Microsoft Security Newsletter
Welcome to the Microsoft Security Newsletter - a monthly newsletter for IT professionals and developers bringing security news, guidance, updates, and community resources direct to your inbox. To view an online version of this newsletter, please click here. If you would like to receive less technical security news, guidance and updates, please subscribe to the Microsoft Security for Home Computer Users Newsletter.

Viewpoint
Security Viewpoint   
By John Steer, CISSP, Senior Security Consultant, Microsoft ACE Services
Corporate security policies are a critical part of securing your corporate assets. This article covers the role of the security policy as a driver in the application development lifecycle, and explains why it is important to imbed security processes and policies into the software development process.

Top Stories
Deploy Forefront Client Security in large enterprises with more than 10,000 users with the use of Forefront Client Security Enterprise Manager. This tool allows you to aggregate reporting and management of up to 10 Client Security down-level deployment, allowing you to manage up to 100,000 client computers from a single Client Security console.
System Center Configuration Manager represents a tremendous advance over its well-regarded predecessor, now providing the control necessary to more effectively manage change in today's dynamic IT infrastructures. Manage the full deployment and update lifecycle with streamlined, policy-based automation; with enhanced insight into, and control over, assets and systems compliance; and with optimization for Windows -- particularly Windows Server 2008 and Windows Vista. When you download the 120-day trial software, you're automatically registered to receive valuable resources delivered at strategic intervals throughout the software evaluation period.
Now with support for Exchange Server 2007 SP1 and Windows Server 2008, Forefront Security for Exchange Server SP1 helps provide comprehensive protection for Exchange Server 2007 environments through the integration of multiple industry-leading antivirus scan engines, content filtering, and enhanced manageability. Begin your evaluation today.

Security Guidance
IT administrators can use Group Policy and the Active Directory services infrastructure in Windows Server 2008 to automate one-to-many management of users and computers -- simplifying administrative tasks and reducing IT costs. These resources will help you to efficiently implement security settings, enforce IT policies, and distribute software consistently across a given site, domain, or range of organizational units.
The number of Group Policy settings has increased from approximately 1,800 in Windows Server 2003 Service Pack 1 to approximately 2,500 in Windows Vista and Windows Server 2008. This gives you more than 700 new policies to help you manage desktops, security, and all other aspects of running your network. This document will help you sort through the new and updated features available in Windows Vista, and provides a number of best practices to help you deploy Group Policy.
Learn about key areas of Group Policy through answers to frequently asked questions and links to related information.
USB thumb-disk keys and other removable devices can make your personal life easier but your professional life harder. For improved security, you need a way to control what hardware devices your users are installing on their work systems. Learn how you can use Group Policy to control which devices they can use and which ones they can't.
This section provides technical reference information for the security settings and privacy options in the 2007 Microsoft Office system. Learn what each setting does, the default configuration for a setting, which tool to use to configure a setting, and where to find the setting in the Office Customization Tool (OCT) or the Group Policy Object Editor.
Security Policy settings on Windows Mobile devices are configurable and provide the flexibility to control access to the device. This article contains a concise table that shows how you can use security policies to protect devices.
Security Configuration Wizard (SCW) is an attack surface reduction tool for computers running a member of the Windows Server 2003 family with Service Pack 1 (SP1). SCW guides you through the process of creating a security policy, based on the roles performed by a given server. Learn how you can use SCW, to create a policy , which then can be edited or applied to one or more similarly configured servers while applied policies can be rolled back in order to undo changes that have caused problems.
Security policy is the configurable set of rules that the common language runtime follows when determining the permissions to grant to code. The runtime examines identifiable characteristics of the code, such as the Web site or zone where the code originates, to determine the access that code can have to resources. During execution, the runtime ensures that code accesses only the resources that it has been granted permission to access. This part of the guide explores the .NET Framework security policy model, permission grants, security policy administration, security policy best practices, and much more.
Security is an important consideration when building applications. The common language runtime grants varying levels of trust to code based on certain attributes, called evidence, that the code possesses. When the runtime establishes that code has a certain level of trust, the code can access protected resources appropriate to that level of trust. Learn how to configure security policy using the .NET Framework Configuration Tool (Mscorcfg.msc) and the Code Access Security Policy Tool (Caspol.exe).

