<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Roger Halbheer on Security &#187; Processes</title>
	<atom:link href="http://www.halbheer.info/security/category/microsoft/processes/feed" rel="self" type="application/rss+xml" />
	<link>http://www.halbheer.info/security</link>
	<description>I am the Worldwide Chief Security Advisor for Microsoft and would like to discuss Information Security</description>
	<lastBuildDate>Thu, 09 Sep 2010 12:29:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft and Adobe: Collaboration Against Threats</title>
		<link>http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats</link>
		<comments>http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats#comments</comments>
		<pubDate>Wed, 28 Jul 2010 16:37:49 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Collaboration]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats</guid>
		<description><![CDATA[You know my opinion on collaboration between countries, on public-private-partnerships as well as on collaboration between companies. Since quite a while we run a program called MAPP – the Microsoft Active Protections Program, where we share vulnerability information with security &#8230; <a href="http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/08/06/security-through-collaboration' rel='bookmark' title='Permanent Link: Security through Collaboration'>Security through Collaboration</a></li>
<li><a href='http://www.halbheer.info/security/2009/11/05/international-collaboration-on-policies-for-cybersecurity-and-data-protection' rel='bookmark' title='Permanent Link: International Collaboration on Policies for Cybersecurity and Data Protection'>International Collaboration on Policies for Cybersecurity and Data Protection</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/16/the-importance-of-international-collaborationeven-in-exercises' rel='bookmark' title='Permanent Link: The Importance of International Collaboration&ndash;Even in Exercises'>The Importance of International Collaboration&ndash;Even in Exercises</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F07%252F28%252Fmicrosoft-and-adobe-collaboration-against-threats%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Microsoft%20and%20Adobe%3A%20Collaboration%20Against%20Threats%22%20%7D);"></div>
<p>You know my opinion on collaboration between countries, on public-private-partnerships as well as on collaboration between companies.</p>
<p>Since quite a while we run a program called MAPP – the <a href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx">Microsoft Active Protections Program</a>, where we share vulnerability information with security vendors to help them to get signatures out to our joint customers the moment we release a security update.</p>
<p>Additionally, we know form our data (see the <a href="http://www.microsoft.com/security/about/sir.aspx">Security Intelligence Report</a>) that PDF is the most exploited file format. Therefore I think it is a great signal that Adobe will join the MAPP program to tighten our joint collaboration.</p>
<p>It is another clear signal that we are up for action to address the security challenges in the ecosystem.</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/08/06/security-through-collaboration' rel='bookmark' title='Permanent Link: Security through Collaboration'>Security through Collaboration</a></li>
<li><a href='http://www.halbheer.info/security/2009/11/05/international-collaboration-on-policies-for-cybersecurity-and-data-protection' rel='bookmark' title='Permanent Link: International Collaboration on Policies for Cybersecurity and Data Protection'>International Collaboration on Policies for Cybersecurity and Data Protection</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/16/the-importance-of-international-collaborationeven-in-exercises' rel='bookmark' title='Permanent Link: The Importance of International Collaboration&ndash;Even in Exercises'>The Importance of International Collaboration&ndash;Even in Exercises</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to Deal With Vulnerabilities</title>
		<link>http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities</link>
		<comments>http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities#comments</comments>
		<pubDate>Tue, 27 Jul 2010 14:53:53 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Incident Sharing]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities</guid>
		<description><![CDATA[This is always a fairly emotional theme. What is better to protect the ecosystem? Public or private disclosure? Should somebody paying for vulnerabilities or not? Is a vulnerability auction ethical or not? I know that there are numerous views on &#8230; <a href="http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete' rel='bookmark' title='Permanent Link: Vulnerability Disclosure to Compete?'>Vulnerability Disclosure to Compete?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/selling-vulnerabilities-and-ethics' rel='bookmark' title='Permanent Link: Selling Vulnerabilities and Ethics'>Selling Vulnerabilities and Ethics</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats' rel='bookmark' title='Permanent Link: Microsoft and Adobe: Collaboration Against Threats'>Microsoft and Adobe: Collaboration Against Threats</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F07%252F27%252Fhow-to-deal-with-vulnerabilities%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22How%20to%20Deal%20With%20Vulnerabilities%22%20%7D);"></div>
<p>This is always a fairly emotional theme. What is better to protect the ecosystem? Public or private disclosure? Should somebody paying for vulnerabilities or not? Is a vulnerability auction ethical or not?</p>
<p>I know that there are numerous views on that and I do not want to debate them here and now. What I just want to do here, is to show Microsoft’s position:</p>
<p>Since a long time Microsoft is working with the researcher community in close collaboration and my understanding is that the researcher community is fairly impressed with what we do, once they get the opportunity to look behind the scenes. One of the outcomes of this outreach is <a href="http://technet.microsoft.com/en-us/security/cc261637.aspx">Bluehat</a> – a Microsoft internal event where the researcher talk to our developers. A very and interesting and insightful get together.</p>
<p>When it comes to handling vulnerabilities, I guess you know <a href="http://www.microsoft.com/security/msrc/default.aspx">Microsoft Security Response Center</a> – the group within Microsoft chartered with handling security vulnerabilities. The policies behind working with the researcher community is two-fold:</p>
<ul>
<li>We are not paying for security vulnerabilities, nor do we intend to do so. There was an article on ZDNet again a few days ago: <a href="http://www.zdnet.com/blog/security/microsoft-no-plans-to-pay-for-security-vulnerabilities/6935">Microsoft: No plans to pay for security vulnerabilities</a></li>
