<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Roger Halbheer on Security</title>
	<atom:link href="http://www.halbheer.info/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.halbheer.info/security</link>
	<description>I am the Worldwide Chief Security Advisor for Microsoft and would like to discuss Information Security</description>
	<lastBuildDate>Wed, 28 Jul 2010 16:39:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=7386</generator>
		<item>
		<title>Microsoft and Adobe: Collaboration Against Threats</title>
		<link>http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats</link>
		<comments>http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats#comments</comments>
		<pubDate>Wed, 28 Jul 2010 16:37:49 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Collaboration]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats</guid>
		<description><![CDATA[You know my opinion on collaboration between countries, on public-private-partnerships as well as on collaboration between companies. Since quite a while we run a program called MAPP – the Microsoft Active Protections Program, where we share vulnerability information with security &#8230; <a href="http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/08/06/security-through-collaboration' rel='bookmark' title='Permanent Link: Security through Collaboration'>Security through Collaboration</a></li>
<li><a href='http://www.halbheer.info/security/2009/11/05/international-collaboration-on-policies-for-cybersecurity-and-data-protection' rel='bookmark' title='Permanent Link: International Collaboration on Policies for Cybersecurity and Data Protection'>International Collaboration on Policies for Cybersecurity and Data Protection</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/16/the-importance-of-international-collaborationeven-in-exercises' rel='bookmark' title='Permanent Link: The Importance of International Collaboration&ndash;Even in Exercises'>The Importance of International Collaboration&ndash;Even in Exercises</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>You know my opinion on collaboration between countries, on public-private-partnerships as well as on collaboration between companies.</p>
<p>Since quite a while we run a program called MAPP – the <a href="http://www.microsoft.com/security/msrc/collaboration/mapp.aspx">Microsoft Active Protections Program</a>, where we share vulnerability information with security vendors to help them to get signatures out to our joint customers the moment we release a security update.</p>
<p>Additionally, we know form our data (see the <a href="http://www.microsoft.com/security/about/sir.aspx">Security Intelligence Report</a>) that PDF is the most exploited file format. Therefore I think it is a great signal that Adobe will join the MAPP program to tighten our joint collaboration.</p>
<p>It is another clear signal that we are up for action to address the security challenges in the ecosystem.</p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/08/06/security-through-collaboration' rel='bookmark' title='Permanent Link: Security through Collaboration'>Security through Collaboration</a></li>
<li><a href='http://www.halbheer.info/security/2009/11/05/international-collaboration-on-policies-for-cybersecurity-and-data-protection' rel='bookmark' title='Permanent Link: International Collaboration on Policies for Cybersecurity and Data Protection'>International Collaboration on Policies for Cybersecurity and Data Protection</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/16/the-importance-of-international-collaborationeven-in-exercises' rel='bookmark' title='Permanent Link: The Importance of International Collaboration&ndash;Even in Exercises'>The Importance of International Collaboration&ndash;Even in Exercises</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/28/microsoft-and-adobe-collaboration-against-threats/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to Deal With Vulnerabilities</title>
		<link>http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities</link>
		<comments>http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities#comments</comments>
		<pubDate>Tue, 27 Jul 2010 14:53:53 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Incident Sharing]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities</guid>
