Microsoft Security Newsletter
Welcome to the Microsoft Security Newsletter - a monthly newsletter for IT professionals and developers bringing security news, guidance, updates, and community resources direct to your inbox. If you have suggestions or comments about the Microsoft Security Newsletter, please send us your feedback. To view an online version of this newsletter, please click here. If you would like to receive less technical security news, guidance and updates, please subscribe to the Microsoft Security for Home Computer Users Newsletter.

Viewpoint
Security Viewpoint   
By John deVadoss, Senior Microsoft Application Development and Platform Marketing; Fred Chong, Microsoft Application Architecture; and Gianpaolo Carraro, Microsoft Service Delivery
Designing a hosted data architecture that reconciles the competing benefits and demands of sharing and isolation isn't a trivial task. Trust, or the lack thereof, is a key factor with respect to the adoption of the Hosted Application and the Software as a Service (SaaS) model. The patterns discussed is this article can help you identify many of the critical questions you will face and help you create the foundation layer of trust that's vital to the success of your hosted application.

Top Stories
Application Security, Inc. and the Ponemon Institute have conducted this inaugural study on database security to document how business and government organizations secure database resources and respond to targeted threats. Find out why, despite organizations’ awareness of these threats, inadequate protection of corporate databases is the norm rather than the exception.
The Malware Removal Starter Kit provides information and recommendations that you can use to effectively address and limit malware that infects computers in your small or midsize organization. The Kit also gives you the ability to discover malware by performing a thorough offline scan of your organization’s computers.
Professional services firms experience challenges around document collaboration and security, both within their own organizations and with client organizations. This white paper describes how infrastructure optimization affects the collaborative and compliance ecosystems of professional services firms. It also outlines scenarios that illustrate typical challenges and benefits that organizations experience, based on optimization levels and their collaboration and business requirements.

Security Guidance
By Devendra Tiwari, Microsoft SQL Server Product Team
User Account Control (UAC), a new feature in Windows Vista that helps administrators manage their use of elevated privileges, affects Microsoft SQL Server in terms of connectivity (SQL Server login) and in limiting access to resources on the administrators’ access control list (ACL). This article discusses the impact of UAC on SQL Server and presents tips on how to run SQL Server applications securely in Windows Vista and Windows Server 2008.
Infrastructure Optimization serves as a gauge for IT organizations and provides a logical roadmap to progress from reactive to proactive IT service management. Use this assessment tool to determine the status of your current core infrastructure. Your results will help you understand where your organization stands today and can help you plan for an IT environment with best-in-class management, security, and efficiency.
This paper covers some of the most important new security features in SQL Server 2005. It tells you how, as an administrator, you can install SQL Server securely and keep it that way even as applications and users make use of the data stored within.
SQL Server 2005 includes a variety of highly precise, configurable security features that can empower administrators to implement defense-in-depth that is optimized for the specific security risks of their environment. Access guidance about password policy, surface-area configuration, credentials, authenticators, and more.
The SQL Server 2005 Database Engine helps you protect data from unauthorized disclosure and tampering. Learn about highly granular authentication, authorization, and validation mechanisms; strong encryption; security context switching and impersonation; and integrated key management.
This white paper covers some of the operational and administrative tasks associated with SQL Server 2005 security and lists best practices and operational and administrative tasks that will result in a more secure SQL Server system.
SQL Server 2005 uses strong encryption to provide the best protection for data, a nearly inviolate barrier to exposure. Explore the encryption features in the core database engine of SQL Server 2005, and learn how they can be used to protect data stored there as well as how to allow user interaction with protected data. Also discussed are the various keys used to protect both data and other keys within a database, and how to get information about encryption objects.
This MSDN article presents recommendations and guidance that will help you develop a secure data access strategy. Topics covered include using Windows authentication from ASP.NET to the database, securing connection strings, storing credentials securely in a database, protecting against SQL injection attacks, and using database roles.
The process of securing Microsoft SQL Server 2005 Analysis Services (SSAS) occurs at multiple levels. Learn how to secure each instance of Analysis Services and its data sources to make sure that only authorized users have read or read/write permissions to selected cubes, dimensions, cells, mining models, and data sources, and to prevent unauthorized users from maliciously compromising sensitive business information.