<li>We just recently announced a slight change in strategy towards <a href="http://blogs.technet.com/b/ecostrat/archive/2010/07/22/coordinated-vulnerability-disclosure-bringing-balance-to-the-force.aspx">Coordinated Vulnerability Disclosure</a>, an approach, where the collaboration between the finder and the vendor shall be deepened. </li>
</ul>
<p>For me, the joint goal between researcher and vendors has to be to protect the ecosystem against the criminals. And with ecosystem I mean not only the big enterprises, having security teams which are able to work on detailed vulnerability information but small and medium businesses as well as the consumer like my mom and dad as well. Therefore we think that the point above help to meet the requirements.</p>
<p>What are your thoughts on that?</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete' rel='bookmark' title='Permanent Link: Vulnerability Disclosure to Compete?'>Vulnerability Disclosure to Compete?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/selling-vulnerabilities-and-ethics' rel='bookmark' title='Permanent Link: Selling Vulnerabilities and Ethics'>Selling Vulnerabilities and Ethics</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats' rel='bookmark' title='Permanent Link: Microsoft and Adobe: Collaboration Against Threats'>Microsoft and Adobe: Collaboration Against Threats</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Open Source and Hackers</title>
		<link>http://www.halbheer.info/security/2010/06/09/open-source-and-hackers</link>
		<comments>http://www.halbheer.info/security/2010/06/09/open-source-and-hackers#comments</comments>
		<pubDate>Wed, 09 Jun 2010 11:45:32 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Critical Infrastructure Protection]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Behavior]]></category>
		<category><![CDATA[Development Lifecycle]]></category>
		<category><![CDATA[Ecosystem]]></category>
		<category><![CDATA[OpenSource]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/?p=1543</guid>
		<description><![CDATA[The debate is probably as old as the Open Source software development model: Which one is more secure: Open Source or shared source as we at Microsoft run it? I know that we could now enter a religious debate about &#8230; <a href="http://www.halbheer.info/security/2010/06/09/open-source-and-hackers">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/20/the-debate-on-security-metrics' rel='bookmark' title='Permanent Link: The Debate on Security Metrics'>The Debate on Security Metrics</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/08/1541' rel='bookmark' title='Permanent Link: We Need Solid and Strong Transparent Processes for the Cloud'>We Need Solid and Strong Transparent Processes for the Cloud</a></li>
<li><a href='http://www.halbheer.info/security/2010/08/24/the-importance-of-application-security' rel='bookmark' title='Permanent Link: The Importance of Application Security'>The Importance of Application Security</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F06%252F09%252Fopen-source-and-hackers%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Open%20Source%20and%20Hackers%22%20%7D);"></div>
<p>The debate is probably as old as the Open Source software development model: Which one is more secure: Open Source or shared source as we at Microsoft run it? I know that we could now enter a religious debate about that, which I do not want to as I do not really believe in the value of such debate.</p>
<p>However, it is always interesting to see who is looking how at this debate. Does it help security if everyone can see the code or does it help the attackers? We have a program which we call <a href="http://www.microsoft.com/resources/sharedsource/gsp.mspx" target="_blank">Government Security Program</a>, giving governments under certain circumstances (e.g. protection of intellectual property) access to our source. Sometimes we have the debate with government officials whether having access to the code could allow an attacking government to get an advantage in the area or cyberwar or cyber espionage. Looking at that debate, OpenSource would even be worse as it means access for everybody.</p>
<p>Now, I just read this article: <a href="http://www.technologyreview.com/computing/25480/?a=f" target="_blank">Open-Source Could Mean an Open Door for Hackers</a>. It is about a paper looking at data from Intrusion Detection Systems and their finding is that <em>flaws in open-source software tend to be attacked more quickly and more often than vulnerabilities in closed-source software. </em>An interesting statement in the light that we know that there are more vulns in OpenSource software than in shared source and fairly often it is because of the lack of processes enforced to engineer security into the product from the beginning.</p>
<p>Another thing which is important to me is <em>&#8220;As defenders get out their patches, the attackers have more incentive to move on to a different exploit,&#8221; Ransbotham </em>[the author of the paper] <em>says. </em>In other words, having a strong incident response (besides the engineering process) is at least as important.</p>
<p>This should be something the industry adopts. We made our engineering process called <a href="http://www.microsoft.com/security/sdl/default.aspx" target="_blank">Security Development Lifecycle</a> public and I think our incident response is wide known as well as being a best practice. So, something people should finally come to adopt</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/20/the-debate-on-security-metrics' rel='bookmark' title='Permanent Link: The Debate on Security Metrics'>The Debate on Security Metrics</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/08/1541' rel='bookmark' title='Permanent Link: We Need Solid and Strong Transparent Processes for the Cloud'>We Need Solid and Strong Transparent Processes for the Cloud</a></li>
<li><a href='http://www.halbheer.info/security/2010/08/24/the-importance-of-application-security' rel='bookmark' title='Permanent Link: The Importance of Application Security'>The Importance of Application Security</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/06/09/open-source-and-hackers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>We Need Solid and Strong Transparent Processes for the Cloud</title>
		<link>http://www.halbheer.info/security/2010/06/08/1541</link>
		<comments>http://www.halbheer.info/security/2010/06/08/1541#comments</comments>
		<pubDate>Tue, 08 Jun 2010 11:17:25 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Associations]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Ecosystem]]></category>
		<category><![CDATA[Engineering]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/?p=1541</guid>
