Secure development lifecycle
A secure development lifecycle (SDL) is a software development process, whichever development methodology an organization already uses, augmented with practices specifically aimed at engineering secure software. It typically adds activities such as code reviews, architectural threat modeling, and both black-box and white-box penetration testing.
An SDL is meant to span a system’s entire lifecycle, not just its build phase. It begins as early as requirements engineering, where security requirements are captured alongside functional ones, and continues after release, feeding vulnerabilities discovered in production back into the requirements and design of future work.
This end-to-end scope is what distinguishes an SDL from a one-off security audit. Security is a standing concern of the process, not an activity performed once before shipping.
The best-known formalization is Microsoft’s Security Development Lifecycle, one of several frameworks that operationalize the broader secure by design philosophy into a concrete sequence of required activities per phase.