This Month's Security Bulletins
Critical:
Important:

MVP Update
MVP of the Month: Aloysius Cheang, CISA, CISSP, GCIH   
Aloysius Cheang is the Director of the Technology Practice in PIPC Asia, delivering complex, multidimensional strategic and information security programs for Global 500 organizations across Asia, the United States, and Europe. He specializes in information risk management and the development of information security strategies, frameworks, policies, and controls. Aloysius has led numerous IT security audits, security reviews, and security penetration testing engagements. He has also provided business continuity management and disaster recovery services, and supported clients in computer forensic and investigation. He also contributes extensively to the INFOSEC community and is a founding member and president of SIG^2, the de facto local INFOSEC community in Singapore and an affiliate of (ISC)2.
By Aloysius Cheang, CISA, CISSP, GCIH, Microsoft MVP
In order to reap maximum benefits from any IT investment, the IT infrastructure must be optimized and benchmarked, and its value to business must be quantifiable. Learn how security plays an important role during the optimization process in bringing an IT infrastructure from a highly vulnerable state to an optimized state, in which a practice of continuous process improvements would ensure that the processes in place are mature and quantifiable.

Partners with Expertise in Security Solutions
Quest Software delivers innovative products that help organizations get more performance and productivity from their applications, databases, and infrastructure. Quest products offer comprehensive management and migration capabilities to simplify, automate, and secure your Microsoft infrastructure.
Protegrity is a leader in enterprise-wide data security management solutions. Protegrity’s Defiance Suite focuses on the specific data that companies around the globe need to protect, and protects it at the application, storage, file, and database level - points where data is accumulated and where most organizations are exposed.

Microsoft Product Lifecycle Information
Find information about your particular products on the Microsoft Product Lifecycle Web site.
See a list of supported service packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

Security Events and Training
See how Windows Vista is easier to deploy and less expensive to maintain than earlier version of Windows. Use these online resources to explore the improved deployment, security, management, and productivity that Windows Vista has to offer. Tune in to live webcasts to ask questions; stream or download on-demand webcasts; listen to podcasts on the go; or test-drive Windows Vista in a virtual lab.
Get the tools and information you need to understand how the Microsoft Forefront family of business security products can help you provide greater protection and control over the security of your network infrastructure. Tune in to these free online events to better understand the Forefront products and how they can help you improve your security for the client operating system, application servers, and the network edge.

