Microsoft Windows Vista SIRT Roundtable Discussion January 12, 2007 Harvard Townsend Interim University IT Security Officer 532-2985 College.

Slides:



Advertisements
Similar presentations
Microsoft ® Official Course First Look Clinic Overview of Windows 8 By Ragowo Riantory, S.Kom, MCP.
Advertisements

Windows XP Tutorial Securing Windows. Introduction This presentation will guide you through basic security principles for Windows XP.
Avoid data leakage, espionage, sabotage and other reputation and business risks without losing employee performance and mobility.
Configuring Windows to run Dr.Web scanner remotely.
Securing. Agenda  Hard Drive Encryption  User Account Permissions  Root Level Access  Firewall Protection  Malware Protection.
Chapter 10 Securing Windows Server 2008 MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration.
Configuring Windows Vista Security Lesson 8. Skills Matrix Technology SkillObjective DomainObjective # Setting Up Users Configure and troubleshoot parental.
Defense-in-Depth Against Malicious Software Jeff Alexander IT Pro Evangelist Microsoft Australia
Configuring Windows Vista Security Chapter 3. IE7 Pop-up Blocker Pop-up Blocker prevents annoying and sometimes unsafe pop-ups from web sites Can block.
Windows Security Tech Talk 9/25/07. What is a virus?  A computer program designed to self replicate without permission from the end user  The program.
Trend Micro Round Table May 19, Agenda Introduction – why switch? Timeline for implementation Related policies Trend Micro product descriptions.
Optimizing Client Security by Using Windows Vista.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
Kaspersky Open Space Security: Release 2 World-class security solution for your business.
Customized solutions. Keep It Secure Contents  Protection objectives  Endpoint and server software  Protection.
STANFORD UNIVERSITY INFORMATION TECHNOLOGY SERVICES Windows Encryption File System (EFS) Tech Briefing July 18 th 2008
Configuring Windows Vista Security Lesson 8. Skills Matrix Technology SkillObjective DomainObjective # Setting Up Users Configure and troubleshoot parental.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
Securing Windows 7 Lesson 10. Objectives Understand authentication and authorization Configure password policies Secure Windows 7 using the Action Center.
MCTS Guide to Microsoft Windows 7 Chapter 7 Windows 7 Security Features.
Chapter 7 Microsoft Windows XP. Windows XP Versions XP Home XP Home XP Professional XP Professional XP Professional 64-Bit XP Professional 64-Bit XP Media.
© 2012 The McGraw-Hill Companies, Inc. All rights reserved. 1 Third Edition Chapter 6 Today’s Windows Windows Vista and Windows 7 McGraw-Hill.
Tutorial 11 Installing, Updating, and Configuring Software
Introducing, Installing, and Upgrading Windows 7 Lesson 7.
Networking Security Chapter 8 powered by dj. Chapter Objectives  Explain various security threats  Monitor security in Windows Vista  Explain basic.
Microsoft ® Official Course Module 8 Securing Windows 8 Desktops.
1. Windows Vista Enterprise And Mid-Market User Scenarios 2. Customer Profiling And Segmentation Tools 3. Windows Vista Business Value And Infrastructure.
© 2012 The McGraw-Hill Companies, Inc. All rights reserved. 1 Third Edition Chapter 6 Today’s Windows Windows Vista and Windows 7 McGraw-Hill.