		<description><![CDATA[This morning I was reading an article called Google seeks to assure customers on cloud security practices on ComputerWeekly. I had to read this – obviously . It references a paper written by the Google Security Officer called Security Whitepaper: &#8230; <a href="http://www.halbheer.info/security/2010/06/08/1541">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2009/11/19/security-a-feature-discussion-some-thoughts-on-googles-chrome-os' rel='bookmark' title='Permanent Link: Security &#8211; A Feature Discussion? Some Thoughts on Google&#8217;s Chrome OS'>Security &#8211; A Feature Discussion? Some Thoughts on Google&#8217;s Chrome OS</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/09/open-source-and-hackers' rel='bookmark' title='Permanent Link: Open Source and Hackers'>Open Source and Hackers</a></li>
<li><a href='http://www.halbheer.info/security/2008/08/18/secure-development-more-than-%e2%80%9ejust%e2%80%9c-code' rel='bookmark' title='Permanent Link: Secure Development: More than „just“ code!'>Secure Development: More than „just“ code!</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F06%252F08%252F1541%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22We%20Need%20Solid%20and%20Strong%20Transparent%20Processes%20for%20the%20Cloud%22%20%7D);"></div>
<p>This morning I was reading an article called <a href="http://www.computerweekly.com/Articles/2010/06/07/241467/Google-seeks-to-assure-customers-on-cloud-security-practices.htm" target="_blank">Google seeks to assure customers on cloud security practices</a> on ComputerWeekly. I had to read this – obviously <img src='http://www.halbheer.info/security/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . It references a paper written by the Google Security Officer called <a href="http://static.googleusercontent.com/external_content/untrusted_dlcp/www.google.com/en//a/help/intl/en/admins/pdf/ds_gsa_apps_whitepaper_0207.pdf" target="_blank">Security Whitepaper: Google Apps Messaging and Collaboration Products</a>. So, I read through it and to me it reflects – unfortunately – the state a lot of Cloud providers are in. Google (and not only Google to be fair), shows how good their physical security to their datacenter is, how they apply access control, monitoring, patch management etc. To me, kind of the standard security practices which I expect them to follow. It is just interesting that to my knowledge Google does not hold an ISO 27001 certification yet – but this is more a side-note.</p>
<p>What really stroke me, is that they do not at all talk about their engineering practices. They always talk about <em>Secure Programming</em> or <em>Implementation Level Security</em> – this is not the whole story as we at Microsoft learned the hard way. It is not about the code as such and if I would have to choose between looking at the code and looking at the engineering practices, I would choose the later. A good product is “just” the outcome of a good process, something we learned in engineering at the university when I was there. So, looking into the code is just the smaller part of the story.</p>
<p>Bearing that in mind, I actually searched for the engineering practices they have and actually found them: <em>Google’s Engineering organization does not require Product Development teams to follow a specific software development process; rather, teams choose and implement processes that fit the project’s needs. As such, a variety of software development processes are in use at Google, from Agile Software Development methodologies to more traditional, phased processes. </em>If I learned one thing during my whole security career then it is that you need fairly strong processes to ensure security – being it on the network or in the design of applications.</p>
<p>That’s the reason we have our <a href="http://www.microsoft.com/security/sdl/default.aspx" target="_blank">Security Development Lifecycle</a> in place. Do not get me wrong, this will not lead to perfect security as there is no such thing like perfect security. However, I am definitely convinced that looking at product security makes less sense than looking into the process the product was engineered. Knowing that it is a requirement for governments, Common Criteria targets at the result and not at the process.</p>
<p>Therefore, statements like: <em>Designed in-house from the ground up, Google’s production servers are based on a stripped and hardened version of Linux that has been customized to include only the components necessary to run Google applications, such as those services required to administer the system and serve user traffic. The system is designed for Google to be able to maintain control over the entire hardware and software stack and to help provide a secure application environment. </em>would not really make me feel any better in the light of what I wrote above.</p>
<p>We as an industry should definitely put more emphasis into the development lifecycle rather than code security and the product as such &#8211; I am clear that secure programming as such as well as tools to do static code analysis are important as well and not to be forgotten.</p>
<p>Rather than re-invent the wheel, I would ask Google (and others) to join <a href="http://www.safecode.org/" target="_blank">SafeCode</a> which exactly targets the process/engineering approach.</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2009/11/19/security-a-feature-discussion-some-thoughts-on-googles-chrome-os' rel='bookmark' title='Permanent Link: Security &#8211; A Feature Discussion? Some Thoughts on Google&#8217;s Chrome OS'>Security &#8211; A Feature Discussion? Some Thoughts on Google&#8217;s Chrome OS</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/09/open-source-and-hackers' rel='bookmark' title='Permanent Link: Open Source and Hackers'>Open Source and Hackers</a></li>
<li><a href='http://www.halbheer.info/security/2008/08/18/secure-development-more-than-%e2%80%9ejust%e2%80%9c-code' rel='bookmark' title='Permanent Link: Secure Development: More than „just“ code!'>Secure Development: More than „just“ code!</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/06/08/1541/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Customer Stories: Why it is not THAT easy to move to the Cloud</title>
		<link>http://www.halbheer.info/security/2010/05/19/customer-stories-why-it-is-not-that-easy-to-move-to-the-cloud</link>
		<comments>http://www.halbheer.info/security/2010/05/19/customer-stories-why-it-is-not-that-easy-to-move-to-the-cloud#comments</comments>
		<pubDate>Wed, 19 May 2010 09:30:19 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Ecosystem]]></category>
		<category><![CDATA[Policies]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/05/19/customer-stories-why-it-is-not-that-easy-to-move-to-the-cloud</guid>
