Thursday, March 11, 2010

Microsoft Security Newsletter - Volume 7, Issue 3

Microsoft Security Newsletter
This is a monthly newsletter for IT professionals and developers—bringing security news, guidance, updates, and community resources directly to your inbox. To view an online version of this newsletter, click here or subscribe to the Featured Security and Privacy Content RSS feed to receive more frequent updates on news and featured resources. If you would like to receive less technical security news, guidance, and updates, please subscribe to the Microsoft Security for Home Computer Users Newsletter.
Note from the Editor
Tim Rains  
I'm back from RSA Conference 2010, held in San Francisco last week. Microsoft was a Global Diamond Sponsor of the event where Scott Charney, the Corporate Vice President of Trustworthy Computing at Microsoft, delivered a keynote. Scott's keynote focused on the vision Microsoft has for a safer, more trusted Internet called "End to End Trust." You can watch Scott's RSA keynote by visiting the End to End Trust Web site.

An important element of the End to End Trust vision is the concept of privacy. Privacy encompasses many different issues and can mean different things to each of us. Keeping yourself and your family safe online from scams that could lead to identity theft is a form of privacy. IT professionals may think of privacy in terms of keeping their organization's customer data confidential and safe from data breaches. Governments may think about privacy as it relates to the cloud and providing services to their citizens. However you think about privacy, Microsoft has resources for you.

To learn more about privacy and access some of the content Microsoft has to offer, please visit www.microsoft.com/privacy and consult the tools and resources outlined below.

Best regards,
Tim Rains, Group Product Manager, Microsoft Trustworthy Computing

Top Stories
The Security TechCenter on TechNet features easier access to the top security tasks, tools, events, and videos, in addition to the latest security bulletin and advisory information, news, and highlights.
Try this integrated identity management solution with powerful self-service capabilities for Office end-users, rich administrative tools and enhanced automation for IT professionals and .NET- and WS-* based extensibility for developers.
With Forefront Server Security Management Console, administrators can easily manage Forefront Security for Exchange Server, Forefront Security for SharePoint, and Microsoft Antigen. Use the Web-based console to centralize configuration and operation, automate the download and distribution of signature and scan engine updates, and generate comprehensive reports.
The 2007 Office system was the first Microsoft Office release to integrate the Microsoft Security Development Lifecycle (SDL) process throughout product development. Learn how the SDL affected the development process and improved the security of the 2007 Office system.

Security Guidance
Learn how the Forefront Identity Manager (FIM) 2010 self-service user profile management can be configured for a privacy scenario, enabling end users to selectively control who can view their home phone number.
Follow these guidelines to ensure that customer privacy and data protection is incorporated into the development process.
Find guidance and tools to manage compliance infrastructure and institute sound principles of IT service governance.
Hear directly from Microsoft privacy professionals on the latest discussions, issues, and announcements related to protecting online privacy and safety.
Learn how to address common vulnerabilities from the perspective of multiple business roles: business decision maker, architect, developer, and tester/QA. These papers are intended to help you address a critical business problem now while moving you toward Microsoft SDL adoption in the future.
Walk through a three-step planning and design process of selecting the Forefront UAG features required, determining the number of instances, and designing the infrastructure. This key guidance will help you successfully implement a Forefront UAG.

This Month's Security Bulletins
Important:
Security Bulletin Overview for March 2010

Community/MVP Update
Matthieu Suiche  
Security MVP of the Month: Matthieu Suiche
Matthieu Suiche is a security researcher who focuses on reverse-code engineering and volatile-memory analysis. His research and utilities to date have included Windows hibernation files and Windows physical memory acquisition (Win32dd/Win64dd).

Matthieu has been a speaker during various security conferences such as PacSec, BlackHat USA, and the EUROPOL High Tech Crime Meeting. He currently works for a computer security and kernel code consulting and software company.

MVP Article of the Month: Privacy Considerations for C Language Applications
Walk through some of the core aspects of privacy you should consider when developing applications, services, and Web sites using C development languages.

Microsoft Product Lifecycle Information
Find information about your particular products on the Microsoft Product Lifecycle Web site.

See a List of Supported Service Packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

Security Events and Training
Check out the Security, Identity, and Access track at Tech•Ed North America 2010 for the latest guidance on and demonstrations of Microsoft Forefront products, identity-based access technologies, Windows security technologies, and more.

Upcoming Security Webcasts
Upcoming security webcasts in a dynamic, interactive format.
For IT Professionals
For Developers
Now On Demand
TechNet Webcast: The Case for Data Governance to Maintain Privacy, Confidentiality and Compliance (Part 1 of 4) (Level 100)
Gain an understanding of key data security, privacy, and compliance concerns, and what data governance is, what it encompasses, and how it compliments IT governance and compliance.

Security Newsletter
Volume 7, No. 3

March 2010
In This Issue:
Top Stories
Security Guidance
This Month's Security Bulletins
Community/MVP Update
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Microsoft SDL – Developer Starter Kit
Security Awareness Materials
Learn Security on the Job
Learning Paths for Security – Microsoft Training References and Resources
Upcoming Chats
View a listing of upcoming technical chats
Security Blogs
Trustworthy Computing Security/Privacy Blogs RSS
Michael Howard RSS
Eric Lippert RSS
Eric Fitzgerald RSS
MSRC Blog RSS
ACE Team RSS
Windows Security RSS
Solution Accelerators - Security & Compliance RSS
Security Vulnerability Research & Defense RSS
Security Development Lifecycle (SDL) RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions
Open with newsreader
ISA Server
Open with newsreader
Window Vista: Security
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server: Security
Open with newsreader
Community Web Sites
IT Pro Security Community
Additional Security Resources
Security Help and Support for IT Professionals
TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Center
MSDN Security Developer Center
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
© 2010 Microsoft Corporation. All rights reserved. Microsoft, Azure, MSDN, Forefront, SharePoint, SQL Server, Windows, Windows Server, Windows Vista, and Zune are trademarks of the Microsoft group of companies.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
One Microsoft Way
Redmond, Washington, USA
98052

Sign up for other newsletters | Unsubscribe | Update your profile
© 2010 Microsoft Corporation Terms of Use | Trademarks | Privacy Statement
Microsoft

Your cOmment"s Here! Hover Your cUrsOr to leave a cOmment.


Subscribe to: Post Comments (Atom)