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
Windows Vista Security Center Chapter 5(WV): Protecting Your Computer 9/17/20151Instructor: Shilpa Phanse.
Week #7 Objectives: Secure Windows 7 Desktop
Windows 2003 Overview Lecture 1. Windows Networking Evolution Windows for Workgroups – peer-to-peer networking built into the OS Windows NT – separate.
COMPREHENSIVE Windows Tutorial 5 Protecting Your Computer.
®® Microsoft Windows 7 Windows Tutorial 5 Protecting Your Computer.
Troubleshooting Windows Vista Security Chapter 4.
MCTS Guide to Microsoft Windows Vista Chapter 7 Windows Vista Security Features.
Module 14: Configuring Server Security Compliance
Windows XP Professional Features ©Richard L. Goldman February 5, 2003.
1 © 2004, Cisco Systems, Inc. All rights reserved. CISCO CONFIDENTIAL Support for Vista Unity 5.0(1)
Windows Vista Inside Out Ch 10: Ch 10: Security Essentials Last modified
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
Chapter Six Maintaining a Computer Part II: Installing, Repairing, and Removing Applications.
MCTS GUIDE TO MICROSOFT WINDOWS 7 Chapter 7 Windows 7 Security Features.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
NetTech Solutions Supporting Users and Troubleshooting Desktop Applications on Microsoft Windows XP Instructor Richard Fredrickson.
Managing Applications, Services, Folders, and Libraries Lesson 4.
May 30 th – 31 st, 2007 Chateau Laurier Ottawa. Getting it Done: Understanding the Security Features of Windows Vista Kai Axford, CISSP, MCSE-Security.
May 25 – June 15, Technical Overview Bruce Cowper IT Pro Advisor Microsoft Canada Damir Bersinic IT Pro Advisor Microsoft.
© 2012 The McGraw-Hill Companies, Inc. All rights reserved. 1 Third Edition Chapter 6 Today’s Windows Windows Vista and Windows 7 McGraw-Hill.
MCTS GUIDE TO MICROSOFT WINDOWS 7 Chapter 7 Windows 7 Security Features.
Windows Administration How to protect your computer.
Internet Explorer 7 Updated Advice for the NHS 04 February 2008 Version 1.3.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Basic Security Networking for Home and Small Businesses – Chapter 8.
John Samuels October, Why Now?  Vista Problems  New Features  >4GB Memory Support  Experience.
Securing a Host Computer BY STEPHEN GOSNER. Definition of a Host  Host  In networking, a host is any device that has an IP address.  Hosts include.
Get2Modern A plan for Windows XP & Office 2003 EOS migration in SMB Microsoft Confidential. NDA required.
Introducing Windows Vista Lesson 1. Skills Matrix Technology SkillObjective DomainObjective # Understanding Windows Vista System Requirements Identify.
Windows Vista Configuration MCTS : NTFS Security Features and File Sharing.
Chapter 1 Objectives Understand the History of Windows Over the Last 20-Plus Years. Compare and Contrast the Available Editions of Windows 7. Understand.
ITMT Windows 7 Configuration Chapter 10 – Securing Windows 7
Customer Guide to Limited-Time Offer
4 Windows 7.
Lesson #8 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 8 Configuring Applications and Internet Explorer.
Implementing Client Security on Windows 2000 and Windows XP Level 150
Securing Windows 7 Lesson 10.
Preparing for the Windows 8. 1 MCSA Module 6: Securing Windows 8
Presentation transcript:

Microsoft Windows Vista SIRT Roundtable Discussion January 12, 2007 Harvard Townsend Interim University IT Security Officer College Court 114

Jan. 12, 2007Windows Vista2 Agenda Vista versions – their features and availability Security features Trend Micro and Vista SIRT recommendations for deployment Microsoft seminar Feb. 6 in Union 212 Other issues Q&A

Jan. 12, 2007Windows Vista3 Versions Starter – not available in US Home Basic – limited functionality Home Premium – minimum for K-State home use Business – minimum for K-State computers Ultimate – $$$ (business+multimedia tools) Enterprise – not available retail; volume license customers with Software Assurance only)

Jan. 12, 2007Windows Vista4 Availability Developers – available now; could order Business version from SHI since November Retail consumers (i.e., ship with new Dell, etc. computers) – January 30 Can pre-order from SHI now (and amazon.com) Dell, Gateway, HP offer Vista “Express Upgrade” with new computer purchase (usually only a shipping fee added) until March 15 Union Computer Store doesn’t know pricing yet or when it will be available

Jan. 12, 2007Windows Vista5 Vista Security “SD3” – security by design, default, and deployment Is more secure, but… –Vulnerabilities already identified (selling for $50K) –Still susceptible to social engineering, “stupid user” attacks (click- happy users) Extent of damage can be limited with “User Account Control” (UAC) –Users don’t have admin control by default –Can perform common tasks w/o admin rights –Administrator Approval Mode prompts user before performing admin task like installing software –Many control settings (is good, but more complicated) –Some applications may break with UAC

Jan. 12, 2007Windows Vista6 Other Vista Security Features Windows Defender built in –Real-time spyware protection –Updates managed by WSUS or Windows Update –Prompts user if a program tries to modify a protected area of the Vista kernel (“PatchGuard” locks kernel) –SIRT will re-evaluate Spybot recommendation Windows Firewall –Filters both inbound and outbound traffic –Different rulesets depending on type of network connection Windows Security Center more user oriented and comprehensive

Jan. 12, 2007Windows Vista7 Other Vista Security Features Malicious Software Removal Tool –cleans up malware missed by antivirus software –New version monthly via WSUS, Windows Update –Similar to Trend OfficeScan Damage Cleanup Services Software Restriction Policies –Control environment in which applications can operate –Similar to Windows XP Pro Internet Explorer 7 security features Group Policies easier to work with, but voluminous

Jan. 12, 2007Windows Vista8 Other Vista Security Features BitLocker –Encrypts entire Windows volume (but leaves system volume unencrypted) –Cannot boot Linux and look at Windows files –Prompts for PIN or uses USB token at boot-up –Can store encryption keys and protect integrity of boot code with TPM chip –Don’t lose your PIN or USB key! –Affects performance of the computer –Only in Ultimate and Enterprise versions

Jan. 12, 2007Windows Vista9 Other Vista Security Features Encrypting File System (EFS) –Encrypt individual files and/or folders –Can store decryption key on smartcard –Can generate recovery key –If use with BitLocker, EFS keys protected (hacker can’t get password hash to try brute force cracking) –Can encrypt multiple drives and network shares –Available in Business, Ultimate, and Enterprise versions

Jan. 12, 2007Windows Vista10 Other Vista Security Features Rights Management Services –Protect info in transit ( , docs, web content) –Requires a server –Application has to be RMS-compatible Device Control –Prevent users from installing certain devices, like USB flash drive or other removable storage –Can turn off AutoPlay or AutoRun

Jan. 12, 2007Windows Vista11 Vista Security Windows Vista Security Guide: VERY useful document – get it, study it Chapters on: –Implementing the Security Baseline (Group Policy) –Protecting Against Malware (UAC, Defender, Firewall, Security Center, Malicious Software Removal Tool) –Protecting Sensitive Data (BitLocker, EFS, Rights Mgmt, Device Control)

Jan. 12, 2007Windows Vista12 Trend Micro Still need AV software with Vista No OfficeScan client for Vista yet Current version = 7.3 Vista-compatible version = 8.0 Expected Q207 (April-June?) Cannot run Windows without antivirus/security software

Jan. 12, 2007Windows Vista13 SIRT Recommendations Hold off on deployment until Trend Micro releases a compatible OfficeScan client Use Business version or better for campus computers Use Home Premium or better for personal computers brought to campus Consider implementation plan carefully Test all applications thoroughly Don’t be in any hurry

Jan. 12, 2007Windows Vista14 Microsoft Visit At K-State Feb. 6, Union 212 Two sessions: –10-11:30 A.M. – general overview of Vista and IE7, general Q&A –1:30-3:30 P.M. – technical details, licensing, security, in-depth Q&A Will be announced in IT Tuesday and sirt- contacts mailing list

Jan. 12, 2007Windows Vista15 Other Issues License downgrade? Are probably some options, but unsure of details at this time Can buy XP Pro for another year License activation under Volume License Agreements Samba broken with default Vista configuration Other applications reported to have problems – test! New user interface – will be challenging transition for some

Jan. 12, 2007Windows Vista16 Q&A?