		<description><![CDATA[Ait ss you know from my postings on Cloud and security and the paper on the Cloud Security Considerations we wrote, I am convinced that there are five areas you should look at, when you try to migrate to the &#8230; <a href="http://www.halbheer.info/security/2010/05/19/customer-stories-why-it-is-not-that-easy-to-move-to-the-cloud">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/27/why-google-wont-beat-microsoft-on-cloud-collaboration' rel='bookmark' title='Permanent Link: Why Google Won&rsquo;t Beat Microsoft on Cloud Collaboration'>Why Google Won&rsquo;t Beat Microsoft on Cloud Collaboration</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/23/mature-your-it-and-then-move-to-the-cloud' rel='bookmark' title='Permanent Link: Mature your IT and then move to the Cloud'>Mature your IT and then move to the Cloud</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/11/insider-threat-of-cloud-computing' rel='bookmark' title='Permanent Link: Insider Threat of Cloud Computing'>Insider Threat of Cloud Computing</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F05%252F19%252Fcustomer-stories-why-it-is-not-that-easy-to-move-to-the-cloud%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Customer%20Stories%3A%20Why%20it%20is%20not%20THAT%20easy%20to%20move%20to%20the%20Cloud%22%20%7D);"></div>
<p>Ait ss you know from my postings on Cloud and security and the paper on the <a href="http://go.microsoft.com/?linkid=9708479" target="_blank">Cloud Security Considerations</a> we wrote, I am convinced that there are five areas you should look at, when you try to migrate to the Cloud:</p>
<ol>
<li>Compliance and Risk Management </li>
<li>Identity and Access Management </li>
<li>Service Integrity </li>
<li>Endpoint Integrity </li>
<li>Information Protection </li>
</ol>
<p>The details on these five points are in the paper above. However, I was missing customer stories on that. I had a lot of discussions with customers and they all agreed on the model but I had not too many customers which were ready to talk about these challenges publically. </p>
<p>Recently we published some customer stories, which are worth looking at – even though they are “just” Microsoft case studies.</p>
<p>Let’s start with <a href="http://msexchangeteam.com/archive/2010/05/17/454897.aspx" target="_blank">Why Phaeton Automotive Chose Exchange 2010</a>: There were a few statements, which stroke me (those are customer quotes, not ours). The customer said that <em>We&#8217;d been using Google Apps to manage employee messaging and collaboration needs but wanted better security and privacy. Google Apps was inadequate in meeting business needs.</em> I do not want to challenge Google’s security. What I want to show here is that obviously the customer moved to the cloud “just trusting” that the provider will solve their security challenges – see Consideration #1 above. Even #2 was violated: <em>It didn&#8217;t allow single sign-on service, user migration and couldn&#8217;t help us centrally manage multiple domains.</em></p>
<p>When we move on to <a href="http://www.microsoft.com/casestudies/Case_Study_Detail.aspx?CaseStudyID=4000006660" target="_blank">Rexel: Electrical Distributor Picks Proven Microsoft Messaging Technology over Google Apps</a>, we see law consideration #3 kicking in: <em>With Exchange Online, we knew that we were not taking major risks. Google has less experience in the corporate world, and I don’t think it makes sense to take risks that you can avoid</em>. </p>
<p>Last but not east Serena: <a href="http://blogs.technet.com/msonline/archive/2010/05/18/customer-story-why-serena-software-is-going-with-bpos.aspx">Customer Story: Why Serena Software is Going with BPOS</a>. It is again about the the service delivery and service integrity: <em>They deliver trustworthy, enterprise-class solutions – with the performance, security, privacy, reliability and support we require. We know that Microsoft is a leader in the providing these kinds of solutions, and in our discussions with them, it became clear that they are 100% committed to Serena’s success and delivering solutions that drive the future of collaboration</em></p>
<p>So, it seems that these considerations are really important. We did not look at #5 – Information Protection which is the absolute base for any cloud implementation. You have to understand what you want to move to which implementation of the cloud and which cloud provider.</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/27/why-google-wont-beat-microsoft-on-cloud-collaboration' rel='bookmark' title='Permanent Link: Why Google Won&rsquo;t Beat Microsoft on Cloud Collaboration'>Why Google Won&rsquo;t Beat Microsoft on Cloud Collaboration</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/23/mature-your-it-and-then-move-to-the-cloud' rel='bookmark' title='Permanent Link: Mature your IT and then move to the Cloud'>Mature your IT and then move to the Cloud</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/11/insider-threat-of-cloud-computing' rel='bookmark' title='Permanent Link: Insider Threat of Cloud Computing'>Insider Threat of Cloud Computing</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/05/19/customer-stories-why-it-is-not-that-easy-to-move-to-the-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Want to introduce the Security Development Lifecycle? Play a Game</title>
		<link>http://www.halbheer.info/security/2010/03/22/want-to-introduce-the-security-development-lifecycle-play-a-game</link>
		<comments>http://www.halbheer.info/security/2010/03/22/want-to-introduce-the-security-development-lifecycle-play-a-game#comments</comments>
		<pubDate>Mon, 22 Mar 2010 07:10:00 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Development Lifecycle]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/22/want-to-introduce-the-security-development-lifecycle-play-a-game</guid>
		<description><![CDATA[I was recently pinged by a customer asking for the “real” version of this game. It was distributed at RSA in the US and I do not have any anymore – but you can still print it yourself. So, if &#8230; <a href="http://www.halbheer.info/security/2010/03/22/want-to-introduce-the-security-development-lifecycle-play-a-game">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website' rel='bookmark' title='Permanent Link: Security Development Lifecycle &ndash; Website!'>Security Development Lifecycle &ndash; Website!</a></li>
<li><a href='http://www.halbheer.info/security/2009/05/19/security-development-lifecycle-template-your-next-step-to-secure-development' rel='bookmark' title='Permanent Link: Security Development Lifecycle Template &#8211; Your next step to &#8220;Secure Development&#8221;'>Security Development Lifecycle Template &#8211; Your next step to &#8220;Secure Development&#8221;</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/18/the-impact-of-the-security-development-lifecycle' rel='bookmark' title='Permanent Link: The Impact of the Security Development Lifecycle'>The Impact of the Security Development Lifecycle</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F03%252F22%252Fwant-to-introduce-the-security-development-lifecycle-play-a-game%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Want%20to%20introduce%20the%20Security%20Development%20Lifecycle%3F%20Play%20a%20Game%22%20%7D);"></div>
