Microsoft Security Newsletter
Welcome to the Microsoft Security Newsletter - a monthly newsletter for IT professionals and developers bringing security news, guidance, updates, and community resources direct to your inbox. To view an online version of this newsletter, please click here. If you would like to receive less technical security news, guidance and updates, please subscribe to the Microsoft Security for Home Computer Users Newsletter.

Viewpoint
Security Viewpoint   
By Jeremy Chapman, Senior Product Manager, Windows Vista Deployment
As with any IT service, security considerations should be made in every phase of the desktop deployment project -- from the initial vision and decision to upgrade through every aspect of planning and developing the components that will eventually be deployed to your desktops. This article explores security considerations and deliverables affecting the deployment project as well as the entire PC life cycle.

Top Stories
Join Mark Russinovich and a panel of experts for a discussion on adopting Windows Vista into a desktop infrastructure. Hear from real IT pros that have tackled Windows Vista deployment--all discussing the challenges, workarounds, and tips & tricks they have learned along the way.
Protect your organization from attacks with the Windows Server 2008 Security Guide. You'll get comprehensive security guidance, preconfigured security settings, and automated tools that reduce security policy deployment times by up to 80 percent.
This new solution accelerator offers software and guidance that will help you to deploy a customizable solution built on Microsoft Windows SharePoint Services 3.0 or Microsoft Office SharePoint Server 2007 that teams can use to collaborate easily and more securely with customers, partners, and vendors across the Internet.
Microsoft Forefront Server Security Management Console allows administrators to easily manage Forefront Security for Exchange Server, Forefront Security for SharePoint, and Microsoft Antigen. Download the 120-day trial software and receive valuable resources delivered at strategic intervals throughout the software evaluation period.

Security Guidance
By Dave Field, Technical Program Manager, Studio B Productions, Inc.
Explore three steps that you can take to set an initial security posture for your users when deploying Windows Vista using Microsoft Deployment or Business Desktop Deployment 2007.
Access materials, resources, and tools to help you discover, explore, pilot, and roll out Windows Vista in your organization with the Springboard Series for Windows Vista. Get advice based on early adopter and community feedback, and learn about current challenges and solutions through monthly straight-talk articles.
Microsoft Deployment Toolkit 2008 is the next version of Business Desktop Deployment 2007. The fourth-generation deployment accelerator adds integration with recently released Microsoft deployment technologies to create a single path for image creation and automated installation of desktops and servers.
Microsoft System Center Configuration Manager 2007 must accept data from clients, which introduces the risk that the clients could attack the site, for example by sending malformed inventory or attempting to overload the site systems. Learn about security and privacy information and best practices for client deployment.
Mobile devices present interesting security challenges in your enterprise environment. Learn how you can use Microsoft System Center Configuration Manager 2007 to better manage your mobile devices by enforcing configurations that enhance security such as passwords and certificates.
This guide includes three ways to enhance the security of your server running Windows Server Update Services (WSUS) 3.0: by hardening your WSUS server, by adding authentication between chained WSUS servers in an Active Directory environment, and by implementing the Secure Sockets Layer protocol on WSUS.
For Windows Vista and later versions of the Windows family of operating systems, kernel-mode software must have a digital signature to load on x64-based computer systems. This paper describes how to manage the signing process for kernel-mode code for Windows Vista.

This Month's Security Bulletins
Critical:

MVP Update
MVP of the Month: Dr. Jesper M. Johansson, ISSAP, CISSP, MSCE   
Jesper Johansson is a well-known authority on information security in general and on Windows security in particular. He is currently a principal software security architect, managing programs and projects related to application security, secure software development practices, and security training. Prior to his current role, Dr. Johansson worked on security at Microsoft. He has delivered presentations on information security on five continents, has spoken at most major security events, and has written many articles on security. His most recent book is Windows Vista Security, coauthored with Roger Grimes.
 By Jesper M. Johansson
You've heard about the new Server Manager tool in Windows Server 2008. But the Security Configuration Wizard is still available as well. Find out why you will still want to use the Security Configuration Wizard.

Microsoft Product Lifecycle Information
Find information about your particular products on the Microsoft Product Lifecycle Web site.
See a List of Supported Service Packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

Security Events and Training
Business systems are increasingly interconnected in order to get maximum value from information technology infrastructure and so employees can collaborate efficiently. As a result, messaging and collaboration servers that enable e-mail, document sharing, and instant messaging have become a mission-critical infrastructure component in business environments around the world. Use the resources in this learning path to find out how to collaborate more securely.
Explore key Windows Vista product features, plus deployment, security, management, and productivity with this series of webcasts, podcasts, and virtual labs.

