Consumerization of IT–How to address this

Bring Your Own Device or Consumerization of IT are fairly hot themes in a lot of customer organizations. When I talk to customers, there are typically different reactions, once we bring this up. Some tell us, that it is not part of their strategy; some tell us that they plan to do it but that . . . → Read More: Consumerization of IT–How to address this

Security of Car Software

We have seen some of the attacks recently, where people started to attack either the locks or the technology/software in the car itself controlling the chassis etc.

On DarkReading I was just reading this article: Car Systems Reminiscent of Early PCs

One of the things I do not get with cars is the way they . . . → Read More: Security of Car Software

Cloud Security in Office365

You heard about the launch of Office365 recently and I hope you read the blog post on the application of the Cloud Computing Security Considerations to the private. cloud. If not, here it is: Security Considerations in a Private Cloud

To complete the series now, we released an additional paper on how these considerations can . . . → Read More: Cloud Security in Office365

Security Considerations in a Private Cloud

I am talking a lot about Cloud Security. There are a few observations I made:

Even though a lot of people are talking about the Cloud, there is still not too much knowledge about it. What is a private Cloud versus a public Cloud? What is Infrastructure as a Service, Platform as a Service, Application . . . → Read More: Security Considerations in a Private Cloud

Ten Immutable Laws Of Security (Version 2.0)

You might have known the 10 Immutable Laws Of Security since quite a while. It is kind of the “collected non-technical wisdom” of what we see in security respeonse being it in Microsoft Security Response Center or in our Security Product Support.

There is now a version 2, which is still as important as version . . . → Read More: Ten Immutable Laws Of Security (Version 2.0)

Rediscover Microsoft Security Guides

Fairly often I am asked whether the Security Guides for our products still exist. The good news is: They do. The bad news is: They are called differently

The previously stand-alone Microsoft product-specific security guides are now included within the Microsoft Security Compliance Manager (SCM) tool, which I blogged about several times already (e.g. . . . → Read More: Rediscover Microsoft Security Guides

Mutual Authentication in Real Life–Launching a Nuclear Missile…

A few years ago, I wanted to run an exercise with our incident response team in Switzerland. A customer, the government and me came together to develop the goals and the scenario. One of the key question we tried to answer together with the university, which we wanted to use as observers was, whether we . . . → Read More: Mutual Authentication in Real Life–Launching a Nuclear Missile…

Customer Experience: Security Can Improve in the Cloud

Last week, when I was in South Africa, a partner of us pointed me to a very interesting paper by KPMG called Cloud computing: Australian lessons and experiences. What I like is, that a lot of the items I was recently raising, where actually reflected in quotes by customers of Cloud providers as well as by the general findings of the study. The final conclusion is to me that there are a lot of security benefits moving to the Cloud. . . . → Read More: Customer Experience: Security Can Improve in the Cloud

Is a “Zero-Trust” Model the Silver Bullet?

I was reading an interesting article: Forrester Pushes ‘Zero Trust’ Model For Security, where they mainly claim that you should not trust your internal network – something I am asking for since a long time. However, the conclusions Forrester and me are drawing are slightly different. John Kindervag – the person quoted in the article . . . → Read More: Is a “Zero-Trust” Model the Silver Bullet?

Mature your IT and then move to the Cloud

Today, I had the opportunity to talk to a group of partners on Cloud and security. The goal was to make them ready for the Cloud and make them ready to answer the customer’s questions. One block – obviously – was about security and as I look at it (and as I said), this starts . . . → Read More: Mature your IT and then move to the Cloud

Calendar

May 2012
M T W T F S S
« Apr    
 123456
78910111213
14151617181920
21222324252627
28293031