Microsoft Security Newsletter
Welcome to the Microsoft Security Newsletter - a monthly newsletter for IT professionals and developers bringing security news, guidance, updates, and community resources direct to your inbox. To view an online version of this newsletter, please click here. If you would like to receive less technical security news, guidance and updates, please subscribe to the Microsoft Security for Home Computer Users Newsletter.

Viewpoint
Security Viewpoint   
By Steve Riley, Senior Security Strategist, Trustworthy Computing
Have you become a support professional outside of the workplace? Read this article and learn how to discuss security with your family, friends, and neighbors to better help them stay safe and secure online.

Top Stories
Learn how to add, manage, secure, and update Windows Mobile devices like you do Windows-based laptops and PCs. Microsoft System Center Mobile Device Manager 2008 provides robust security features and a comprehensive device management solution that helps safeguard your corporate data, reduce the cost and complexity of mobile deployments, and centralize and simplify Windows Mobile device management.
The technique of island hopping -- penetrating a network through a weak link and then hopping around systems within that network -- has been around for years, but it continues to take on new dimensions. This article discusses the beginning steps of using a USB flash drive to attack a network and why the least privilege approach really matters.

Security Guidance
Your biggest vulnerability is not necessarily your computers. It's your users. See how to educate them.
Microsoft Security at Home provides easy-to-understand guidelines to help people protect their computers, themselves, and their families.
Know a friend or family member with a small business? Help them assess what they know and what they ought to know about protecting their businesses from security risks.
Virus protection is a two-stage process. First, you need to educate your users, and then strengthen your network's security defenses. Review this checklist to see if your employees and systems are covered.
This article discusses what makes a strong password, password strategies to avoid, the importance of keeping passwords secret, and how to create a strong, memorable password in six easy steps.
Use this tool to help you gauge the strength of your password.
The Microsoft Windows Malicious Software Removal Tool checks computers running Windows Vista, Windows XP, Windows 2000, and Windows Server 2003 for infections by specific, prevalent malicious software -- including Blaster, Sasser, and MyDoom. It also helps remove any infection you find. When the detection and removal process is complete, the tool displays a report describing the outcome, including which, if any, malicious software was detected and removed.
Detect computer vulnerabilities with the Microsoft Baseline Security Analyzer, a free tool that you can download and use to scan your stand-alone or networked computers for security vulnerabilities.
Although many companies focus on the security of their internal systems, it's important to examine the external supply chain as well. Here's how to work with business partners to establish a comprehensive security strategy.
Learn how to optimize two key encryption technologies already available to you in Windows XP and Windows Vista: the Encrypting File System (EFS) and Windows BitLocker Drive Encryption.

This Month's Security Bulletins
Critical:
Important:

MVP Update
Security MVP of the Month: Deb Shinder   
Microsoft Enterprise Security MVP Debra Littlejohn Shinder is a technology consultant, trainer, and writer who has authored books about computer operating systems, networking, and security, and served as technical editor, developmental editor, and contributor for more than 25 technology books. She has also published hundreds of articles in TechRepublic, CNET, Windows & .NET Magazine/Windows IT Pro, ComputerWorld and other print and online publications.
By Deb Shinder, Co-owner, TACteam (Trainers, Authors, and Consultants)
In this article, MVP Deb Shinder continues the conversation and reminds IT pros to ensure that friends and family members recognize the importance of securing all devices that connect to their home networks.

Microsoft Product Lifecycle Information
Find information about your particular products on the Microsoft Product Lifecycle Web site.
See a List of Supported Service Packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

Security Events and Training
See how Microsoft Forefront Client Security can help you protect business desktops, laptops, and servers from security threats, such as spyware, rootkits, and viruses with these webcasts, podcasts, and virtual labs. Learn how simplified deployment, management, and analysis features allow Forefront Client Security to integrate easily with your organization's IT infrastructure and help you keep your infrastructure secure.
Use the resources in this learning path to better understand how Windows Server 2008 is the most secure Windows Server ever, helping to protect networks with a hardened security platform. Plus, learn how Windows Server 2008 helps reduce network downtime by enforcing compliance with customized health policies.