		<description><![CDATA[This is always a fairly emotional theme. What is better to protect the ecosystem? Public or private disclosure? Should somebody paying for vulnerabilities or not? Is a vulnerability auction ethical or not? I know that there are numerous views on &#8230; <a href="http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete' rel='bookmark' title='Permanent Link: Vulnerability Disclosure to Compete?'>Vulnerability Disclosure to Compete?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/selling-vulnerabilities-and-ethics' rel='bookmark' title='Permanent Link: Selling Vulnerabilities and Ethics'>Selling Vulnerabilities and Ethics</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885' rel='bookmark' title='Permanent Link: Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)'>Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>This is always a fairly emotional theme. What is better to protect the ecosystem? Public or private disclosure? Should somebody paying for vulnerabilities or not? Is a vulnerability auction ethical or not?</p>
<p>I know that there are numerous views on that and I do not want to debate them here and now. What I just want to do here, is to show Microsoft’s position:</p>
<p>Since a long time Microsoft is working with the researcher community in close collaboration and my understanding is that the researcher community is fairly impressed with what we do, once they get the opportunity to look behind the scenes. One of the outcomes of this outreach is <a href="http://technet.microsoft.com/en-us/security/cc261637.aspx">Bluehat</a> – a Microsoft internal event where the researcher talk to our developers. A very and interesting and insightful get together.</p>
<p>When it comes to handling vulnerabilities, I guess you know <a href="http://www.microsoft.com/security/msrc/default.aspx">Microsoft Security Response Center</a> – the group within Microsoft chartered with handling security vulnerabilities. The policies behind working with the researcher community is two-fold:</p>
<ul>
<li>We are not paying for security vulnerabilities, nor do we intend to do so. There was an article on ZDNet again a few days ago: <a href="http://www.zdnet.com/blog/security/microsoft-no-plans-to-pay-for-security-vulnerabilities/6935">Microsoft: No plans to pay for security vulnerabilities</a></li>
<li>We just recently announced a slight change in strategy towards <a href="http://blogs.technet.com/b/ecostrat/archive/2010/07/22/coordinated-vulnerability-disclosure-bringing-balance-to-the-force.aspx">Coordinated Vulnerability Disclosure</a>, an approach, where the collaboration between the finder and the vendor shall be deepened. </li>
</ul>
<p>For me, the joint goal between researcher and vendors has to be to protect the ecosystem against the criminals. And with ecosystem I mean not only the big enterprises, having security teams which are able to work on detailed vulnerability information but small and medium businesses as well as the consumer like my mom and dad as well. Therefore we think that the point above help to meet the requirements.</p>
<p>What are your thoughts on that?</p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/11/vulnerability-disclosure-to-compete' rel='bookmark' title='Permanent Link: Vulnerability Disclosure to Compete?'>Vulnerability Disclosure to Compete?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/selling-vulnerabilities-and-ethics' rel='bookmark' title='Permanent Link: Selling Vulnerabilities and Ethics'>Selling Vulnerabilities and Ethics</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885' rel='bookmark' title='Permanent Link: Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)'>Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/27/how-to-deal-with-vulnerabilities/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Chief Security Advisor in Sweden: Magnus is back</title>
		<link>http://www.halbheer.info/security/2010/07/27/chief-security-advisor-in-sweden-magnus-is-back</link>
		<comments>http://www.halbheer.info/security/2010/07/27/chief-security-advisor-in-sweden-magnus-is-back#comments</comments>
		<pubDate>Tue, 27 Jul 2010 01:01:50 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Chief Security Advisor]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/27/chief-security-advisor-in-sweden-magnus-is-back</guid>
		<description><![CDATA[After my overall announcement that we grow the community in Off to See the World, and Stuart Aston joining as the CSA in the UK, it is a great pleasure to see Magnus Lindkvist coming back. Magnus was the CSA &#8230; <a href="http://www.halbheer.info/security/2010/07/27/chief-security-advisor-in-sweden-magnus-is-back">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/07/22/a-new-chief-security-advisor-in-the-uk' rel='bookmark' title='Permanent Link: A new Chief Security Advisor in the UK'>A new Chief Security Advisor in the UK</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/infosec-security-community-must-work-together' rel='bookmark' title='Permanent Link: Infosec: Security community must work together'>Infosec: Security community must work together</a></li>
