Friday, May 15, 2009

Microsoft Security Newsletter - Volume 6, Issue 5

Microsoft Security Newsletter
Welcome to the Microsoft Security Newsletter - a monthly newsletter for IT professionals and developers bringing security news, guidance, updates, and community resources direct to your inbox. To view an online version of this newsletter, please click here. If you would like to receive less technical security news, guidance and updates, please subscribe to the Microsoft Security for Home Computer Users Newsletter.

Want to receive more frequent updates on news and featured resources? Subscribe to the Featured Security and Privacy Content RSS feed. Have an idea for a future article, or looking for guidance around a specific topic that you have not seen in this newsletter (or on TechNet or MSDN)? E-mail secaware@microsoft.com.
Security Viewpoint
By John Steer, Security Architect, Microsoft Application Consulting & Engineering (ACE) Team
Security is a foundational component that needs to be integrated from the ground up in the development lifecycle. This article provides insight into impersonation and access control lists (ACLs) from a developer's perspective.

Top Stories
First provided in Visual Studio .NET 2002, the Visual C++ compiler's GS switch, which is on by default, is one of the built-in defenses designed to mitigate the buffer overrun attacks. Learn what Microsoft's VC++ compiler team is proactively working on to refine and enhance the abilities of the GS switch.
Join Scott Charney, Corporate Vice President of Microsoft's Trustworthy Computing Group, as he discusses the trusted Internet experience of the future and the need for technological innovation, global public policy, and societal shifts around the issues of privacy and security.
Watch this quick video to learn about features and improvements in the Windows 7 Release Candidate (RC) in areas like performance, networking, security, and PC management—then download the Release Candidate and take a test drive.
By delivering simplified management and providing critical visibility into threats, vulnerabilities, and configuration risks, Forefront codename "Stirling" helps you protect your business with greater confidence and efficiency.

Security Guidance
Download the Microsoft Assessment and Planning (MAP) Toolkit, and assess your PCs' virus and spyware vulnerability, and readiness for implementing Forefront Client Security.
With the introduction of transparent data encryption (TDE) in SQL Server 2008, users now have the choice between cell-level encryption as in SQL Server 2005, full database-level encryption by using TDE, or the file-level encryption options provided by Windows. This white paper compares TDE with these other encryption methods for application developers and database administrators.
SQL Server includes a variety of precise, configurable security features. These features empower administrators to implement defense-in-depth that is optimized for the specific security risks of their environment. Get up to speed on security for the SQL Server Database Engine.
Policy-Based Management is a system for managing one or more instances of SQL Server 2008. Learn monitoring and enforcement best practices and policy-based management scenarios, then get a tutorial on administering servers using Policy-Based Management.
Learn how to install and configure Forefront Security for Exchange Server using Windows PowerShell, fight spam with connection and content filtering, and configure multiple scanning engines and scanning policies.
Get the necessary information and resources that you need before you start the installation and configuration of ISA Server 2006. With this information, your deployment of ISA Server 2006 will be more efficient. The information in this document focuses on a few of the many features in ISA Server 2006, to enable you to quickly prepare for deployment.

This Month's Security Bulletins
Critical:

Community / MVP Update
Security MVP of the Month: Susan Bradley   
Susan Bradley is a Certified Public Accountant (CPA) with CITP, MCP, and GSEC technical certifications. She has been a Small Business Server (SBS) owner since the 4.0 days and supports public SBS newsgroups as a contributor to the Center for Internet Security and a member of the Computer Security Institute.

Microsoft Product Lifecycle Information
Find information about your particular products on the Microsoft Product Support Lifecycle Web site.
See a List of Supported Service Packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

Security Events and Training
MSDN Virtual Lab Series: Microsoft SDL - Developer Starter Kit
Learn how to operate the desired configuration management (DCM) feature in Microsoft System Center Configuration Manager 2007 Service Pack 1 (SP1) for security baseline compliance monitoring.
Examine the reporting capabilities of the desired configuration management (DCM) feature in Microsoft System Center Configuration Manager 2007 Service Pack 1 (SP1), which includes a reporting feature that allows IT specialists either to use built-in reports or customize reports to meet their needs.