Upcoming Security Webcasts
Tune in and learn how you can meet evolving business needs by continuously adapting your IT infrastructure to support new applications and capabilities. See how you can improve the security of your IT infrastructure with Microsoft integrated management and security solutions. During this series, we show you how the Microsoft Core Infrastructure Optimization (IO) Model can help you control costs, improve service levels, and increase business agility. We also explore identity and access management, desktop device and server management, security and networking, and data protection and recovery.
View upcoming security webcasts in a dynamic, interactive format.
For IT Professionals
TechNet Webcast: Forefront Client Security Series: Deploying Forefront Client Security in Large Enterprises (Level 200)
Friday, February 15, 9:30 AM Pacific Time
Ken Stavinoha, Senior Security Consultant, Microsoft Corporation
IT Manager Webcast: Dynamic IT and Security (Part 3 of 5): Network and Edge Protection (Level 100)
Tuesday, February 19, 11:00 AM Pacific Time
Mike Wolfe, Strategic Security Advisor, Microsoft Corporation
TechNet Webcast: Forefront Client Security Series: Troubleshooting Forefront Client Security in Large Enterprises (Level 200)
Friday, February 22, 9:30 AM Pacific Time
Craig Wiand, Security Escalation Engineer, Microsoft Corporation
TechNet Webcast: Windows Network Policy Server Fundamentals (Level 300)
Monday, February 25, 11:30 AM Pacific Time
Blain Barton, IT Pro Evangelist, Microsoft Corporation
IT Manager Webcast: Dynamic IT and Security (Part 4 of 5): Identity and Access (Level 200)
Tuesday, February 26, 11:00 AM Pacific Time
Norm Barber, Strategic Security Advisor, Microsoft Corporation
IT Manager Webcast: Dynamic IT and Security (Part 5 of 5): Data Protection (Level 200)
Tuesday, March 4, 11:00 AM Pacific Time
Steve Haack, Strategic Security Advisor, Microsoft Corporation
TechNet Webcast: Information About Microsoft March Security Bulletins (Level 200)
Wednesday, March 12, 11:00 AM Pacific Time
Bill Sisk, Security Response Communications Manager, Microsoft Corporation
Adrian Stone, Lead Security Program Manager, Microsoft Corporation
For Developers
What’s New in SQL Server 2008 -- Security Enhancements
Wednesday, February 20, 11:00 AM India
L. Srividya, Architect Advisor, Microsoft Corporation
MSDN Webcast: Windows Server 2008 for Embedded Systems (Level 100)
Thursday, February 28, 8:00 AM Pacific Time
Scott Ottaway, Senior Product Manager, Microsoft Corporation
Microsoft On-Demand Webcasts
Microsoft Webcast: Improve and Simplify Mobile Device Security and Management
Securing and managing mobile devices across an enterprise poses many challenges for IT professionals. Learn how the Windows Mobile security and device management solution can help you deliver enterprisewide control, improve secure access to corporate data and line-of-business (LOB) applications, and simplify management of Windows Mobile devices across your business.

Security Newsletter
Volume 5, No. 2

February 2008
In This Issue:
Viewpoint
Top Stories
Security Guidance
This Month's Security Bulletins
MVP Update
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Security Awareness Materials
Guidance, samples, and templates for creating a security-awareness program in your organization.
Learn Security On the Job
Learning Paths for Security - Microsoft Training References and Resources
Upcoming Chats
View a listing of upcoming technical chats.
Free In-Person Events
TechNet Events
Security Blogs
Michael Howard RSS
Eric Lippert RSS
Eric Fitzgerald RSS
Steve Lamb RSS
MSRC Blog RSS
ACE Team RSS
Jeff Jones RSS
Windows Vista Security RSS
Solution Accelerators - Security & Compliance RSS
Kai Axford RSS
Security Vulnerability Research & Defense RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions 
Open with newsreader
ISA Server
Open with newsreader
Windows 2000: Security
Open with newsreader
Windows XP: Security Administration
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server: Security
Open with newsreader
Other Security Newsgroups
Community Web Sites
IT Pro Security Community
Security Newsgroups
Related Communities
Additional Security Resources
Security Help and Support for IT Professionals
TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Center
MSDN Security Developer Center 
Midsize Business Security Center
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
Subscribe to MSDN
© 2008 Microsoft Corporation. All rights reserved. Microsoft, BitLocker, Forefront, SQL Server, Windows, Windows Mobile, Windows Server, and Windows Vista are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
One Microsoft Way
Redmond, Washington, USA
98052

Sign up for other newsletters | Unsubscribe | Update your profile
© 2008 Microsoft Corporation  Terms of Use | Trademarks | Privacy Statement
Microsoft