<p>I was recently pinged by a customer asking for the “real” version of this game. It was distributed at RSA in the US and I do not have any anymore – but you can still print it yourself. </p>
<p>So, if you want to introduce SDL or if you introduced it already and want to re-enforce the message, look at that <a href="http://www.microsoft.com/Security/sdl/eop.aspx" target="_blank">Elevation of Privilege (EoP) card game</a> and start to play!</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website' rel='bookmark' title='Permanent Link: Security Development Lifecycle &ndash; Website!'>Security Development Lifecycle &ndash; Website!</a></li>
<li><a href='http://www.halbheer.info/security/2009/05/19/security-development-lifecycle-template-your-next-step-to-secure-development' rel='bookmark' title='Permanent Link: Security Development Lifecycle Template &#8211; Your next step to &#8220;Secure Development&#8221;'>Security Development Lifecycle Template &#8211; Your next step to &#8220;Secure Development&#8221;</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/18/the-impact-of-the-security-development-lifecycle' rel='bookmark' title='Permanent Link: The Impact of the Security Development Lifecycle'>The Impact of the Security Development Lifecycle</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/22/want-to-introduce-the-security-development-lifecycle-play-a-game/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Legal Challenges of International Business and the Cloud</title>
		<link>http://www.halbheer.info/security/2010/03/09/legal-challenges-of-international-business-and-the-cloud</link>
		<comments>http://www.halbheer.info/security/2010/03/09/legal-challenges-of-international-business-and-the-cloud#comments</comments>
		<pubDate>Tue, 09 Mar 2010 07:10:41 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Behavior]]></category>
		<category><![CDATA[Citizens]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Collaboration]]></category>
		<category><![CDATA[International]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Jurisdiction]]></category>
		<category><![CDATA[MLAT]]></category>
		<category><![CDATA[Policy Makers]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/08/legal-challenges-of-international-business-and-the-cloud</guid>
		<description><![CDATA[To start with: I am an engineer not a lawyer – and this might be part of the problem… When I started to think about the Cloud and security and thought about all the work I do with Law Enforcement &#8230; <a href="http://www.halbheer.info/security/2010/03/09/legal-challenges-of-international-business-and-the-cloud">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/04/21/a-detailed-analysis-of-an-attack-do-we-need-an-international-incident-sharing-database' rel='bookmark' title='Permanent Link: A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?'>A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/23/council-of-europe-octopus-conference-cooperation-against-cybercrime-day-1' rel='bookmark' title='Permanent Link: Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 1'>Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 1</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/24/council-of-europe-octopus-conference-cooperation-against-cybercrime-day-2' rel='bookmark' title='Permanent Link: Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 2'>Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 2</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F03%252F09%252Flegal-challenges-of-international-business-and-the-cloud%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Legal%20Challenges%20of%20International%20Business%20and%20the%20Cloud%22%20%7D);"></div>
<p>To start with: I am an engineer not a lawyer – and this might be part of the problem…</p>
<p>When I started to think about the Cloud and security and thought about all the work I do with Law Enforcement and the challenges they face. Additionally, I started to think about the legal challenges we – as an industry – already had. Or better, the legal challenges I knew about. Our <a href="http://www.halbheer.info/security/2010/01/30/cloud-security-paper-looking-for-feedback" target="_blank">Cloud Security Challenges</a> paper just touches a little bit on this but to me it is a big challenge (to big for an engineer <img src='http://www.halbheer.info/security/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ?)</p>
<p>Let me give you an example: A case which happens often is that Law Enforcement is approaching any mail-provider with the request to access the content of a mailbox because they have a case where the suspect is expected to have mails which can be used as evidence. This is actually fairly standard and within the legal boundaries of a country straight-forward if the law enforcement officer has a court decision. Now, with international providers it gets more complicated as a case in Belgium showed: The Belgium policed asked Yahoo! to give them access to a mailbox of a person living in Belgium based on a Belgium court decision. However, this data is hosted in the United States. Pretty normal: The police then should the FBI for help, they issue the corresponding papers (together with the court) and Yahoo! would hand over the data – this process is called <a href="http://en.wikipedia.org/wiki/Mutual_Legal_Assistance_Treaty" target="_blank">MLAT (mutual legal assistance treaty)</a>. Belgium refused to do that as it was their position that a Belgium decision is good enough because the suspect lives in Belgium. Yahoo! now had two choices: Violate the US law by handing over the data or violate the Belgium court decision by not handing over the data – a lose-lose position they were in <img src='http://www.halbheer.info/security/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> . </p>
<p>And the worst thing to me is that we all have just one goal: <strong>We want to get the criminals arrested – this is a battle where law enforcement, policy makers and the industry are on the same side!</strong> If you want to read more: <a href="http://techcrunch.com/2009/03/02/yahoo-fined-by-belgian-court-for-refusing-to-give-up-e-mail-account-info/">Yahoo Fined By Belgian Court For Refusing To Give Up E-Mail Account Info</a></p>
<p>And there are a lot of cases like this. Cases where the data retention policy in one country asks for data up to 12 months and another country tells you that you are not allowed to keep data for longer than 8 months because of the Data Protection law – if you operate in both, what do you do?</p>