Upcoming Security Webcasts
Monday, April 7, 9:30 AM Pacific Time
Brian Hoskins, Senior Product Manager, Microsoft Corporation
View upcoming security webcasts in a dynamic, interactive format.
For IT Professionals
TechNet Webcast: Deploying Operating Systems with Configuration Manager 2007 (Part 1 of 2) (Level 300)
Friday, March 14, 11:30 AM Pacific Time
John Baker, TechNet Presenter, Microsoft Corporation
TechNet Webcast: What's New with ISA and IAG and a Road Map for the Future of Edge Security (Level 300)
Wednesday, March 19, 11:00 AM Pacific Time
Uri Lichtenfeld, Product Manager, Microsoft Corporation
TechNet Webcast: Deploying Operating Systems with Configuration Manager 2007 (Part 2 of 2) (Level 300)
Friday, March 21, 11:30 AM Pacific Time
John Baker, TechNet Presenter, Microsoft Corporation
Optimizing Your Infrastructure: Windows Vista SP1
Wednesday, March 26, 12:00 PM Eastern Time
Microsoft Exchange Hosted Services: E-Mail Filtering & Archiving
Thursday, March 27, 11:30 AM Eastern Time
TechNet Webcast: 24 Hours of SQL Server 2008: Ensuring Your Data Is Secure with a Trusted Platform (Level 200)
Monday, March 31, 11:30 AM Pacific Time
Bryan Von Axelson, Partner Solutions Advisor, Microsoft Corporation
TechNet Webcast: How to Overcome the Top 10 Mobile Device Security and Management Challenges (Level 200)
Tuesday, April 8, 11:30 AM Pacific Time
Jason Langridge, Enterprise Mobility Solution Specialist, Microsoft Corporation
TechNet Webcast: Information about Microsoft April Security Bulletins (Level 200)
Wednesday, April 9, 11:00 AM Pacific Time
Bill Sisk, Security Response Communications Manager, Microsoft Corporation
Adrian Stone, Lead Security Program Manager, Microsoft Corporation
For Developers
MSDN Webcast Audio: MSDN geekspeak: CardSpace, Why Should You Care, Who's Using It Today, and How? (Level 300)
Available on demand.
Michele Leroux Bustamante, Chief Architect, IDesign, Inc
MSDN Webcast: SharePoint Server 2007 and Authentication (Level 100)
Thursday, March 13, 9:00 AM Pacific Time
Mike Benkovich, MSDN Developer Evangelist, Microsoft Corporation
Microsoft On-Demand Webcasts
Security Series: Core IO Model
Improve the security of your IT infrastructure. Learn how the Microsoft Core Infrastructure Optimization (IO) Model can help you control costs, improve service levels, and increase business agility.
2008 Defense in Depth Security Webcast Series
Join Senior Security Strategist with the Trustworthy Computing Group Kai Axford as he explores each layer of Defense in Depth during this eight-part webcast miniseries in January. Kai will show how to mitigate the new risks in security and may have you rethinking the methods you’re using. He’ll also spend time talking about hot topics of the day.

Security Newsletter
Volume 5, No. 3

March 2008
In This Issue:
Viewpoint
Top Stories
Security Guidance
This Month's Security Bulletins
MVP Update
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Security Awareness Materials
Guidance, samples, and templates for creating a security-awareness program in your organization.
Learn Security On the Job
Learning Paths for Security - Microsoft Training References and Resources
Upcoming Chats
View a listing of upcoming technical chats.
Free In-Person Events
TechNet Events
Security Blogs
Michael Howard RSS
Eric Lippert RSS
Eric Fitzgerald RSS
Steve Lamb RSS
MSRC Blog RSS
ACE Team RSS
Jeff Jones RSS
Windows Vista Security RSS
Solution Accelerators - Security & Compliance RSS
Kai Axford RSS
Security Vulnerability Research & Defense RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions 
Open with newsreader
ISA Server
Open with newsreader
Windows 2000: Security
Open with newsreader
Windows XP: Security Administration
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server: Security
Open with newsreader
Other Security Newsgroups
Community Web Sites
IT Pro Security Community
Security Newsgroups
Related Communities
Additional Security Resources
Security Help and Support for IT Professionals
TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Center
MSDN Security Developer Center 
Midsize Business Security Center
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
Subscribe to MSDN
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Active Directory, Forefront, MSDN, SharePoint, Windows, Windows Server, and Windows Vista are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
One Microsoft Way
Redmond, Washington, USA
98052

Sign up for other newsletters | Unsubscribe | Update your profile
© 2008 Microsoft Corporation  Terms of Use | Trademarks | Privacy Statement
Microsoft