Wednesday, March 11, 2009

Microsoft Security Newsletter - Volume 6, Issue 3

Microsoft Security Newsletter
Welcome to the Microsoft Security Newsletter - a monthly newsletter for IT professionals and developers bringing security news, guidance, updates, and community resources direct to your inbox. To view an online version of this newsletter, please click here. If you would like to receive less technical security news, guidance and updates, please subscribe to the Microsoft Security for Home Computer Users Newsletter.
Security Viewpoint
By Paul Cooke, Director, Windows Client Enterprise Security, Microsoft Corporation
Security is still a top concern for IT professionals. Now that Windows 7 Beta is available, questions regarding what Microsoft has done with the Windows 7 operating system abound. This article covers a few of the key security-related changes and improvements.

Top Stories
Download this guide today and become more effective in building reliable, scalable, and secure applications on the Microsoft platform. Ideal for solution architects and developer leads, this guide provides design-level guidance for integrating security and other quality attributes into the architecture and design of applications built on the .NET Framework. It focuses on the most common types of applications, partitioning application functionality into layers, components, and services, and walks you through their key design characteristics.
Try the next generation of Microsoft Internet Security & Acceleration (ISA) Server and experience key features that include Web antimalware, HTTPS inspection, and the Network Inspection System.
Watch as Mark Russinovich and a panel of subject matter experts discuss what's in store for IT pros with Windows 7. Learn about the evolution of features like Group Policy, BitLocker To Go, DirectAccess, BranchCache, and AppLocker then get tips on troubleshooting, security, deployment, and application compatibility.

Security Guidance
Designed to help you secure and monitor Windows operating systems and the 2007 Microsoft Office system installations, this series marks the next generation of Microsoft security guides. This release includes updated security guides, predefined Group Policy policies, the GPOAccelerator tool, and configuration packs to help you plan, deploy, and monitor your Windows and Office 2007 security baselines.
With Windows 7, IT professionals can provide more capabilities and support greater flexibility for their users, while continuing to minimize cost and security risks. Check out short overviews of what's new in Group Policy, biometrics, smart cards, and more.
Learn about enhancements to core BitLocker Drive Encryption functionality and the new BitLocker To Go, which gives system administrators control over how removable storage devices can be used and what strength of protection is required.
AppLocker is a flexible, easily administered mechanism you can use to specify exactly what is allowed to run on user desktops. Learn how you can realize the security, operational, and compliance benefits of application standardization by using AppLocker.
In this video, VistaPCGuy Kyle Rosenthal takes you on a journey through the tools that you may use every day as an IT administrator to manage and configure the security of a Windows Vista machine -- tools such as Windows Firewall and Windows Defender.

This Month's Security Bulletins
Critical:
Important:
The release candidates (RC) of Windows Server 2008 Service Pack 2 and Windows Vista Service Pack 2 include all previously released updates for Windows Server 2008 and Windows Vista. For a list of these updates, with links to their descriptive pages on the Microsoft Web Support site, click here.

Community / MVP Update
Security MVP of the Month: Marcus Murray   
Marcus Murray is a Senior Security Consultant whose most common work deals with security assessments, penetration testing, server/client/AD hardening, PKI, smartcard deployments, IPSEC, and ISA Server deployments. A certified CISSP, MCT, MCSE+Security, and MVP-Server Security, Marcus is also a keynote speaker for Microsoft road shows and was selected as top speaker for TechEd North America 2007.
In this TechNet Edge interview, Marcus and fellow TrueSec Security Team member Hasain Alshakarti offer tips to help IT pros better secure their environments, discuss the benefits they see in Forefront Stirling, and outline what they would like to see from security 5 - 10 years down the road. Marcus also discusses why he shifted focus from Linux to Microsoft security.

Microsoft Product Lifecycle Information
Find information about your particular products on the Microsoft Product Support Lifecycle Web site.
See a List of Supported Service Packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

Security Events and Training
Register now for Tech•Ed North America, May 11 - 15 in Los Angeles, CA, and then explore the 88 Security, Identity, and Access sessions to customize your Tech•Ed experience. Early Bird savings have ended, but you can still save $150 if you register by March 22.
This free online clinic will provide the knowledge necessary to understand the key features of Microsoft Forefront Client Security, as well as the considerations for deploying Forefront Client Security in a network environment. In addition to providing an overview of the Forefront Security products, the clinic will cover different deployment scenarios, such as installing Forefront Client Security in both single-server and multiple-server environments, and transitioning from existing client security products. The clinic will also cover the process of deploying Forefront Client Security policies.
This free online clinic will provide the knowledge necessary to manage operations in Microsoft Forefront Client Security in a networked environment. The clinic focuses on using the reporting features in Forefront Client Security to better manage the security environment, using alerts and setting alert parameters to detect security risks, and performing scanning operations using Forefront Client Security. The clinic also covers troubleshooting issues that may occur in a Forefront Client Security deployment.

Upcoming Security Webcasts
Thursday, March 12, 11:00 AM Pacific Time
Maya Macauley, Microsoft IT Lead Program Manager, Microsoft Corporation
Wednesday, March 25, 9:00 AM Pacific Time
Bill Jensen, Senior Product Manager, Microsoft Corporation
Find out about upcoming security webcasts using a dynamic, interactive format.
For IT Professionals
TechNet Webcast: Governing Your Enterprise with Policy-Based Management (Level 300)
Thursday, March 12, 1:00 PM Pacific Time
Lara Rubbelke, Data Platform Technology Specialist, Microsoft Corporation
TechNet Webcast: Virtualization Solutions in Branch Offices (Level 300)
Friday, March 13, 8:00 AM Pacific Time
Chris Avis, IT Pro Evangelist, Microsoft Corporation
TechNet Webcast: SQL Server 2008 Capabilities for Meeting PCI Compliance Needs (Level 200)
Monday, March 30, 1:00 PM Pacific Time
Cynthia Papas, Manager of Corporate Governance and Risk Management, Parente Randolph LL, and John Bastow, Application Engineering Manager, Vitale, Caturano and Company, LTD
TechNet Webcast: Windows Mobile 6.1 and Mobile Device Manager 2008: The Gateway to Your Corporate Network (Level 200)
Tuesday, April 7, 10:00 AM Pacific Time
Anthony Spencer, Mobility Consultant, Enterprise Mobile
TechNet Webcast: Management Lockdown of Windows Mobile Devices (Level 300)
Thursday, April 9, 11:30 AM Pacific Time
David Field, Software Architect and Development Manager, Enterprise Mobile
TechNet Webcast: Information About Microsoft April Security Bulletins (Level 200)
Wednesday, April 15, 11:00 AM Pacific Time
Adrian Stone, Senior Security Program Manager Lead, Microsoft Corporation and Christopher Budd, Security Response Communications Lead, Microsoft Corporation
For Developers
MSDN Webcast: Office Communications Server 2007 R2 and Exchange Server 2007 SP1: Under the Hood for Developers (Level 300)
Wednesday, April 1, 1:00 PM Pacific Time
Chris Mayo, Unified Communications Technical Evangelist, Microsoft Corporation
Microsoft On-Demand Webcasts
TechNet Webcast: Windows BitLocker for the Enterprise: Notes from the Field (Level 200)
Join this webcast to learn from some of the experiences encountered in deploying BitLocker Drive Encryption to the desktops of some of the world's largest companies. Discover the questions to ask before deploying BitLocker Drive Encryption, tips to ease deployment, and security guidance for ensuring a secure BitLocker Drive Encryption deployment.
TechNet Webcast: Deploying Forefront Client Security in the Enterprise Using Virtualization (Level 300)
The Microsoft Forefront Client Security (FCS) agent can be installed on Windows Server 2008 host and virtualized operating systems to protect against malicious threats. In addition, you can install the FCS Management Server on Hyper-V virtualized machines to consolidate management server roles. Join this webcast to learn more about deploying FCS in a virtualized environment.

Security Newsletter
Volume 6, No. 3

March 2009
In This Issue:
Security Viewpoint
Top Stories
Security Guidance
This Month's Security Bulletins
Community / MVP Update
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Security Awareness Materials
Guidance, samples, and templates for creating a security-awareness program in your organization.
Learn Security On the Job
Learning Paths for Security - Microsoft Training References and Resources
Upcoming Chats
View a listing of upcoming technical chats
Free In-Person Events
TechNet Events
Security Blogs
Michael Howard RSS
Eric Lippert RSS
Eric Fitzgerald RSS
Steve Lamb RSS
MSRC Blog RSS
ACE Team RSS
Jeff Jones RSS
Windows Vista Security RSS
Solution Accelerators - Security & Compliance RSS
Kai Axford RSS
Security Vulnerability Research & Defense RSS
Steve Riley RSS
Security Development Lifecycle (SDL) RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions
Open with newsreader
ISA Server
Open with newsreader
Windows 2000: Security
Open with newsreader
Window Vista: Security
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server: Security
Open with newsreader
Other Security Newsgroups
Community Web Sites
IT Pro Security Community
Security Newsgroups
Related Communities
Additional Security Resources
Security Help and Support for IT Professionals
TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Center
MSDN Security Developer Center
Midsize Business Security Center
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
© 2009 Microsoft Corporation. All rights reserved. Microsoft, BitLocker, Forefront, Hyper-V, MSDN, SQL Server, Windows, Windows Mobile, Windows Server, and Windows Vista are trademarks of the Microsoft group of companies.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
One Microsoft Way
Redmond, Washington, USA
98052

Sign up for other newsletters | Unsubscribe | Update your profile
© 2009 Microsoft Corporation Terms of Use | Trademarks | Privacy Statement
Microsoft

Your cOmment"s Here! Hover Your cUrsOr to leave a cOmment.


Subscribe to: Post Comments (Atom)