<p>The longer I work in this space the more complicated it gets for me and more of such challenges pop up. This morning I read the following article: <a href="http://blog.uncommonsensesecurity.com/2010/03/step-in-right-direction.html">A step in the right direction</a>. Basically this blog post covers a privacy law put in place in Massachusetts which has broad impact as it is valid not only if you are located in Massachusetts but if the company <em>owns or licenses, receives, stores, maintains, processes, or otherwise has access to personal information in connection with the provision of goods or services or in connection with employment</em>. In other words – if you “run the risk” of selling to somebody in Massachusetts, you are subject to this law! </p>
<p>As I said, the situation gets incredible complex.</p>
<p>Where does this lead us to? To me there are a few things which should be done:</p>
<ul>
<li>Governments and the industry have to work much closer together. The industry has to have the ability to show the stumbling blocks for the businesses and together &#8211; the government and the industry &#8211; have to find solutions which protects the citizens’ rights, helps to grow the economy and helps to go after the criminals. </li>
<li>Governments have to think globally and act locally. Today’s cybercrime environment does not allow anymore for “local only” solutions. There needs to be a certain level of harmonization of laws across the countries and the willingness to collaboration fast. As there is not a global jurisdiction on that level, the willingness to have harmonized legislation will be key. The challenge however is that governments are re-elected locally – not globally… </li>
<li>The Industry has to behave responsibly. In order to make this happen, the industry has to be seen as a partner for the government. The only way to get there – in my opinion – is to act responsibly. If I look at certain behaviors I see in the industry, it is sometimes too much focused on the short-term revenue, rather than a responsible behavior. </li>
</ul>
<p>This will definitely be the basis for a better collaboration and an environment where the legal challenges (see the Yahoo! case above) do not have to be solved on the shoulders of the businesses “just because” of legal deficiencies between countries. As I said above, we all want to fight crime as it is necessary and as it is the only way to grow the Internet in the future. And this all helps us I think</p>
<p>Roger   </p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/04/21/a-detailed-analysis-of-an-attack-do-we-need-an-international-incident-sharing-database' rel='bookmark' title='Permanent Link: A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?'>A Detailed Analysis of an Attack &ndash; Do We Need an International Incident Sharing Database?</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/23/council-of-europe-octopus-conference-cooperation-against-cybercrime-day-1' rel='bookmark' title='Permanent Link: Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 1'>Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 1</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/24/council-of-europe-octopus-conference-cooperation-against-cybercrime-day-2' rel='bookmark' title='Permanent Link: Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 2'>Council of Europe &ndash; Octopus Conference (Cooperation against Cybercrime) Day 2</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/09/legal-challenges-of-international-business-and-the-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Development Lifecycle &#8211; Website!</title>
		<link>http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website</link>
		<comments>http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website#comments</comments>
		<pubDate>Mon, 08 Mar 2010 08:30:13 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Process]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Development Lifecycle]]></category>
		<category><![CDATA[Ecosystem]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Threat Modeling]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website</guid>
		<description><![CDATA[I often talk about how we learned to engineer security into the products and the results prove that we are on the right track. One of the challenges we always have is how to help the ecosystem to improve as &#8230; <a href="http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2009/05/19/security-development-lifecycle-template-your-next-step-to-secure-development' rel='bookmark' title='Permanent Link: Security Development Lifecycle Template &#8211; Your next step to &#8220;Secure Development&#8221;'>Security Development Lifecycle Template &#8211; Your next step to &#8220;Secure Development&#8221;</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/22/want-to-introduce-the-security-development-lifecycle-play-a-game' rel='bookmark' title='Permanent Link: Want to introduce the Security Development Lifecycle? Play a Game'>Want to introduce the Security Development Lifecycle? Play a Game</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/18/the-impact-of-the-security-development-lifecycle' rel='bookmark' title='Permanent Link: The Impact of the Security Development Lifecycle'>The Impact of the Security Development Lifecycle</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F03%252F08%252Fsecurity-development-lifecycle-website%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Security%20Development%20Lifecycle%20%26ndash%3B%20Website%21%22%20%7D);"></div>
<p>I often talk about how we learned to engineer security into the products and the results prove that we are on the right track. One of the challenges we always have is how to help the ecosystem to improve as well. One of the ways is to communicate through our website. Not, that this is really new news – it is actually a few weeks old but still… We renewed our <a href="http://www.microsoft.com/security/sdl/default.aspx" target="_blank">Security Development Lifecycle site</a>. </p>
<p>If you are developing software internally you should definitely look at the site and think how to implement SDL in your organization. If you want help, there is the <a href="http://www.microsoft.com/security/sdl/getstarted/pronetwork.aspx" target="_blank">SDL Pro Network</a> here to help you to implement SDL. Or <a href="http://www.microsoft.com/security/sdl/getstarted/tools.aspx" target="_blank">leverage the tools</a> we make available. Or much more…</p>
<p>If you are “just” buying software, look at the lifecycle and start to ask your vendors a few questions like:</p>
<ul>
<li>How do you engineer security into the products? (I am not talking about the classical software engineering processes – I am talking about security…) </li>
<li>How do you do Threat Modeling (to me a key piece of the engineering process) </li>
<li>… </li>
</ul>
