Desired Configuration Management Kevin Parr, PMP Principal System Center Technology Specialist Heartland District Microsoft Corporation

Slides:



Advertisements
Similar presentations
What is Infrastructure Optimisation and Why should you care?
Advertisements

2  Industry trends and challenges  Windows Server 2012: Modern workstyle, enabled  Access from virtually anywhere, any device  Full Windows experience.
Windows Server Deployment and Management With System Center.
Identity & Security. Today's IT Security challenges Rising Internal Attacks 75% of companies report insiders responsible for breaches Growing headcount.
The System Center Family Microsoft. Mobile Device Manager 2008.
Robert Bakker Marktsituatie Management strategie System Center Partner resources.
System Center 2012 R2 Overview
Introduction to Systems Management Server 2003 Tyler S. Farmer Sr. Technology Specialist II Education Solutions Group Microsoft Corporation.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco Confidential 14854_10_2008_c1 1 Holistic Approach to Information Security Greg Carter, Cisco Security.
Enterprise CAL Overview. Different Types of CALs Standard CAL base A component Standard CAL is a base CAL that provides access rights to basic features.
1 Vladimir Knežević Microsoft Software d.o.o.. 80% Održavanje 80% Održavanje 20% New Cost Reduction Keep Business Up & Running End User Productivity End.
A Technical Overview of Microsoft Forefront Client Security (FCS) Howard Chow Microsoft MVP.
Unleashing the Power of Ubiquitous Connectivity with IPv6 Sandeep K. Singhal, Ph.D Director of Program Management Windows Networking.
Security Controls – What Works
Ronald Beekelaar Beekelaar Consultancy Forefront Overview.
IT PLANNING Enterprise Architecture (EA) & Updates to the Plan.
Microsoft Operations Management Suite
© Copyright Lumension Security Lumension Security PatchLink Enterprise Reporting™ 6.4 Overview and What’s New.
Ronald Beekelaar Beekelaar Consultancy Forefront Overview.
Why Improve Datacenter Automation? “ Studies show up to 80% of network availability incidents and 60% of security issues can be tied to human error” CIO.
Minimising IT costs, maximising operational efficiency Traditional Approach to Management Small point tools to perform particular tasks.
Cliff Evans Security and Privacy Lead Trustworthy Computing Group Microsoft UK.
Cloud Attributes Business Challenges Influence Your IT Solutions Business to IT Conversation Microsoft is Changing too Supporting System Center In House.
Wally Mead Senior Program Manager Microsoft Corporation.
What is Infrastructure Optimization and Why do I Care?
Partnering For Profitability Growing your business with Microsoft Forefront Security Solutions Mark Hassall Director Security & