Consumerization of IT–How to address this
Bring Your Own Device or Consumerization of IT are fairly hot themes in a lot of customer organizations. When I talk to customers, there are typically different reactions, once we bring this up. Some tell us, that it is not part of their strategy; some tell us that they plan to do it but that they have a hard time figuring out, how to secure such an environment; very, very ...
10 Years of Trustworthy Computing at Microsoft
Before joining Microsoft a little bit more than 10 years ago, I ran a team at PricewarehoureCoopers on e-Business Risk Management – classical security consulting in the Internet bubble time. When I announced that I will leave PwC and join Microsoft, I got interesting reactions (and remember, this was 2001). Mainly they were along two lines: Oh, you are joining a desktop company? ...
10 Reasons to migrate off Windows XP
I would like you to sit back, close your eyes and think about the year 2001. Think about how you used technology back then, how you used the Internet. Now, let’s take it a little bit further back in history and think of the year 2000. Just after we realized that the Year-2000-Problem was handled very well by the industry. How you used technology, how you used the Internet, the ...
Office 365 Becomes First and Only Major Cloud Productivity Service to Comply With Leading EU and U.S. Standards for Data Protection and Security
A long title but this was the title of the official press statement yesterday. Compliance is always a key question in the public cloud space. Therefore it is very important for us that we now achieved three things: Office 365 is compliant with EU Model Clauses, Data Processing Agreements and ISO 27001 among other standards. Office 365 is the first and only major ...
By Roger Halbheer, on October 31st, 2008% It will be interesting how you see it. When I blogged on Suspended Jail for Hacking Tutorial in France, I got quite some negative feedback like “do you have nothing better to do than to go after these guys”, “why should it be illegal to publish such a tutorial” etc. So, where do you draw . . . → Read More: Hacker arrested for Video Giving Tips for ATM Skimmers
By Roger Halbheer, on October 30th, 2008% I am often asked about the risks of outsourcing (we often talk about processes, legal risks (e.g. Data Protection), etc.) – the list is very long. Today I read an article which touches a completely different issue: It is all about the security processes and the turnover within the outsourcing company.
The story is . . . → Read More: Risk of Outsourcing (and Security Outsourcing)
By Roger Halbheer, on October 29th, 2008% It is as so often, autumn is the time when all the big events are happening in EMEA. This week was RSA Europe (or I think still is) and next week I am looking forward to TechEd EMEA in Barcelona.
So, I worked at RSA Europe on Monday and Tuesday on the two stories . . . → Read More: Getting Ready for TechED EMEA
By Roger Halbheer, on October 27th, 2008% You might know Jeff Jones’ work on the different vulnerability reports comparing different products and vendors. Our goal is to understand and measure our progress and see where we stand with regards to the industry.
Today, Jeff release his OS Desktop vulnerability report for H1 2008, which shows to me some interesting results.
. . . → Read More: H1 OS Desktop Vulnerability Report – Get It Now
By Roger Halbheer, on October 23rd, 2008% Our security team just published an excellent post with a lot more details on the vulnerability we patched. You should definitely read it: http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx
Roger
By Roger Halbheer, on October 23rd, 2008% This is just to inform you that we just released the announced out of band security update MS08-067. Please read the bulletin carefully and then apply the update as soon as possible
Roger
By Roger Halbheer, on October 23rd, 2008% I guess you have seen this already but wanted to make sure that we are reaching you: We are planning to release an Out of Band Security Update today 10am Pacific Time (which is 18pm GMT). This update will affect all currently supported versions of Windows.
Please read the official Advanced Notification in our . . . → Read More: Out of Band Security Update to be Released
By Roger Halbheer, on October 20th, 2008% I recently had the pleasure to be part of an article in World Finance called Stacked against hacks
Visit the virtual version here and go to page 60 and 61
Roger
By Roger Halbheer, on October 17th, 2008% I already blogged a few times on MSAT (the Microsoft Security Assessment Tool). We just released a new version for it, version 4.
For those of you who do not know MSAT: MSAT is a free (stress: free) Risk Assessment Tool mainly targeted a Small and Medium Businesses to get a good understanding of . . . → Read More: Microsoft Security Assessment Tool v4.0 available
By Roger Halbheer, on October 14th, 2008% Today is the day! At Blackhat in August we announced two significant changes to our bulletin release process and today it is the first time this actually kicks in.
Just to recapitulate: What did we change?
We introduced the Microsoft Active Protections Program which is to me a major shift in policy. Up . . . → Read More: Two Important Changes Today to Our Bulletin Process
|
|
|