<p>Roger   </p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2009/05/19/security-development-lifecycle-template-your-next-step-to-secure-development' rel='bookmark' title='Permanent Link: Security Development Lifecycle Template &#8211; Your next step to &#8220;Secure Development&#8221;'>Security Development Lifecycle Template &#8211; Your next step to &#8220;Secure Development&#8221;</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/22/want-to-introduce-the-security-development-lifecycle-play-a-game' rel='bookmark' title='Permanent Link: Want to introduce the Security Development Lifecycle? Play a Game'>Want to introduce the Security Development Lifecycle? Play a Game</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/18/the-impact-of-the-security-development-lifecycle' rel='bookmark' title='Permanent Link: The Impact of the Security Development Lifecycle'>The Impact of the Security Development Lifecycle</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/08/security-development-lifecycle-website/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why it pays to be secure &#8211; Chapter 5 &#8211; I need tools!</title>
		<link>http://www.halbheer.info/security/2010/03/07/why-it-pays-to-be-secure-chapter-5-i-need-tools</link>
		<comments>http://www.halbheer.info/security/2010/03/07/why-it-pays-to-be-secure-chapter-5-i-need-tools#comments</comments>
		<pubDate>Sat, 06 Mar 2010 23:23:56 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Standardization]]></category>
		<category><![CDATA[Tool]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/03/07/why-it-pays-to-be-secure-chapter-5-i-need-tools</guid>
		<description><![CDATA[Our EMEA Security Program Manager, Henk van Roest, started this series internally and with his consent I am publishing it here in my blog as I think it contains a lot of great information for you to use. So far, &#8230; <a href="http://www.halbheer.info/security/2010/03/07/why-it-pays-to-be-secure-chapter-5-i-need-tools">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2009/08/27/why-it-pays-to-be-secure-chapter-1-data-breaches' rel='bookmark' title='Permanent Link: Why it pays to be secure &#8211; Chapter 1 &#8211; Data Breaches'>Why it pays to be secure &#8211; Chapter 1 &#8211; Data Breaches</a></li>
<li><a href='http://www.halbheer.info/security/2009/11/13/why-it-pays-to-be-secure-chapter-4-i-want-to-learn' rel='bookmark' title='Permanent Link: Why it pays to be secure &#8211; Chapter 4 &#8211; I want to learn!'>Why it pays to be secure &#8211; Chapter 4 &#8211; I want to learn!</a></li>
<li><a href='http://www.halbheer.info/security/2009/10/18/why-it-pays-to-be-secure-%e2%80%93-chapter-3-%e2%80%93-but-how-do-i' rel='bookmark' title='Permanent Link: Why it pays to be secure – Chapter 3 – But how do I?'>Why it pays to be secure – Chapter 3 – But how do I?</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F03%252F07%252Fwhy-it-pays-to-be-secure-chapter-5-i-need-tools%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Why%20it%20pays%20to%20be%20secure%20%26ndash%3B%20Chapter%205%20%26ndash%3B%20I%20need%20tools%21%22%20%7D);"></div>
<p>Our EMEA Security Program Manager, Henk van Roest, started this series internally and with his consent I am publishing it here in my blog as I think it contains a lot of great information for you to use.</p>
<hr />
<p>So far, in the first 4 chapters, we have addressed the usual excuses for not Managing Your IT Environment and Security Updates:</p>
<ol>
<li>Security is not worth it, nothing ever happens and if it does it will be “no big deal” </li>
<li>I installed the Microsoft updates, but my network was still compromised </li>
<li>OK now I understand why Security is important but no idea how I start </li>
<li>I now know what I want to do, I just don’t know how, I need training </li>
</ol>
<p>Here we address the need for automation, cost reduction and standardization, Microsoft has literally hundreds of tools to help management assess risk and administrators implement security updates and policies.</p>
<p><strong>Security Update Management Tools:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#EPC">http://technet.microsoft.com/en-gb/security/cc297183.aspx#EPC</a></p>
<p><strong>Security Update Detection Tools:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#EID">http://technet.microsoft.com/en-gb/security/cc297183.aspx#EID</a></p>
<p><strong>Security Risk Assessment Tool:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#EUD">http://technet.microsoft.com/en-gb/security/cc297183.aspx#EUD</a></p>
<p><strong>Lockdown, Auditing, Intrusion Detection, Remediation Tools:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#E2D">http://technet.microsoft.com/en-gb/security/cc297183.aspx#E2D</a></p>
<p><strong>Virus and Malware Protection and Removal Tools &amp; Apps:</strong> <a href="http://technet.microsoft.com/en-gb/security/cc297183.aspx#E1E">http://technet.microsoft.com/en-gb/security/cc297183.aspx#E1E</a></p>
<p><strong><font color="#ff0000">Reduce Your Risk: 10 Security Rules To Live By</font></strong></p>
<p>This is from 2006 but it demonstrates on a conceptual level how the technology can change but the rules remain the same.&#160; <u>Yet again we learn that Security is a Process, not a Product!</u></p>
<p><a href="http://technet.microsoft.com/en-us/magazine/2006.05.reducerisk.aspx">http://technet.microsoft.com/en-us/magazine/2006.05.reducerisk.aspx</a></p>
<hr />Henk and Roger </p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2009/08/27/why-it-pays-to-be-secure-chapter-1-data-breaches' rel='bookmark' title='Permanent Link: Why it pays to be secure &#8211; Chapter 1 &#8211; Data Breaches'>Why it pays to be secure &#8211; Chapter 1 &#8211; Data Breaches</a></li>
<li><a href='http://www.halbheer.info/security/2009/11/13/why-it-pays-to-be-secure-chapter-4-i-want-to-learn' rel='bookmark' title='Permanent Link: Why it pays to be secure &#8211; Chapter 4 &#8211; I want to learn!'>Why it pays to be secure &#8211; Chapter 4 &#8211; I want to learn!</a></li>
<li><a href='http://www.halbheer.info/security/2009/10/18/why-it-pays-to-be-secure-%e2%80%93-chapter-3-%e2%80%93-but-how-do-i' rel='bookmark' title='Permanent Link: Why it pays to be secure – Chapter 3 – But how do I?'>Why it pays to be secure – Chapter 3 – But how do I?</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/03/07/why-it-pays-to-be-secure-chapter-5-i-need-tools/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Making the Management of Security Compliance Easier!</title>
		<link>http://www.halbheer.info/security/2010/02/18/making-the-management-of-security-compliance-easier</link>
		<comments>http://www.halbheer.info/security/2010/02/18/making-the-management-of-security-compliance-easier#comments</comments>
		<pubDate>Thu, 18 Feb 2010 14:26:00 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Processes]]></category>
		<category><![CDATA[Products]]></category>

		<guid isPermaLink="false">/security/archive/2010/02/18/making-the-management-of-security-compliance-easier.aspx</guid>
