




版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領
文檔簡介
1、Microsoft Security StrategySteven AdlerProduct ManagerMicrosoft EMEASession AgendaFocus on Customer ChallengesMicrosoft Security StrategySecure Windows InitiativeStrategic Technology Protection ProgramTrustworthy ComputingBuilding the secure platform.NET FrameworkWindows .NETSummaryQuestionsTechnolo
2、gy, Process, PeopleWhat are the challenges?Products lack security featuresProducts have bugsInsufficient technical standardsDifficult to stay up-to-dateDesign for securityRoles & responsibilitiesVigilanceBusiness continuity plansStay up-to-date with security developmentProblem recognitionSkills shor
3、tageHuman errorProcessPeopleTechnologyTrustworthy ComputingStrategic Technology Protection ProgramSecure Windows InitiativeMicrosoft Security StrategySecure Windows Initiative“Engineering For Security”Goal: Eliminate Every Security Vulnerability Before The Product ShipsPeopleProcessTechnologyIndustr
4、y YardstickSource: Security Focus Secure Windows InitiativePeopleTrain, and keep current, every developer, tester, and program manager in the specific techniques of building secure productsProcessMake security a critical factor in design, coding and testing of every product Microsoft buildsCross-gro
5、up design & code reviewsSecurity Threat Analysis part of every design specRed Team testing and code reviewsFocus not confined to buffer overrunsSecurity bug feedback loop & code sign-off requirements External reviews and testing by consultants and publicTechnologyBuild tools to automate everything p
6、ossible in the quest to code the most secure productsPrefix and Prefast for buffer overrun detectionUpdated as new vulnerabilities foundVisual C+ 7.0 compiler improvementsDomain-specific tools (i.e. RPC security stress)Secure Windows InitiativeExternal Security ReviewFIPS 140-1 evaluation of Cryptog
7、raphic Service Provider (CSP) CompletedGovernment validation of base crypto algorithms in WindowsCommon Criteria evaluation In PreparationEvaluation of Windows source code against International security criteria for evaluating Third party expert review of key componentsSource code licensed to over 8
8、0 universities, labs, and government agenciesGoal: Help customers secure their Windows SystemsPeopleProcessTechnologyStrategic TechnologyProtection ProgramStrategic Technology Protection Program - Customers Need Our HelpI didnt know which patches I neededI didnt know where to find the updatesI didnt
9、 know which machines to updateWe updated our production servers, but the rogue servers got infectedMore than 50% of the customers affected by Code Red were not patched in time for NimdaSTPP: “Get Secure”Coming - Enterprise Security ToolsMicrosoft Baseline Security AnalyzerSMS security patch rollout
10、toolWindows Update Auto-update clientNow - Microsoft Security ToolkitServer oriented security resources.New server security tools and updates, Windows Update bootstrap client for Windows 2000Now - Security Assessment Program OfferingAvailable immediately through MCS/PSSNow - Free Virus Support Hotli
11、neContact your local PSS officeGet SecureMicrosoft Security ToolkitGets Windows NT and 2000 systems to secure baseline, even disconnected netAutomates server updatesOne-button wizard and SMS ScriptsUpdates and Patches Includes all Service Packs and critical OS and IIS patches through 10/15HFNetchk:
12、patch level verifierIIS Lockdown & URLScanSTPP: “Stay Secure”Ongoing - Enhanced Product SecurityProvide greater security enhancements in the releases of all new products, including theWindows .NET Server family Spring 2002 - Federated Corporate Windows Update ProgramAllows enterprise to host and sel
13、ectWindows Update contentSpring 2002 - Windows 2000 Service Pack (SP3)Provide ability to install SP3 + security rollupwith a single rebootJan. 2002 - Windows 2000 Security Rollup PatchesBundle all security fixes in single patchesReduces reboots and administrator burdenCorporate Update Server Solutio
14、nAutomatic Update (AU) clientAutomatically download and install critical updatesSecurity patches, high impact bug fixes and new drivers when no driver is installed for a deviceChecks Windows Update service or Corporate Update server once a dayNew! Install at schedule time after automatic downloads A
15、dministrator control of configuration via registry-based policySupport for Windows .NET Server, Windows XP and Windows 2000Update serverCorporate hosted WU server to support download and install of critical updates through AU clientServer synchronizes with the public Windows Update serviceSimple adm
16、inistrative model via IE Updates are not made available to clients until the administrator approves themRuns on Windows .NET Server and Windows 2000 ServerTrustworthy ComputingGoal: Make devices powered by computers and software as trustworthy as devices powered by electricity. A Trust TaxonomyAvail
17、abilityAt advertised levelsSuitabilityFeatures fit function IntegrityAgainst data loss or alterationPrivacyAccess authorized by end-userReputationSystem and provider brandSecurityResists unauthorized accessQualityPerformance criteriaDev PracticesMethods, philosophyOperationsGuidelines and benchmarks
18、Business PracticesBusiness modelPoliciesLaws, regulations, standards, normsIntentManagement assertionsRisksWhat undermines intent, causes liabilityImplementationSteps to deliver intentEvidenceAudit mechanismsGoalsMeansExecutionBuilding the secure platformGoal: Provide IT with a secure, integrated fo
19、undation for managing how users, business, and technologies connect.Infrastructure (PKI, Directory)Security in depthNetwork (IPSec, Wireless, VPN)Device (PDA, Laptops, PCs, Servers)ApplicationManagementFront EndTypical Application ArchitectureUsersBack EndAuthenticationNetwork AccessAuthorizationAud
20、itAlertsFront EndSecure Network AccessUsersBack EndAuthorizationAuthenticationNetwork AccessFirewallVPNWirelessIPSECAuditAlertsFront EndFlexible AuthenticationUsersBack EndBasicHTTP DigestKerberosCertificatesSmartcardsAuthenticationNetwork AccessAuthorizationAuditAlertsFront EndRich Access ControlsUsersBack EndAuthenticationNetwork AccessAuthorizationAuditAlertsAccess Control
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯系上傳者。文件的所有權益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經權益所有人同意不得將文件中的內容挪作商業或盈利用途。
- 5. 人人文庫網僅提供信息存儲空間,僅對用戶上傳內容的表現方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
- 6. 下載文件中如有侵權或不適當內容,請與我們聯系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 2025至2030年中國柞木原木項目投資可行性研究報告
- 2025至2030年中國工業采礦業項目投資可行性研究報告
- 2025至2030年不銹鋼衛生級由任行業深度研究報告
- 2025至2030年CDR音樂刻錄機項目投資價值分析報告
- 組胚世鄂課件消化管(5+3)學習資料
- 2025年烤通脊項目可行性研究報告
- 美育融合發展行動方案
- 25年公司安全管理人員安全培訓考試試題及答案高清版
- 25年公司級安全培訓考試試題及答案【考點梳理】
- 25年公司管理人員安全培訓考試試題【模擬題】
- iso28000-2022供應鏈安全管理手冊程序文件表單一整套
- 養老院敬老院福利醫養機構消防知識培訓科普講座教學課件
- 醫院腎臟病健康宣教
- 【MOOC】化工安全(下)-華東理工大學 中國大學慕課MOOC答案
- 【MOOC】電動力學-同濟大學 中國大學慕課MOOC答案
- 婦科術后腸梗阻病人護理查房
- 介入手術宣教
- 第19課 資本主義國家的新變化 課件-高一下學期統編版(2019)必修中外歷史綱要下
- 論持久戰全文(完整)
- 2022版ISO27001信息安全管理體系基礎培訓課件
- 2023-2024學年廣東省深圳市羅湖區八年級(下)期中英語試卷
評論
0/150
提交評論