Friday, April 16, 2010

Microsoft Security Newsletter – April 2010

Email Preview Security Newsletter

Security Newsletter
This is a monthly newsletter for IT professionals and developers-bringing security news, guidance, updates, and community resources directly to your inbox. To view an online version of this newsletter, click here or subscribe to the Featured Security and Privacy Content RSS feed to receive more frequent updates on news and featured resources. If you would like to receive less technical security news, guidance, and updates, please subscribe to the Microsoft Security for Home Computer Users Newsletter.
Note from the Editor

Tim Rains

Maintaining the security of an organization's network isn't something that a single technology or "the administrator" can take care of all by themselves. Successfully managing the security of a network is a collaborative effort that requires a combination of security products, tools, practices, and most importantly, the cooperation of the people using the network.

As the saying goes, a chain is only as strong as its weakest link. If you have fortified your network with security technologies and processes, but don't have the cooperation of the network's users, the chain is probably weaker than you think. The importance of end user education cannot be overstated in this context. If the people using your network don't know about the risks and some of the ways they can help mitigate them, they won't be able to help you protect the network. Certainly technologies like BitLocker, Group Policy, and virtualization can help, but security-conscious end users can also be very effective at avoiding threats and/or recognizing and reporting them.

Microsoft offers free tools to help you educate your end users and add another layer of defense for your network. The Internet Safety Toolkit can help you teach employees how to protect company information, customer information, and their own personal information. The Microsoft Security Awareness Toolkit provides actionable guidance, sample training materials, and templates to help you create a security awareness program for your organization. We also recently launched "Tools and Guidance for Managers," a single-page experience for IT managers offering a consolidated view of the latest security research, guidance, and training materials available from Microsoft. Read on for more details on this new experience and other resources to help you continue to evolve your security measures.

Best regards,
Tim Rains, Group Product Manager,
Microsoft Trustworthy Computing


Top Stories
Want an easy way to plan, deploy, operate, and manage your security baselines for the most widely-used Microsoft technologies? Download the latest evolution of the Security Compliance Management (SCM) Toolkit and take advantage of centralized management, a baseline portfolio, customization capabilities, and security baseline export flexibility to better balance your organization's needs for security and functionality.
In order to more quickly deliver information on emerging security issues affecting Microsoft customers, the Microsoft Security Response Center (MSRC) team has launched an official Twitter channel. Follow us @MSFTSecResponse.
The Microsoft Desktop player allows you to access technical security content (videos, webcasts, podcasts, guidance, etc.)-plus links to security resources such as Microsoft IT Evangelist or Developer Evangelist, training opportunities, and user groups in your area-all directly from your desktop. Download an offline version or view the player online.

Security Guidance
Learn how to use FIM 2010 to facilitate self-service password resets and group management with this quick, step-by-step tutorial from IT Content Architect Alan Le Marquand.
Start preparing for FIM 2010 deployment with this overview of the various factors that affect capacity, topology, and performance.
Version 5.0 of the Microsoft SDL process guidance is now available for download. The new version offers added security requirements and recommendations for secure software development at Microsoft as well as SDL guidance for Waterfall and Spiral Development, Agile development, Web applications and line of business applications.
Whether your company already has a solid security strategy in place, or needs guidance to get started, quickly access the tools and resources that can help. We've gathered a wide variety of valuable information you can use to understand the current threat landscape; speed up the development of internal security awareness and training programs; and ensure your IT and developer staff have the information they need to help manage your risk.
Explore early adopter experiences, best practices, and lessons learned from Microsoft's own deployments of security solutions within its global enterprise. By leveraging our best practices, you can make decisions about how best to plan for, deploy, and manage Microsoft solutions in your own environment.
Explore the world of browser and Internet Explorer security from out-of-the-box security features to new options for privacy protection.

This Month's Security Bulletins
Critical:
Important:
Moderate:
Security Bulletin Overview for April 2010
Learn more about MS10-018, released out-of-band on March 30th due to increases in attacks against Internet Explorer 6 and Internet Explorer 7 using the vulnerability discussed in Security Advisory 981374.

Community/MVP Update

Harry L. WaldronSecurity MVP of the Month: Harry L. Waldron, CPCU, CCP, CSP, AAI, AIM, AIS, AIT, AAM, ARP, API
With more than 37 years of experience in IT, Harry Waldron shares security developments and best practices in several technical forums as well as his TechNet Blog. Professionally, he works as a senior developer for Fairfax Information Technology Services, where he provides technical, business, and leadership support on key projects. He has earned 10 professional designations in insurance and technology.

MVP Article of the Month: IT Security Requirements for the New Decade
Technology advancements in the new decade will challenge organizations, due to the fiduciary responsibility of protecting customer information and corporate records. Explore why true protection is only achieved with strong technical defenses, meaningful corporate policies, awareness programs, and an active security team.


Microsoft Product Lifecycle Information

Find information about your particular products on the Microsoft Product Lifecycle Web site.

See a List of Supported Service Packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.


Security Events and Training
Available on demand
Learn how to better address your day-to-day security and privacy challenges, drawing from the experience of some of our top security industry experts. Discover products and solutions, the latest and greatest security features, prescriptive guidelines, and relevant tips.
June 7-10, New Orleans, LA
Check out the Security, Identity, and Access Track at Tech•Ed North America 2010 for the latest guidance and demonstrations of Microsoft Forefront products, identity-based access technologies, Windows security technologies, and more.

Upcoming Security Webcasts
Upcoming security webcasts in a dynamic, interactive format.
For IT Professionals
For Developers
Now On Demand
MSDN Webcast: Security Talk: Security Best Practices for Design and Deployment on Windows Azure (Level 200)
Developing secure applications and services in the cloud requires knowledge of the threat landscape specific to the cloud provider. Learn about the threats that are specific to the cloud and how the Windows Azure architecture deals with these threats. We also cover how to use built-in Windows Azure security features to protect your applications, and how to design services to minimize attack surface.

Security Newsletter
Volume 7, No. 4
April 2010

In This Issue:
Top Stories
Security Guidance
This Month's Security Bulletins
Community/MVP Update
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Microsoft SDL - Developer Starter Kit
Security Awareness Materials
Learn Security On the Job
Learning Paths for Security -Microsoft Training References and Resources
Upcoming Chats
View a listing of upcoming technical chats
Security Blogs
Trustworthy Computing Security/Privacy Blogs RSS
Michael Howard RSS
Eric Lippert RSS
Eric Fitzgerald RSS
MSRC Blog RSS
ACE Team RSS
Windows Security RSS
Solution Accelerators - Security & Compliance RSS
Security Vulnerability Research & Defense RSS
Security Development Lifecycle (SDL) RSS
Security/Privacy Blogs RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions
Open with newsreader
ISA Server
Open with newsreader
Window Vista: Security
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server: Security
Open with newsreader
Community Web Sites
IT Pro Security Community
Additional Security Resources
Security Help and Support for IT Professionals
TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Center
MSDN Security Developer Center
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
© 2010 Microsoft Corporation. All rights reserved. Microsoft, MSDN, Windows, Windows NT, and Windows Server are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
One Microsoft Way
Redmond, WA, 98052, USA

Sign up for other newsletters | Unsubscribe | Update your profile

© 2010 Microsoft Corporation Terms of Use | Trademarks | Privacy Statement
Microsoft

Your cOmment"s Here! Hover Your cUrsOr to leave a cOmment.


Subscribe to: Post Comments (Atom)