<li><a href='http://www.halbheer.info/security/2008/10/20/%e2%80%9cstacked-against-hacks%e2%80%9d-in-world-finance' rel='bookmark' title='Permanent Link: “Stacked against hacks” in World Finance'>“Stacked against hacks” in World Finance</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>After my overall announcement that we grow the community in <a href="http://www.halbheer.info/security/2010/07/09/off-to-see-the-world">Off to See the World</a>, and <a href="http://www.halbheer.info/security/2010/07/22/a-new-chief-security-advisor-in-the-uk">Stuart Aston joining as the CSA</a> in the UK, it is a great pleasure to see Magnus Lindkvist coming back. Magnus was the CSA in Sweden a few years back and accepted the offer now to come back and re-join the community.</p>
<p>Welcome back Magnus!</p>
<p>Watch out, there are more to come <img style="border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.halbheer.info/security/wp-content/uploads/2010/07/wlEmoticonsmile4.png"></p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/07/22/a-new-chief-security-advisor-in-the-uk' rel='bookmark' title='Permanent Link: A new Chief Security Advisor in the UK'>A new Chief Security Advisor in the UK</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/infosec-security-community-must-work-together' rel='bookmark' title='Permanent Link: Infosec: Security community must work together'>Infosec: Security community must work together</a></li>
<li><a href='http://www.halbheer.info/security/2008/10/20/%e2%80%9cstacked-against-hacks%e2%80%9d-in-world-finance' rel='bookmark' title='Permanent Link: “Stacked against hacks” in World Finance'>“Stacked against hacks” in World Finance</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/27/chief-security-advisor-in-sweden-magnus-is-back/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A new Chief Security Advisor in the UK</title>
		<link>http://www.halbheer.info/security/2010/07/22/a-new-chief-security-advisor-in-the-uk</link>
		<comments>http://www.halbheer.info/security/2010/07/22/a-new-chief-security-advisor-in-the-uk#comments</comments>
		<pubDate>Thu, 22 Jul 2010 06:16:00 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Chief Security Advisor]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/22/a-new-chief-security-advisor-in-the-uk</guid>
		<description><![CDATA[As you have seen in my post Off to see the World, we are hiring Chief Security Advisors all over the place. The first one was announced last week: Stuart Aston was announced to take over the Chief Security Advisor &#8230; <a href="http://www.halbheer.info/security/2010/07/22/a-new-chief-security-advisor-in-the-uk">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/07/27/chief-security-advisor-in-sweden-magnus-is-back' rel='bookmark' title='Permanent Link: Chief Security Advisor in Sweden: Magnus is back'>Chief Security Advisor in Sweden: Magnus is back</a></li>
<li><a href='http://www.halbheer.info/security/about' rel='bookmark' title='Permanent Link: About'>About</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/09/off-to-see-the-world' rel='bookmark' title='Permanent Link: Off to See the World'>Off to See the World</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>As you have seen in my post <a href="http://www.halbheer.info/security/2010/07/09/off-to-see-the-world" target="_blank">Off to see the World</a>, we are hiring Chief Security Advisors all over the place. The first one was announced last week: Stuart Aston was announced to take over the Chief Security Advisor in the UK.</p>
<p>Have a good start!</p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/07/27/chief-security-advisor-in-sweden-magnus-is-back' rel='bookmark' title='Permanent Link: Chief Security Advisor in Sweden: Magnus is back'>Chief Security Advisor in Sweden: Magnus is back</a></li>
<li><a href='http://www.halbheer.info/security/about' rel='bookmark' title='Permanent Link: About'>About</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/09/off-to-see-the-world' rel='bookmark' title='Permanent Link: Off to See the World'>Off to See the World</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/22/a-new-chief-security-advisor-in-the-uk/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Secunia: Apple makes the most vulnerable software in the market today</title>
