List of C functions banned by Microsoft (in SDL)
msdn.microsoft.com
msdn.microsoft.com
Joel had some thoughts on this a while ago (2005); prepending s for safe and us for unsafe to variables.
Although, IMHO, it's just a poor attempt to compensate for a weak type system (Type Synonyms, etc. are a much better fix, since then your compiler can guarantee that you are doing the right thing).
And banning strlen() is just idiotic. The differences between strlen() and strnlen_s() (the suggested "safe" replacement) are apparently: (1) strnlen_s() takes a maximum string length argument (2) strnlen_s() returns 0 on a NULL pointer. #1 is pointless (what if the string has no predefined maximum length), and will just lead to programmers hardcoding inappropriate constants. #2 is potentially hazardous, because it hides problems: NULL and the empty string are not the same thing, so having strnlen_s() return 0 for both cases is misleading.