Upcoming Security Webcasts
Thursday, June 4, 1:00 PM Pacific Time
Heath Madison, Director of Management and Security, Advaiya, Inc., and Eric Zinn, Enterprise Solutions Specialist, Advaiya, Inc.
Upcoming security webcasts in a dynamic, interactive format.
For IT Professionals
TechNet Webcast: How Microsoft Does IT: Deploying Windows 7 Using System Center Configuration Manager 2007 and OSD. (Level 300)
Tuesday, May 19, 9:30 AM Pacific Time
Chris Adams, Microsoft IT Program Manager II, Microsoft Corporation
TechNet Webcast: Microsoft Identity Lifecycle Manager "2" (ILM "2") for IT Professionals (Level 300)
Tuesday, May 19, 1:00 PM Pacific Time
Brjann Brekkan, Technical Product Manager, Microsoft Corporation
TechNet Webcast: File Classification in Windows Server 2008 R2 (Level 300)
Thursday, May 21, 8:00 AM Pacific Time
Nir Ben-Zvi, Senior Program Manager, Microsoft Corporation and Matthias Wollnik, Storage Solutions Program Manager, Microsoft Corporation
TechNet Webcast: Microsoft Forefront Codename "Stirling" – An Integrated Security Suite (Level 200)
Thursday, May 21, 1:00 PM Pacific Time
Neha Sharma, Group Product Manager, Microsoft Corporation
TechNet Webcast: Microsoft Forefront Codename "Stirling" – Forefront Client Security 2.0 Release Update (Level 200)
Tuesday, May 26, 1:00 PM Pacific Time
Sheila Talwar, Senior Product Manager, Microsoft Corporation
TechNet Webcast: Protect Instant Messenger with Microsoft Forefront Security for Office Communications Server (Level 200)
Thursday, May 28, 1:00 PM Pacific Time
Mike Chan, Senior Product Manager, Microsoft Corporation
TechNet Webcast: Fundamentals of Third-Party Security Management (Level 300)
Monday, June 1, 10:00 AM Pacific Time
Gerard Morisseau, Senior Program Manager, Microsoft Corporation
TechNet Webcast: Configuring with Least Privilege in SQL Server 2008 (Level 300)
Tuesday, June 2, 8:00 AM Pacific Time
Varun Sharma, Security Engineer, Microsoft Corporation
TechNet Webcast: Microsoft Forefront Codename "Stirling" - The next generation of Forefront Security for SharePoint (Level 200)
Tuesday, June 2, 1:00 PM Pacific Time
Kelli Cook, Product Manager, Microsoft Corporation
TechNet Webcast: Windows 7 Feature Overview (Level 200)
Wednesday, June 3, 10:00 AM Pacific Time
Kevin Remde, Senior IT Pro Evangelist, Microsoft Corporation
TechNet Webcast: Forefront Codename "Stirling" - The next generation of Forefront Security for Exchange Server (Level 200)
Thursday, June 4, 1:00 PM Pacific Time
Mike Chan, Senior Product Manager, Microsoft Corporation
TechNet Webcast: Microsoft Exchange Hosted Filtering is now Forefront Online Security for Exchange (Level 200)
Tuesday, June 9, 1:00 PM Pacific Time
Mike Chan, Senior Product Manager, Microsoft Corporation
TechNet Webcast: Information About Microsoft June Security Bulletins (Level 200)
Wednesday, June 10, 11:00 AM Pacific Time
Adrian Stone, Senior Security Program Manager Lead, Microsoft Corporation and Christopher Budd, Security Response Communications Lead, Microsoft Corporation
TechNet Webcast: How to Manage Microsoft System Center Data Protection Manager 2007 in Large Enterprises (Level 300)
Wednesday, June 10, 1:00 PM Pacific Time
Jason Buffington, Senior Technical Product Manager, Microsoft Corporation and Ryan Finnamore, Product Manager, Brocada Inc.
For Developers
MSDN Webcast: Windows Server 2008 R2, NUMA and UMS APIs (Level 300)
Thursday, May 28, 9:00 AM Pacific Time
Phil Pennington, Windows Server Technology Evangelist, Microsoft Corporation
Microsoft On-Demand Webcasts
TechNet Webcast: Security for Exchange and SharePoint - what's not in the box? (Level 200)
Done implementing Microsoft Office SharePoint Server or Microsoft Exchange Server? There's more you can do! Spend an hour with us walking through the Identity and Security products and solutions that help make deployments more secure. We'll spend time discussing Microsoft Forefront Security, the Intelligent Application Gateway, Internet Security and Acceleration Server, Rights Management Services and Identity Lifecycle Manager.
TechNet Webcast: Virtualization with Centralized, Policy-Based Management (Level 300)
The best overall virtualization solution for an organization could be a combination of all the products, technologies, and practices we have seen so far in this webcast series. This begs the question of management. With all these technologies, how will an IT department cope with enforcing company policy? In this webcast, we look at the management side of virtualization in more detail, covering how polices can be managed centrally.

Security Newsletter
Volume 6, No. 5

May 2009
In This Issue:
Security Viewpoint
Top Stories
Security Guidance
This Month's Security Bulletins
Community / MVP Update
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Security Awareness Materials
Guidance, samples, and templates for creating a security-awareness program in your organization.
Learn Security On the Job
Learning Paths for Security - Microsoft Training References and Resources
Upcoming Chats
Security Chat with Kevin Remde
May 18, 2:00 PM Pacific Time
Windows IE8 Expert
Zone

May 21, 10:00 AM Pacific Time
View a listing of upcoming technical chats
Free In-Person Events
TechNet Events
Security Blogs
Michael Howard RSS
Eric Lippert RSS
Eric Fitzgerald RSS
Steve Lamb RSS
MSRC Blog RSS
ACE Team RSS
Jeff Jones RSS
Windows Vista Security RSS
Solution Accelerators - Security & Compliance RSS
Kai Axford RSS
Security Vulnerability Research & Defense RSS
Security Development Lifecycle (SDL) RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions
Open with newsreader
ISA Server
Open with newsreader
Windows 2000: Security
Open with newsreader
Window Vista: Security
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server: Security
Open with newsreader
Other Security Newsgroups
Community Web Sites
IT Pro Security Community
Security Newsgroups
Related Communities
Additional Security Resources
Security Help and Support for IT Professionals
TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Center
MSDN Security Developer Center
Midsize Business Security Center
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
© 2009 Microsoft Corporation. All rights reserved. Microsoft, MSDN, Windows, Windows NT, and Windows Server are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
One Microsoft Way
Redmond, Washington, USA
98052

Sign up for other newsletters | Unsubscribe | Update your profile
© 2009 Microsoft Corporation Terms of Use | Trademarks | Privacy Statement
Microsoft

Your cOmment"s Here! Hover Your cUrsOr to leave a cOmment.


Subscribe to: Post Comments (Atom)