC BY‑NC‑SA deed. (microsoft.com)

(Aside: ’s logo comment is noted, but the licensing details above are what determine reuse and redistribution rights.)

sagemore48 0 Newbie Poster

The logo is to telling poeple what it can do

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.