		<link>http://www.halbheer.info/security/2010/07/21/secunia-apple-makes-the-most-vulnerable-software-in-the-market-today</link>
		<comments>http://www.halbheer.info/security/2010/07/21/secunia-apple-makes-the-most-vulnerable-software-in-the-market-today#comments</comments>
		<pubDate>Wed, 21 Jul 2010 11:10:32 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Industry]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Development Lifecycle]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/21/secunia-apple-makes-the-most-vulnerable-software-in-the-market-today</guid>
		<description><![CDATA[And everybody tells me how secure they are….. So,according to this article Secunia: Apple makes the most vulnerable software in the market today, apple hast most vulns, then Oracle and then us (and then the rest). And you know, the &#8230; <a href="http://www.halbheer.info/security/2010/07/21/secunia-apple-makes-the-most-vulnerable-software-in-the-market-today">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/29/the-growth-of-the-tablet-market' rel='bookmark' title='Permanent Link: The Growth of the Tablet Market'>The Growth of the Tablet Market</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/12/who-needs-a-vulnerable-ipad-if-you-can-get-an-npad' rel='bookmark' title='Permanent Link: Who needs a (vulnerable) iPad if you can get an nPad?'>Who needs a (vulnerable) iPad if you can get an nPad?</a></li>
<li><a href='http://www.halbheer.info/security/2009/06/11/welcome-to-reality-apple-acknowledges-os-x-malware' rel='bookmark' title='Permanent Link: Welcome to reality: Apple Acknowledges OS X Malware'>Welcome to reality: Apple Acknowledges OS X Malware</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>And everybody tells me how secure they are….. So,according to this article <a href="http://www.thewindowsclub.com/secunia-apple-makes-the-most-vulnerable-software-in-the-market-today" target="_blank">Secunia: Apple makes the most vulnerable software in the market today,</a> apple hast most vulns, then Oracle and then us (and then the rest). And you know, the interesting thing is that the comparison is not “apples with apples” as we tend to have somewhat more products out in the market than all of them together (at least this would be my guess)…</p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/29/the-growth-of-the-tablet-market' rel='bookmark' title='Permanent Link: The Growth of the Tablet Market'>The Growth of the Tablet Market</a></li>
<li><a href='http://www.halbheer.info/security/2010/06/12/who-needs-a-vulnerable-ipad-if-you-can-get-an-npad' rel='bookmark' title='Permanent Link: Who needs a (vulnerable) iPad if you can get an nPad?'>Who needs a (vulnerable) iPad if you can get an nPad?</a></li>
<li><a href='http://www.halbheer.info/security/2009/06/11/welcome-to-reality-apple-acknowledges-os-x-malware' rel='bookmark' title='Permanent Link: Welcome to reality: Apple Acknowledges OS X Malware'>Welcome to reality: Apple Acknowledges OS X Malware</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/21/secunia-apple-makes-the-most-vulnerable-software-in-the-market-today/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Doing the right thing on ID management isn&#8217;t enough&#8230;</title>
		<link>http://www.halbheer.info/security/2010/07/16/doing-the-right-thing-on-id-management-isnt-enough</link>
		<comments>http://www.halbheer.info/security/2010/07/16/doing-the-right-thing-on-id-management-isnt-enough#comments</comments>
		<pubDate>Fri, 16 Jul 2010 19:55:17 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/16/doing-the-right-thing-on-id-management-isnt-enough</guid>
		<description><![CDATA[Even though it might be obvious, compliance is not only about protecting data but identities as well – and more. Jon Collins, Freeform Dynamics, whom I value high, wrote a good article: Doing the right thing on ID management isn&#8217;t &#8230; <a href="http://www.halbheer.info/security/2010/07/16/doing-the-right-thing-on-id-management-isnt-enough">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/06/07/security-compliance-management-%e2%80%93-solution-accelerator-available' rel='bookmark' title='Permanent Link: Security Compliance Management – Solution Accelerator Available'>Security Compliance Management – Solution Accelerator Available</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/24/security-compliance-management-toolkit' rel='bookmark' title='Permanent Link: Security Compliance Management Toolkit'>Security Compliance Management Toolkit</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/best-practices-for-microsoft-pki-certificate-management' rel='bookmark' title='Permanent Link: Best Practices for Microsoft PKI &amp; Certificate Management'>Best Practices for Microsoft PKI &amp; Certificate Management</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Even though it might be obvious, compliance is not only about protecting data but identities as well – and more. Jon Collins, Freeform Dynamics, whom I value high, wrote a good article: <a href="http://www.theregister.co.uk/2010/07/16/id_management_compliance/" target="_blank">Doing the right thing on ID management isn&#8217;t enough&#8230;</a> – you should read it!</p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/06/07/security-compliance-management-%e2%80%93-solution-accelerator-available' rel='bookmark' title='Permanent Link: Security Compliance Management – Solution Accelerator Available'>Security Compliance Management – Solution Accelerator Available</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/24/security-compliance-management-toolkit' rel='bookmark' title='Permanent Link: Security Compliance Management Toolkit'>Security Compliance Management Toolkit</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/20/best-practices-for-microsoft-pki-certificate-management' rel='bookmark' title='Permanent Link: Best Practices for Microsoft PKI &amp; Certificate Management'>Best Practices for Microsoft PKI &amp; Certificate Management</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/16/doing-the-right-thing-on-id-management-isnt-enough/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US Cybersecurity Research!</title>
		<link>http://www.halbheer.info/security/2010/07/15/us-cybersecurity-research</link>
		<comments>http://www.halbheer.info/security/2010/07/15/us-cybersecurity-research#comments</comments>
		<pubDate>Thu, 15 Jul 2010 20:22:28 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Research]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/14/us-cybersecurity-research</guid>
		<description><![CDATA[The Department of Homeland Security published a report on A Roadmap for Cybersecurity Research, I was definitely impressed! All the themes, which are important to me are in their list : Scalable trustworthy systems (including system architectures and requisite development &#8230; <a href="http://www.halbheer.info/security/2010/07/15/us-cybersecurity-research">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/26/researcher-at-microsoft-research-wins-acm-award-for-privacy-protection' rel='bookmark' title='Permanent Link: Researcher at Microsoft Research wins ACM award for Privacy Protection'>Researcher at Microsoft Research wins ACM award for Privacy Protection</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/22/is-security-research-ethical' rel='bookmark' title='Permanent Link: Is Security Research Ethical?'>Is Security Research Ethical?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/21/analysis-of-the-estonian-attacks' rel='bookmark' title='Permanent Link: Analysis of the Estonian Attacks'>Analysis of the Estonian Attacks</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>The Department of Homeland Security published a report on <a href="http://www.cyber.st.dhs.gov/docs/DHS-Cybersecurity-Roadmap.pdf" target="_blank">A Roadmap for Cybersecurity Research</a>, I was definitely impressed!</p>
<p>All the themes, which are important to me are in their list :</p>
<ol>
<li>Scalable trustworthy systems (including system architectures and requisite development methodology)</li>
<li>Enterprise-level metrics (including measures of overall system trustworthiness)</li>
<li>System evaluation life cycle (including approaches for sufficient assurance)</li>
<li>Combating insider threats</li>
<li>Combating malware and botnets</li>
<li>Global-scale identity management</li>
<li>Survivability of time-critical systems</li>
<li>Situational understanding and attack attribution</li>
<li>Provenance (relating to information, systems, and hardware)</li>
<li>Privacy-aware security</li>
<li>Usable security</li>
</ol>
<p>It is great to see that this goes in the right direction! The key will be, when the research will deliver results.</p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/05/26/researcher-at-microsoft-research-wins-acm-award-for-privacy-protection' rel='bookmark' title='Permanent Link: Researcher at Microsoft Research wins ACM award for Privacy Protection'>Researcher at Microsoft Research wins ACM award for Privacy Protection</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/22/is-security-research-ethical' rel='bookmark' title='Permanent Link: Is Security Research Ethical?'>Is Security Research Ethical?</a></li>