Upcoming Security Webcasts
Upcoming security webcasts in a dynamic, interactive format.
For IT Professionals
TechNet Webcast: A Technical Overview of Windows Server 2008 Terminal Services (Level 200)
Friday, August 17, 9:30 AM Pacific Time
Blain Barton, IT Pro Evangelist, Microsoft Corporation
TechNet Webcast: Security Features in Windows Vista (Level 200)
Wednesday, August 22, 8:00 AM Pacific Time
Matthew Hester, IT Pro Evangelist, Microsoft Corporation
TechNet Webcast: Remote Infrastructure Improvements in Windows Server 2008 (Level 300)
Wednesday, August 22, 9:30 AM Pacific Time
Russ Humphries, Senior Product Manager, Microsoft Corporation; Andrew Mason, Principal Program Manager Lead, Microsoft Corporation; and Nathan Muggli, Senior Program Manager Lead, Microsoft Corporation
TechNet Webcast: A Technical Overview of Forefront Client Security (Level 200)
Monday, August 27, 1:00 PM Pacific Time
Harold Wong, IT Pro Evangelist, Microsoft Corporation
TechNet Webcast: Protect Your Windows Virtual Environment with System Center Data Protection Manager (Level 200)
Thursday, August 30, 9:30 AM Pacific Time
Jason Buffington, Senior Technical Product Manager, Microsoft Corporation, and Tony Bailey, Senior Product Manager, Microsoft Corporation
TechNet Webcast: Deploying Forefront Client Security (Part 1 of 2) (Level 200)
Wednesday, September 5, 11:30 AM Pacific Time
Blain Barton, IT Pro Evangelist, Microsoft Corporation
TechNet Webcast: Information About Microsoft September Security Bulletins (Level 200)
Wednesday, September 12, 11:00 AM Pacific Time
Christopher Budd, Security Program Manager, Microsoft Corporation, and Mike Reavey, Group Manager MSRC, Microsoft Corporation
For Developers
MSDN Webcast: MSDN geekSpeak: Custom Authentication Providers for SharePoint Server 2007 (Level 200)
Wednesday, August 15, Noon Pacific Time
Glen Gordon, MSDN Developer Evangelist, Microsoft Corporation, and Lynn Langit, MSDN Developer Evangelist, Microsoft Corporation
MSDN Webcast: Windows Communication Foundation Top to Bottom (Part 10 of 15): Security Fundamentals (Level 200)
Friday, August 24, 9:00 AM Pacific Time
Michele Leroux Bustamante, Chief Architect, IDesign Inc.
MSDN Webcast: Windows Communication Foundation Top to Bottom (Part 11 of 15): Federated Security (Level 200)
Monday, August 27, 9:00 AM Pacific Time
Michele Leroux Bustamante, Chief Architect, IDesign Inc.
MSDN Webcast: Windows CardSpace (Level 200)
Friday, August 31, Noon Pacific Time
Glen Gordon, MSDN Developer Evangelist, Microsoft Corporation
Microsoft On-Demand Webcasts
TechNet Webcast: SQL Server 2005 Security (Level 200)
This webcast highlights security concepts that are new to Microsoft SQL Server 2005, such as encryption and user-schema separation, and looks at how SQL Server 2005 breaks security down into several distinct areas. We discuss security from the perspective of the server, the database, and the database objects, and examine some of the different options you can use at each level to help secure your data. We also show you some of the tools you can use to monitor the security of your SQL Server 2005 implementation.
MSDN Webcast: SQL Server 2005: Security for Mere Mortals (Level 300)
Microsoft SQL Server 2005 includes many security enhancements, from data encryption and key management to advanced context impersonation. In this webcast, we walk you through the major improvements in the security space and show you how to get the most out of the security features in SQL Server 2005.

Security Newsletter
Volume 4, No. 8

August 2007
In This Issue:
Viewpoint
Top Stories
Security Guidance
This Month's Security Bulletins
MVP Update
Partners with Expertise in Security Solutions
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Microsoft Security Awareness Toolkit
Guidance, samples, and templates for creating a security-awareness program in your organization.
Learn Security On the Job
Learning Paths for Security - Microsoft Training References and Resources
Upcoming Chats
Windows Server 2008: Management, Security, and Improved Performance for Your Remote Infrastructure
August 28, 10:00 AM Pacific Time
Join us for a Q&A on the new features in Windows Server 2008 that will help you manage and secure your remote infrastructure. We will also cover WAN performance improvements included in the new TCP and SMB protocols. Ask our experts about Windows BitLocker Drive Encryption, improvements in Active Directory, Server Core, the Next Generation TCP stack, and SMB 2.0.
Free In-Person Events
TechNet Events
Security Blogs
Michael Howard RSS
Eric Lippert RSS
Eric Fitzgerald RSS
Steve Lamb RSS
MSRC Blog RSS
ACE Team RSS
Jeff Jones RSS
Windows Vista Security RSS
User Account Control Team RSS
Solution Accelerators - Security & Compliance RSS
Kai Axford RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions 
Open with newsreader
ISA Server
Open with newsreader
Windows 2000: Security
Open with newsreader
Windows XP: Security Administration
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server: Security
Open with newsreader
Other Security Newsgroups
Community Web Sites
IT Pro Security Community
Security Newsgroups
Related Communities
Additional Security Resources
Security Help and Support for IT Professionals
TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Center
MSDN Security Developer Center 
Midsize Business Security Center
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
Subscribe to MSDN
© 2007 Microsoft Corporation. All rights reserved. Microsoft, Forefront, MSDN, SQL Server, Windows, Windows Server, and Windows Vista are trademarks of the Microsoft group of companies. All other trademarks are property of their respective owners.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052

Sign up for other newsletters | Unsubscribe | Update your profile
© 2007 Microsoft Corporation  Terms of Use | Trademarks | Privacy Statement
Microsoft