This Month's Security Bulletins
Critical:
Important:

MVP Update
By Harry L. Waldron, CPCU, AAI, Microsoft MVP
Good security requires a balance of technological and human behavioral controls. Corporate policies promote the best behavioral standards for users, which can complement technical defense systems. In this month’s MVP Article of the Month, Harry Waldron explores why the overall effectiveness of policies relates directly to how well those policies are communicated, promoted, and evaluated in terms of continuous improvement.

Partners with Expertise in Security Solutions
FullArmor Corporation is a leading provider of enterprise policy management software. FullArmor Endpoint Policy Manager automates the delivery, enforcement, and auditing of critical security policies on mobile, disconnected, and unmanaged endpoint devices, including guest machines with temporary access to the network.
NetIQ is a leading provider of integrated systems and security management solutions that empower IT organizations with the knowledge and ability necessary to assure IT service Customers can use NetIQ Group Policy Administrator to better plan, manage, troubleshoot, and report on Group Policy Objects (GPOs), a key component of Active Directory service. At the same time NetIQ Group Policy Guardian minimizes the risks associated with GPO change management and helps identify and document all authorized and unauthorized Group Policy changes to the live environment.

Microsoft Product Lifecycle Information
Find information about your particular products on the Microsoft Product Lifecycle Web site.
See a List of Supported Service Packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

Security Events and Training
Registration for the 2008 Microsoft Office Visio Conference is closing soon. Don’t miss the opportunity to learn how Visio 2007 can enhance visualization and complement your existing security solutions. Register today to maximize your efficiency and effectiveness with Visio, hear about the updated product roadmap, and make the connections to grow your Visio business.
Register today to join us at this Security Virtual Conference where you can discuss the danger of not having good software development security skills and also learn about concrete actions you can take to help improve your own skills. Security skills can have a very positive effect on your value as a developer and take you to a whole new level when having security discussions with stakeholders in any application development lifecycle.
This 90-minute lab provides hands-on experience with the following security and Policy enforcement functionality in Windows Server 2008. Topics covered include security enhancements in Windows Server 2008 and Network Access Protection (NAP).
Network Access Protection (NAP) is a policy enforcement platform built into Microsoft Windows Vista and Windows Server 2008 that you can use to better protect your private network by enforcing compliance with computer health requirements. These requirements include having a firewall installed and enabled and having the latest operating system updates installed. Use the resources in this learning path to better understand how NAP can improve the overall health compliance of your network. The tools provided will also help you set up NAP so you can create customized policies and limit access for unhealthy devices.

