微軟藍灰風格PPT模板精編版_第1頁
微軟藍灰風格PPT模板精編版_第2頁
微軟藍灰風格PPT模板精編版_第3頁
微軟藍灰風格PPT模板精編版_第4頁
微軟藍灰風格PPT模板精編版_第5頁
已閱讀5頁,還剩22頁未讀 繼續免費閱讀

下載本文檔

版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領

文檔簡介

1、Session AgendaFocus on Customer ChallengesMicrosoft Security StrategySecure Windows InitiativeStrategic Technology Protection ProgramTrustworthy ComputingBuilding the secure platform.NET FrameworkWindows .NETSummaryQuestionsTechnology, Process, PeopleWhat are the challenges?Products lack security fe

2、aturesProducts have bugsInsufficient technical standardsDifficult to stay up-to-dateDesign for securityRoles & responsibilitiesVigilanceBusiness continuity plansStay up-to-date with security developmentProblem recognitionSkills shortageHuman errorProcessPeopleTechnologyMicrosoft Security StrategySec

3、ure Windows Initiative“Engineering For Security”Goal: Eliminate Every Security Vulnerability Before The Product ShipsIndustry YardstickSource: Security Focus http:/ Windows InitiativePeoplePeopleTrain, and keep current, every developer, tester, Train, and keep current, every developer, tester, and p

4、rogram manager in the specific techniques of and program manager in the specific techniques of building secure productsbuilding secure productsProcessProcessMake security a critical factor in design, coding and Make security a critical factor in design, coding and testing of every product Microsoft

5、buildstesting of every product Microsoft buildsCross-group design & code reviewsCross-group design & code reviewsSecurity Threat Analysis part of every design specSecurity Threat Analysis part of every design specRed Team testing and code reviewsRed Team testing and code reviewsFocus not confined to

6、 buffer overrunsFocus not confined to buffer overrunsSecurity bug feedback loop & code sign-off requirements Security bug feedback loop & code sign-off requirements External reviews and testing by consultants and publicExternal reviews and testing by consultants and publicTechnologyTechnologyBuild t

7、ools to automate everything possible in the Build tools to automate everything possible in the quest to code the most secure productsquest to code the most secure productsPrefix and Prefast for buffer overrun detectionPrefix and Prefast for buffer overrun detectionUpdated as new vulnerabilities foun

8、dUpdated as new vulnerabilities foundVisual C+ 7.0 compiler improvementsVisual C+ 7.0 compiler improvementsDomain-specific tools (i.e. RPC security stress)Domain-specific tools (i.e. RPC security stress)Secure Windows InitiativeExternal Security ReviewFIPS 140-1 evaluation of Cryptographic Service P

9、rovider (CSP) CompletedGovernment validation of base crypto algorithms in WindowsCommon Criteria evaluation In PreparationEvaluation of Windows source code against International security criteria for evaluating Third party expert review of key componentsSource code licensed to over 80 universities,

10、labs, and government agenciesGoal: Help customers secure their Windows SystemsStrategic TechnologyProtection ProgramStrategic Technology Protection Program - Customers Need Our HelpI didnt know which patches I neededI didnt know where to find the updatesI didnt know which machines to updateWe update

11、d our production servers, but the rogue servers got infectedMore than 50% of the customers affected by Code Red were not patched in time for NimdaSTPP: “Get Secure”Coming - Enterprise Security ToolsMicrosoft Baseline Security AnalyzerSMS security patch rollout toolWindows Update Auto-update clientNo

12、w - Microsoft Security ToolkitServer oriented security resources.New server security tools and updates, Windows Update bootstrap client for Windows 2000Now - Security Assessment Program OfferingAvailable immediately through MCS/PSSNow - Free Virus Support HotlineContact your local PSS officeGet Secu

13、reMicrosoft Security ToolkitGets Windows NT and 2000 systems to secure baseline, even disconnected netAutomates server updatesOne-button wizard and SMS ScriptsUpdates and Patches Includes all Service Packs and critical OS and IIS patches through 10/15HFNetchk: patch level verifierIIS Lockdown & URLS

14、canSTPP: “Stay Secure”Ongoing - Enhanced Product SecurityProvide greater security enhancements in the releases of all new products, including theWindows .NET Server family Spring 2002 - Federated Corporate Windows Update ProgramAllows enterprise to host and selectWindows Update contentSpring 2002 -

15、Windows 2000 Service Pack (SP3)Provide ability to install SP3 + security rollupwith a single rebootJan. 2002 - Windows 2000 Security Rollup PatchesBundle all security fixes in single patchesReduces reboots and administrator burdenCorporate Update Server SolutionAutomatic Update (AU) clientAutomatica

16、lly download and install critical updatesSecurity patches, high impact bug fixes and new drivers when no driver is installed for a deviceChecks Windows Update service or Corporate Update server once a dayNew! Install at schedule time after automatic downloads Administrator control of configuration v

17、ia registry-based policySupport for Windows .NET Server, Windows XP and Windows 2000Update serverCorporate hosted WU server to support download and install of critical updates through AU clientServer synchronizes with the public Windows Update serviceSimple administrative model via IE Updates are no

18、t made available to clients until the administrator approves themRuns on Windows .NET Server and Windows 2000 ServerTrustworthy ComputingGoal: Make devices powered by computers and software as trustworthy as devices powered by electricity. A Trust TaxonomyBuilding the secure platformGoal: Provide IT with a s

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯系上傳者。文件的所有權益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
  • 4. 未經權益所有人同意不得將文件中的內容挪作商業或盈利用途。
  • 5. 人人文庫網僅提供信息存儲空間,僅對用戶上傳內容的表現方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
  • 6. 下載文件中如有侵權或不適當內容,請與我們聯系,我們立即糾正。
  • 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

評論

0/150

提交評論