Consumerization of IT–How to address this
Bring Your Own Device or Consumerization of IT are fairly hot themes in a lot of customer organizations. When I talk to customers, there are typically different reactions, once we bring this up. Some tell us, that it is not part of their strategy; some tell us that they plan to do it but that they have a hard time figuring out, how to secure such an environment; very, very ...
10 Years of Trustworthy Computing at Microsoft
Before joining Microsoft a little bit more than 10 years ago, I ran a team at PricewarehoureCoopers on e-Business Risk Management – classical security consulting in the Internet bubble time. When I announced that I will leave PwC and join Microsoft, I got interesting reactions (and remember, this was 2001). Mainly they were along two lines: Oh, you are joining a desktop company? ...
10 Reasons to migrate off Windows XP
I would like you to sit back, close your eyes and think about the year 2001. Think about how you used technology back then, how you used the Internet. Now, let’s take it a little bit further back in history and think of the year 2000. Just after we realized that the Year-2000-Problem was handled very well by the industry. How you used technology, how you used the Internet, the ...
Office 365 Becomes First and Only Major Cloud Productivity Service to Comply With Leading EU and U.S. Standards for Data Protection and Security
A long title but this was the title of the official press statement yesterday. Compliance is always a key question in the public cloud space. Therefore it is very important for us that we now achieved three things: Office 365 is compliant with EU Model Clauses, Data Processing Agreements and ISO 27001 among other standards. Office 365 is the first and only major ...
By Roger Halbheer, on January 12th, 2012%
Before joining Microsoft a little bit more than 10 years ago, I ran a team at PricewarehoureCoopers on e-Business Risk Management – classical security consulting in the Internet bubble time. When I announced that I will leave PwC and join Microsoft, I got interesting reactions (and remember, this was 2001). Mainly they were along . . . → Read More: 10 Years of Trustworthy Computing at Microsoft
By Roger Halbheer, on July 28th, 2011% I know, I have been fairly slow in blogging currently but I was fairly busy with a few cool projects (which I will disclose later) and – time flies if you are having fun
Just a quick one:
The MMPC on Facebook and Twitter
The Microsoft Malware Protection Center (MMPC) officially launched its Facebook page . . . → Read More: Microsoft Malware Protection Center on Facebook and Twitter
By Roger Halbheer, on June 16th, 2011% You might have known the 10 Immutable Laws Of Security since quite a while. It is kind of the “collected non-technical wisdom” of what we see in security respeonse being it in Microsoft Security Response Center or in our Security Product Support.
There is now a version 2, which is still as important as version . . . → Read More: Ten Immutable Laws Of Security (Version 2.0)
By Roger Halbheer, on January 24th, 2011% If you evern wondered, what our CISO thinks about security in the Cloud, you should listen to him directly. . . . → Read More: From the Inside: Our CISO on Cloud Security
By Roger Halbheer, on December 9th, 2010% Our Security Research and Defense team published a blog post, which is really interesting to read to understand how to protect Windows Vista and Windows 7: On the effectiveness of DEP and ASLR.
There is a lot of information on how both raise the bar for attackers. These are the key take away:
DEP and . . . → Read More: On the effectiveness of DEP and ASLR
By Roger Halbheer, on November 30th, 2010% A quick one: An interesting download location:
With the SDL Quick Security References (QSR), the Security Development Lifecycle (SDL) team introduces a series of basic guidance papers designed to address common vulnerabilities from the perspective of multiple business roles – business decision maker, architect, developer, and tester/QA. These papers will help you address a critical . . . → Read More: Security Development Lifecycle: Quick References
By Roger Halbheer, on November 19th, 2010% Just a quick one. Our Global Foundation Services organization (the ones who run our datacenters) just published a new whitepaper:
Information Security Management System for Microsoft Cloud Infrastructure This paper describes the Information Security Management System program for Microsoft’s Cloud Infrastructure, as well as some of the processes and benefits realized from operating this model. . . . → Read More: Information Security Management System for Microsoft Cloud Infrastructure
By Roger Halbheer, on November 11th, 2010% If you use Hotmail, you should enable full session SSL in my opinion. Additionally we use SSL for additional services like Skydrive etc. However, there are some caveats. Read the blog post on that:
Hotmail security improves with full-session HTTPS encryption
Roger
By Roger Halbheer, on November 1st, 2010% I know I have been very, very quiet over the last two weeks. The reason was, that the worldwide Chief Security Advisor met at our HQ in Redmond for four days to discuss community related questions as well as the future of certain products. . . . → Read More: Worldwide Chief Security Advisor Meeting
By Roger Halbheer, on September 28th, 2010% Last week, when I was in South Africa, a partner of us pointed me to a very interesting paper by KPMG called Cloud computing: Australian lessons and experiences. What I like is, that a lot of the items I was recently raising, where actually reflected in quotes by customers of Cloud providers as well as by the general findings of the study. The final conclusion is to me that there are a lot of security benefits moving to the Cloud. . . . → Read More: Customer Experience: Security Can Improve in the Cloud
|
|
|