The Security Development Lifecycle
SDL: A Process for Developing Demonstrably More Secure Software
Describes how to put software security into practice, covering such topics as risk analysis, coding policies, Agile Methods, cryptographic standards, and threat tree patterns.