<li><a href='http://www.halbheer.info/security/2008/05/21/analysis-of-the-estonian-attacks' rel='bookmark' title='Permanent Link: Analysis of the Estonian Attacks'>Analysis of the Estonian Attacks</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/15/us-cybersecurity-research/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blocking Social Networks? Think Again&#8230;</title>
		<link>http://www.halbheer.info/security/2010/07/14/blocking-social-networks-think-again</link>
		<comments>http://www.halbheer.info/security/2010/07/14/blocking-social-networks-think-again#comments</comments>
		<pubDate>Wed, 14 Jul 2010 20:13:20 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Industry]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/14/blocking-social-networks-think-again</guid>
		<description><![CDATA[You know that I am not a big fan of blocking social networks within enterprises for different reasons. I just read an article on this subject based on a study by Trend Micro. One of the conclusions in the article &#8230; <a href="http://www.halbheer.info/security/2010/07/14/blocking-social-networks-think-again">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/11/09/safe-social-networking' rel='bookmark' title='Permanent Link: Safe Social Networking'>Safe Social Networking</a></li>
<li><a href='http://www.halbheer.info/security/2010/04/14/banning-social-media-a-good-idea' rel='bookmark' title='Permanent Link: Banning Social Media &ndash; a good idea?'>Banning Social Media &ndash; a good idea?</a></li>
<li><a href='http://www.halbheer.info/security/2010/05/12/the-khobe-8-0-earthquake-whats-behind-it' rel='bookmark' title='Permanent Link: The &ldquo;KHOBE &ndash; 8.0 earthquake&rdquo; &ndash; What&rsquo;s behind it'>The &ldquo;KHOBE &ndash; 8.0 earthquake&rdquo; &ndash; What&rsquo;s behind it</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>You know that I am not a big fan of blocking social networks within enterprises for different reasons. I just read an article on this subject based on a study by Trend Micro. One of the conclusions in the article is:</p>
<p><em>Trying to just prevent users accessing social networks from work could potentially increase the risk to an organization as users look for ways around computer security possibly increasing the chance of exposure to security threats.</em> </p>
<p>False sense of security…</p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2008/11/09/safe-social-networking' rel='bookmark' title='Permanent Link: Safe Social Networking'>Safe Social Networking</a></li>
<li><a href='http://www.halbheer.info/security/2010/04/14/banning-social-media-a-good-idea' rel='bookmark' title='Permanent Link: Banning Social Media &ndash; a good idea?'>Banning Social Media &ndash; a good idea?</a></li>
<li><a href='http://www.halbheer.info/security/2010/05/12/the-khobe-8-0-earthquake-whats-behind-it' rel='bookmark' title='Permanent Link: The &ldquo;KHOBE &ndash; 8.0 earthquake&rdquo; &ndash; What&rsquo;s behind it'>The &ldquo;KHOBE &ndash; 8.0 earthquake&rdquo; &ndash; What&rsquo;s behind it</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/14/blocking-social-networks-think-again/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Support for Windows XP SP2 ends today!</title>
		<link>http://www.halbheer.info/security/2010/07/13/support-for-windows-xp-sp2-ends-today</link>
		<comments>http://www.halbheer.info/security/2010/07/13/support-for-windows-xp-sp2-ends-today#comments</comments>
		<pubDate>Tue, 13 Jul 2010 08:49:25 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Lifecycle]]></category>
		<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Updates]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/13/support-for-windows-xp-sp2-ends-today</guid>