		<description><![CDATA[As you all know, I have two main pet themes: Risk Management and Compliance Management as I see very often that there is room for improvement when it comes to such processes within our customers. Internally, we often think about &#8230; <a href="http://www.halbheer.info/security/2010/02/18/making-the-management-of-security-compliance-easier">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/04/09/microsoft-security-compliance-manager-now-available' rel='bookmark' title='Permanent Link: Microsoft Security Compliance Manager: Now available!'>Microsoft Security Compliance Manager: Now available!</a></li>
<li><a href='http://www.halbheer.info/security/2008/06/07/security-compliance-management-%e2%80%93-solution-accelerator-available' rel='bookmark' title='Permanent Link: Security Compliance Management – Solution Accelerator Available'>Security Compliance Management – Solution Accelerator Available</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/24/security-compliance-management-toolkit' rel='bookmark' title='Permanent Link: Security Compliance Management Toolkit'>Security Compliance Management Toolkit</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_blue" style="float: right;margin-left: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fwww.halbheer.info%252Fsecurity%252F2010%252F02%252F18%252Fmaking-the-management-of-security-compliance-easier%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Making%20the%20Management%20of%20Security%20Compliance%20Easier%21%22%20%7D);"></div>
<p>As you all know, I have two main pet themes: Risk Management and Compliance Management as I see very often that there is room for improvement when it comes to such processes within our customers. Internally, we often think about how we can make it easier for our customers to manage compliance in their networks.</p>
<p>So, basically it is about helping you to plan, deploy, operate, and manage the baselines in your environment. As you might know, we provide free tools, which we call <a href="http://technet.microsoft.com/en-us/solutionaccelerators/cc835245.aspx" target="_blank">Solution Accelerators</a> since quite a while (if you did not know, shame on us), we provide a Security Compliance Manager in this program as well and have the new version just in Beta now. </p>
<p>Basically the new Security Compliance Manager Solution Accelerator helps you to provides you a few pretty exciting features:</p>
<ul>
<li>Centralized management and baseline portfolio</li>
<li>You can customize the security baselines</li>
<li>You can compare them and export them (e.g. to GPOs)</li>
<li>You can verify and monitor them</li>
</ul>
<p>As a picture shows more than a thousand words, here are a few (cool!!) screenshots of the tool:</p>
<p align="center"><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313647/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="500x303[1]" border="0" alt="500x303[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/500x303[1]_1.png" width="500" height="303"></a> <em>Check for Baselines</em></p>
<p align="center"><em><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313648/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="500x268[1]" border="0" alt="500x268[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/500x268[1]_1.png" width="500" height="268"></a> Compare Baselines</em></p>
<p align="center"><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313649/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="521x480[1]" border="0" alt="521x480[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/521x480[1]_1.png" width="521" height="480"></a> <em>Customize the Baseline</em></p>
<p align="center"><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313650/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="535x480[1]" border="0" alt="535x480[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/535x480[1]_1.png" width="535" height="480"></a> <em>Export it (to enforce it through GPOs)</em></p>
<p align="center"><a href="http://blogs.technet.com/photos/rhalbheer_gallery/images/3313651/original.aspx" target="_blank"><img style="border-bottom:0px;border-left:0px;display:block;float:none;margin-left:auto;border-top:0px;margin-right:auto;border-right:0px" title="500x285[1]" border="0" alt="500x285[1]" src="http://www.halbheer.info/security/Media/WindowsLiveWriter/MakingtheManagementofSecurityComplianceE_8865/500x285[1]_1.png" width="500" height="285"></a><em> Merge different Baselines</em></p>
<p>So, if you are as excited as I am, you should join the Beta program, which is now open. That’s the way to give feedback and influence it now! Therefore my “call to action” for you is:</p>
<ul>
<li><a href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=2682&#038;InvitationID=SUN-TJKJ-7XWY&#038;SiteID=715">Join the Security Compliance Manager Beta.</a> Then tell the development team what you think!</li>
<li>Already a member? <a href="https://connect.microsoft.com/content/content.aspx?ContentID=10295&#038;SiteID=715">Bookmark this link for access to the program page.</a></li>
<li>Help us spread the word—<a href="https://connect.microsoft.com/InvitationUse.aspx?ProgramID=2682&#038;InvitationID=SUN-TJKJ-7XWY&#038;SiteID=715">share the beta invitation link with your friends</a>. </li>
<li>Want to see where it all started? <a href="http://download.microsoft.com/download/B/2/4/B24D224D-054A-46A2-BB30-925B943F00E1/Security Compliance Management Toolkit - All.zip">Download the current version: Security Compliance Management Toolkit.</a></li>
</ul>
<p>The beta will run through March 2010. That means now is the time to join the beta program, take an early look at this tool, and provide the Security Solution Accelerators team with your feedback. </p>
<p>Want the facts straight from the development team? <a href="http://www.youtube.com/user/SATSASC">Check out this series of short videos!</a> Better yet, post your own video response sharing your favorite feature. </p>
<p>Want more information on a specific feature? Interested in speaking with the development team? Please contact <a href="mailto:marney@microsoft.com?subject=SCM blogger's kit inquiry">Michelle Arney</a>. </p>
<p>Have a lot of fun!!</p>
<p>Roger</p>



<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/04/09/microsoft-security-compliance-manager-now-available' rel='bookmark' title='Permanent Link: Microsoft Security Compliance Manager: Now available!'>Microsoft Security Compliance Manager: Now available!</a></li>
<li><a href='http://www.halbheer.info/security/2008/06/07/security-compliance-management-%e2%80%93-solution-accelerator-available' rel='bookmark' title='Permanent Link: Security Compliance Management – Solution Accelerator Available'>Security Compliance Management – Solution Accelerator Available</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/24/security-compliance-management-toolkit' rel='bookmark' title='Permanent Link: Security Compliance Management Toolkit'>Security Compliance Management Toolkit</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/02/18/making-the-management-of-security-compliance-easier/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
