diff --git a/includes/licensing/_edition-requirements.md b/includes/licensing/_edition-requirements.md index 517cf27df5..2b9838f0ae 100644 --- a/includes/licensing/_edition-requirements.md +++ b/includes/licensing/_edition-requirements.md @@ -44,7 +44,7 @@ ms.topic: include |**[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint)**|Yes|Yes|Yes|Yes| |**[Microsoft Defender SmartScreen](/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-overview)**|Yes|Yes|Yes|Yes| |**[Microsoft Pluton](/windows/security/hardware-security/pluton/microsoft-pluton-security-processor)**|Yes|Yes|Yes|Yes| -|**Microsoft Security Development Lifecycle (SDL)**|Yes|Yes|Yes|Yes| +|**[Microsoft Security Development Lifecycle (SDL)](/windows/security/security-foundations/msft-security-dev-lifecycle)**|Yes|Yes|Yes|Yes| |**[Microsoft vulnerable driver blocklist](/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules)**|Yes|Yes|Yes|Yes| |**[Microsoft Windows Insider Preview bounty program](https://www.microsoft.com/msrc/bounty-windows-insider-preview)**|Yes|Yes|Yes|Yes| |**[Modern device management through (MDM)](/windows/client-management/mdm-overview)**|Yes|Yes|Yes|Yes| diff --git a/includes/licensing/_licensing-requirements.md b/includes/licensing/_licensing-requirements.md index 305a28bba1..aab2ad2aeb 100644 --- a/includes/licensing/_licensing-requirements.md +++ b/includes/licensing/_licensing-requirements.md @@ -44,7 +44,7 @@ ms.topic: include |**[Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint)**|❌|❌|Yes|❌|Yes| |**[Microsoft Defender SmartScreen](/windows/security/threat-protection/microsoft-defender-smartscreen/microsoft-defender-smartscreen-overview)**|Yes|Yes|Yes|Yes|Yes| |**[Microsoft Pluton](/windows/security/hardware-security/pluton/microsoft-pluton-security-processor)**|Yes|Yes|Yes|Yes|Yes| -|**Microsoft Security Development Lifecycle (SDL)**|Yes|Yes|Yes|Yes|Yes| +|**[Microsoft Security Development Lifecycle (SDL)](/windows/security/security-foundations/msft-security-dev-lifecycle)**|Yes|Yes|Yes|Yes|Yes| |**[Microsoft vulnerable driver blocklist](/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules)**|Yes|Yes|Yes|Yes|Yes| |**[Microsoft Windows Insider Preview bounty program](https://www.microsoft.com/msrc/bounty-windows-insider-preview)**|Yes|Yes|Yes|Yes|Yes| |**[Modern device management through (MDM)](/windows/client-management/mdm-overview)**|Yes|Yes|Yes|Yes|Yes| diff --git a/windows/security/includes/sections/security-foundations.md b/windows/security/includes/sections/security-foundations.md index 23533d333f..3da545604f 100644 --- a/windows/security/includes/sections/security-foundations.md +++ b/windows/security/includes/sections/security-foundations.md @@ -9,7 +9,7 @@ ms.topic: include | Feature name | Description | |:---|:---| -| **Microsoft Security Development Lifecycle (SDL)** | The Microsoft Security Development Lifecycle (SDL) introduces security best practices, tools, and processes throughout all phases of engineering and development. | +| **[Microsoft Security Development Lifecycle (SDL)](/windows/security/security-foundations/msft-security-dev-lifecycle)** | The Microsoft Security Development Lifecycle (SDL) introduces security best practices, tools, and processes throughout all phases of engineering and development. | | **OneFuzz service** | A range of tools and techniques - such as threat modeling, static analysis, fuzz testing, and code quality checks - enable continued security value to be embedded into Windows by every engineer on the team from day one. Through the SDL practices, Microsoft engineers are continuously provided with actionable and up-to-date methods to improve development workflows and overall product security before the code has been released. | | **[Microsoft Windows Insider Preview bounty program](https://www.microsoft.com/msrc/bounty-windows-insider-preview)** | As part of our secure development process, the Microsoft Windows Insider Preview bounty program invites eligible researchers across the globe to find and submit vulnerabilities that reproduce in the latest Windows Insider Preview (WIP) Dev Channel. The goal of the Windows Insider Preview bounty program is to uncover significant vulnerabilities that have a direct and demonstrable impact on the security of customers using the latest version of Windows.