		<description><![CDATA[I just wanted to remind you: The support for Windows XP SP2 ends today. I hope that this does not catch you by surprise. If you need all the information about which kind of support ends when for which product, &#8230; <a href="http://www.halbheer.info/security/2010/07/13/support-for-windows-xp-sp2-ends-today">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/18/end-of-support-for-windows-2000-and-windows-xp-sp2' rel='bookmark' title='Permanent Link: End of Support for Windows 2000 and Windows XP SP2'>End of Support for Windows 2000 and Windows XP SP2</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/27/pre-warning-windows-server-2003-sp1-out-of-support-in-april' rel='bookmark' title='Permanent Link: Pre-warning: Windows Server 2003 SP1 Out of Support in April'>Pre-warning: Windows Server 2003 SP1 Out of Support in April</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885' rel='bookmark' title='Permanent Link: Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)'>Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I just wanted to remind you: The support for Windows XP SP2 ends today. I hope that this does not catch you by surprise. If you need all the information about which kind of support ends when for which product, please consult out <a href="http://www.microsoft.com/lifecycle" target="_blank">Lifecycle</a> page. If you have a Premier Support contract with us, your Technical Account Manager should inform you as well.</p>
<p>But what does that really mean? You can find this information on the Windows website: <a href="http://windows.microsoft.com/en-us/windows/help/what-does-end-of-support-mean" target="_blank">What does it mean if my version of Windows is no longer supported?</a></p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/2010/06/18/end-of-support-for-windows-2000-and-windows-xp-sp2' rel='bookmark' title='Permanent Link: End of Support for Windows 2000 and Windows XP SP2'>End of Support for Windows 2000 and Windows XP SP2</a></li>
<li><a href='http://www.halbheer.info/security/2009/02/27/pre-warning-windows-server-2003-sp1-out-of-support-in-april' rel='bookmark' title='Permanent Link: Pre-warning: Windows Server 2003 SP1 Out of Support in April'>Pre-warning: Windows Server 2003 SP1 Out of Support in April</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/02/attacks-on-the-windows-help-and-support-center-vulnerability-cve-2010-1885' rel='bookmark' title='Permanent Link: Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)'>Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/13/support-for-windows-xp-sp2-ends-today/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Off to See the World</title>
		<link>http://www.halbheer.info/security/2010/07/09/off-to-see-the-world</link>
		<comments>http://www.halbheer.info/security/2010/07/09/off-to-see-the-world#comments</comments>
		<pubDate>Fri, 09 Jul 2010 11:06:53 +0000</pubDate>
		<dc:creator>Roger</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.halbheer.info/security/2010/07/09/off-to-see-the-world</guid>
		<description><![CDATA[If you follow my blog you saw recently that there are two themes constantly popping up: One is everything about a government’s Cybersecurity Agenda (or the lack thereof) and the second one is the Cloud. Let me briefly line them &#8230; <a href="http://www.halbheer.info/security/2010/07/09/off-to-see-the-world">Continue reading <span class="meta-nav">&#8594;</span></a>


Related posts:<ol><li><a href='http://www.halbheer.info/security/about' rel='bookmark' title='Permanent Link: About'>About</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/11/insider-threat-of-cloud-computing' rel='bookmark' title='Permanent Link: Insider Threat of Cloud Computing'>Insider Threat of Cloud Computing</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/06/cloud-computing-benefits-and-risks-of-moving-federal-it-into-the-cloud' rel='bookmark' title='Permanent Link: Cloud Computing: Benefits and Risks of Moving Federal IT into the Cloud'>Cloud Computing: Benefits and Risks of Moving Federal IT into the Cloud</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>If you follow my blog you saw recently that there are two themes constantly popping up: One is everything about a government’s Cybersecurity Agenda (or the lack thereof) and the second one is the Cloud.</p>
<p>Let me briefly line them out: When I talk to governments I often feel that there is a lack of internal coordination when Cybersecurity is addressed. No too many people in governments are trying to get a holistic view on their Cybersecurity agenda and the sequence things should be addressed. I am convinced that an effective program or agenda will drive the growth of an economy as there will be increased trust in the respective country. If I may give you an example of what I mean: I am often asked whether governments could get more intelligence from us. Therefore we recently launched a program called <a href="http://www.microsoft.com/industry/publicsector/government/programs/scpabout.mspx#EJC">DISP (Defensive Intelligence Sharing Program)</a> where we share vulnerability information with governments. This information is only useful to the government if they can do something with it like if they have a Critical Infrastructure Protection program in place where they have the technical people understanding the information, being able to aggregate it to the right level and distribute it to the critical infrastructure provider in due time.</p>