Upcoming Security Webcasts
Being responsible for information security can be a daunting task, so where do you begin? From the design of acceptable use policies to preventing insiders from stealing data, the job can be a challenging one. Join Kai Axford, Senior Security Strategist with the Trustworthy Computing Group, as he explores each layer of Defense in Depth during this eight-part webcast miniseries in January. Kai will show you how to mitigate the new risks in security and may have you rethinking the methods you are using. He will also spend time talking about hot topics of the day.
View upcoming security webcasts in a dynamic, interactive format.
For IT Professionals
TechNet Webcast: 2008 Defense in Depth Security Series (Part 4 of 8): Living on the Edge (Level 200)
Thursday, January 10, 11:30 AM Pacific Time
Kai Axford, Senior Security Strategist, Microsoft Corporation
TechNet Webcast: eDiscovery for E-Mail (Level 200)
Friday, January 11, 11:30 AM Pacific Time
Diane Prescott, Technical Product Manager, Microsoft Corporation, and Aimee Chaille, Lead Product Manager, Microsoft Corporation
TechNet Webcast: 2008 Defense in Depth Security Series (Part 5 of 8): Keeping Your House in Order (Level 200)
Monday, January 14, 11:30 AM Pacific Time
Kai Axford, Senior Security Strategist, Microsoft Corporation
TechNet Webcast: 2008 Defense in Depth Security Series (Part 6 of 8): Save the Box, Save the Network (Level 200)
Thursday, January 15, 11:30 AM Pacific Time
Kai Axford, Senior Security Strategist, Microsoft Corporation
TechNet Webcast: 2008 Defense in Depth Security Series (Part 7 of 8): If You Build It (Securely), They Won't Come (Level 200)
Wednesday, January 16, 11:30 AM Pacific Time
Kai Axford, Senior Security Strategist, Microsoft Corporation
TechNet Webcast: Exchange Server 2007 in Depth (Part 1 of 8): Overview (Level 200)
Wednesday, January 16, 1:00 PM Pacific Time
Chris Avis, TechNet Presenter, Microsoft Corporation
TechNet Webcast: 2008 Defense in Depth Security Series (Part 8 of 8): If a Terabyte Falls in the Middle of the (Active Directory) Forest (Level 200)
Thursday, January 17, 11:30 AM Pacific Time
Kai Axford, Senior Security Strategist, Microsoft Corporation
TechNet Webcast: SharePoint Server 2007 (Part 2 of 6): Securing Data in SharePoint Server 2007 (Level 200)
Monday, January 21, 9:30 AM Pacific Time
Kevin Remde, TechNet Presenter, Microsoft Corporation
TechNet Webcast: Exchange Server 2007 in Depth (Part 5 of 8): Client Access and Web Services (Level 200)
Friday, January 25, 1:00 PM Pacific Time
John Weston, TechNet Presenter, Microsoft Corporation
TechNet Webcast: Exchange Server 2007 in Depth (Part 7 of 8): Key Scenarios, Examples, Demos, and How-to's (Level 300)
Friday, February 1, 1:00 PM Pacific Time
John Weston, TechNet Presenter, Microsoft Corporation
TechNet Webcast: Security Enhancements in SQL Server 2008 (Level 300)
Tuesday, February 5, 11:30 AM Pacific Time
Il-Sung Lee, Program Manager, Microsoft Corporation
TechNet Webcast: Information About Microsoft February Security Bulletins (Level 200)
Wednesday, February 13, 11:00 AM Pacific Time
Bill Sisk, Security Response Communications Manager, Microsoft Corporation, and Adrian Stone, Lead Security Program Manager, Microsoft Corporation
For Developers
MSDN Webcast: Developing Secure Code Using Visual Studio Partner Solutions (Level 100)
Thursday, January 10, 9:00 AM Pacific Time
Terry Clancy, Business Development Manager, Microsoft Corporation
MSDN: Security Virtual Conference for Developers
Tuesday, January 29, Noon Eastern Time
MSDN Webcast: MSDN geekSpeak: Security from a Public, Anonymous Windows SharePoint Services 3.0 Site (Level 300)
Wednesday, January 30, Noon Pacific Time
Jim Wilt, Chief Software Architect, Metrics Reporting, Inc.
Microsoft On-Demand Webcasts
SQL Server 2005 Security for Administrators
In this webcast you learn the principles and methodology of designing SQL Server security. You also learn the benefits of having a security policy in place and the process of creating a security policy. We will also cover aspects of design for SQL Server instance-level, database-level, and object-level security policies.
Ignite Your Coding: Security Essentials for Windows
Gain a solid overview of security concepts and technologies in Windows with this webcast. We will address many different challenges such as access control lists, identity, and security policy.

Security Newsletter
Volume 5, No. 1

January 2008
In This Issue:
Viewpoint
Top Stories
Security Guidance
This Month's Security Bulletins
MVP Update
Partners with Expertise in Security Solutions
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Security Awareness Materials
Guidance, samples, and templates for creating a security-awareness program in your organization.
Learn Security On the Job
Learning Paths for Security - Microsoft Training References and Resources
Upcoming Chats
Free In-Person Events
TechNet Events
Security Blogs
Michael Howard RSS
Eric Lippert RSS
Eric Fitzgerald RSS
Steve Lamb RSS
MSRC Blog RSS
ACE Team RSS
Jeff Jones RSS
Windows Vista Security RSS
Solution Accelerators - Security & Compliance RSS
Kai Axford RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions 
Open with newsreader
ISA Server
Open with newsreader
Windows 2000: Security
Open with newsreader
Windows XP: Security Administration
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server: Security
Open with newsreader
Other Security Newsgroups
Community Web Sites
IT Pro Security Community
Security Newsgroups
Related Communities
Additional Security Resources
Security Help and Support for IT Professionals
TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Center
MSDN Security Developer Center 
Midsize Business Security Center
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
Subscribe to MSDN
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Active Directory, Forefront, MSDN, SharePoint, SQL Server, Visual Studio, Windows, Windows Server, and Windows Vista are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052

Sign up for other newsletters | Unsubscribe | Update your profile
© 2008 Microsoft Corporation  Terms of Use | Trademarks | Privacy Statement
Microsoft