Through this collaboration with researchers across the globe, our teams identify critical vulnerabilities that were not previously found during development and quicky fix the issues before releasing the final Windows. | diff --git a/windows/security/index.yml b/windows/security/index.yml index 1d02ae460e..96eb0ab2b3 100644 --- a/windows/security/index.yml +++ b/windows/security/index.yml @@ -85,14 +85,14 @@ productDirectory: - title: Application security imageSrc: /media/common/i_queries.svg links: - - url: /windows/security/application-security/application-control/windows-defender-application-control/wdac + - url: /windows/security/application-security/application-control/windows-defender-application-control/ text: Windows Defender Application Control (WDAC) - url: /windows/security/application-security/application-control/user-account-control text: User Account Control (UAC) - url: /windows/security/application-security/application-control/windows-defender-application-control/design/microsoft-recommended-driver-block-rules text: Microsoft vulnerable driver blocklist - url: /windows/security/application-security/application-isolation/microsoft-defender-application-guard/md-app-guard-overview - text: Microsoft Defender Application Guard + text: Microsoft Defender Application Guard (MDAG) - url: /windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview text: Windows Sandbox - url: /windows/security/application-security @@ -101,32 +101,30 @@ productDirectory: - title: Security foundations imageSrc: /media/common/i_build.svg links: - - url: /windows/security/security-foundations - text: Feature 1 - - url: /windows/security/security-foundations - text: Feature 2 - - url: /windows/security/security-foundations - text: Feature 3 - - url: /windows/security/security-foundations - text: Feature 4 - - url: /windows/security/security-foundations - text: Feature 5 + - url: /windows/security/security-foundations/certification/fips-140-validation + text: FIPS 140-2 validation + - url: /windows/security/security-foundations/certification/windows-platform-common-criteria + text: Common Criteria Certifications + - url: /windows/security/security-foundations/msft-security-dev-lifecycle + text: Microsoft Security Development Lifecycle (SDL) + - url: https://www.microsoft.com/msrc/bounty-windows-insider-preview + text: Microsoft Windows Insider Preview bounty program - url: /windows/security/security-foundations text: Learn more about security foundations > - title: Cloud security imageSrc: /media/common/i_cloud-security.svg links: - - url: /windows/security/cloud-security - text: Feature 1 - - url: /windows/security/cloud-security - text: Feature 2 - - url: /windows/security/cloud-security - text: Feature 3 - - url: /windows/security/cloud-security - text: Feature 4 - - url: /windows/security/cloud-security - text: Feature 5 + - url: /mem/intune/protect/security-baselines + text: Security baselines with Intune + - url: /windows/deployment/windows-autopatch + text: Windows Autopatch + - url: /windows/deployment/windows-autopilot + text: Windows Autopilot + - url: /universal-print + text: Universal Print + - url: /windows/client-management/mdm/remotewipe-csp + text: Remote wipe - url: /windows/security/cloud-security text: Learn more about cloud security > diff --git a/windows/security/security-foundations/toc.yml b/windows/security/security-foundations/toc.yml index 51e238fc1f..ae838451e0 100644 --- a/windows/security/security-foundations/toc.yml +++ b/windows/security/security-foundations/toc.yml @@ -3,7 +3,11 @@ items: href: index.md - name: Zero Trust and Windows href: zero-trust-windows-device-health.md -- name: Microsoft Security Development Lifecycle - href: msft-security-dev-lifecycle.md +- name: Offensive research + items: + - name: Microsoft Security Development Lifecycle + href: msft-security-dev-lifecycle.md + - name: Microsoft Windows Insider Preview bounty program 🔗 + href: https://www.microsoft.com/msrc/bounty-windows-insider-preview - name: Certification href: certification/toc.yml \ No newline at end of file diff --git a/windows/security/toc.yml b/windows/security/toc.yml index 1234cb6efc..74469d7972 100644 --- a/windows/security/toc.yml +++ b/windows/security/toc.yml @@ -1,6 +1,4 @@ items: -- name: Windows security - href: index.yml - name: Introduction to Windows security href: introduction.md - name: Security features licensing and edition requirements