<p>The Cloud is the other big theme. You know that I am convinced that there is too much fuzz out there and not enough guidance. Therefore we published our <a href="http://go.microsoft.com/?linkid=9708479">Cloud Security Considerations</a> paper to elevate the discussion and give a framework which works for high-level people. The framework has been very effective and I used it often with customers so far. However, to me there is a huge necessity to work closer with customers and governments on a very senior level on how to approach those challenges and what is needed to enable the customer to move to the cloud – from a technical, regulatory but from an emotional perspective as well.</p>
<p>All these points, made us re-think our strategy around the Chief Security Advisor (CSA) community, where I was responsible for EMEA (yes, <i>was</i> but I am coming back to that). Today we are covering in</p>
<ul>
<li><b>Americas Time Zone</b>: Brazil, LATAM, US </li>
<li><b>Asia Time Zone</b>: APAC, Australia, Korea, Greater China Region, India, Japan </li>
<li><b>EMEA Time Zone</b>: EMEA, Russia, France, Germany, Austria, Finland, the Netherlands, Norway </li>
</ul>
<p>This is simply not enough for the work to be done. Therefore, we decided to significantly invest in Chief Security Advisors around the Globe to get closer to the businesses of our customers and governments and to help to leverage security as an enabler, rather than a disabler. Therefore we will broaden the coverage and end up with the following countries (the underlined countries/regions are the ones we are in the process of hiring or will kick the hiring process off):</p>
<ul>
<li><b>Americas Time Zone</b>: <u>Americas Time Zone Lead</u>, LATAM, <u>Brazil</u> </li>
<li><b>Asia Time Zone:</b> <u>Asia Time Zone Lead</u>, Australia, Korea, Greater China Region, <u>India</u>, Japan </li>
<li><b>EMEA Time Zone: </b><u>EMEA Time Zone Lead</u>, <u>Poland</u>, Russia, France, Germany, <u>UK</u>, Austria, <u>Denmark</u>, Finland, Italy, <u>the Netherlands</u>, Norway, <u>Spain</u>, <u>Sweden</u>, <u>Switzerland</u>, <u>South Africa</u>, <u>Turkey</u> </li>
</ul>
<p>These will be very senior security people being able to work on eye’s level with CxOs, government elites and policy maker – if you think that you suit this high-level description and are interested, get in touch with me and I could link you to the relevant people.</p>
<p>This is a huge investment in time and an investment I am convinced is needed to drive the market and support governments in their initiatives.</p>
<p>Finally, I have the great pleasure to move on – well, partly. <strong><em>I will move away from my EMEA position to take over the worldwide Chief Security Advisor role, being responsible for Microsoft’s global CSA community</em></strong>. This is a great challenge, which I am looking forward to. To remain close to the field and close to the customer’s need, I decided to stay in Switzerland and not to move to the headquarters (well, there are some family reasons as well <img style="border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.halbheer.info/security/wp-content/uploads/2010/07/wlEmoticonsmile3.png" />).</p>
<p>I will continue my blog but will broaden the scope from EMEA to the world.</p>
<p>Roger</p>


<p>Related posts:<ol><li><a href='http://www.halbheer.info/security/about' rel='bookmark' title='Permanent Link: About'>About</a></li>
<li><a href='http://www.halbheer.info/security/2010/03/11/insider-threat-of-cloud-computing' rel='bookmark' title='Permanent Link: Insider Threat of Cloud Computing'>Insider Threat of Cloud Computing</a></li>
<li><a href='http://www.halbheer.info/security/2010/07/06/cloud-computing-benefits-and-risks-of-moving-federal-it-into-the-cloud' rel='bookmark' title='Permanent Link: Cloud Computing: Benefits and Risks of Moving Federal IT into the Cloud'>Cloud Computing: Benefits and Risks of Moving Federal IT into the Cloud</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.info/security/2010/07/09/off-to-see-the-world/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
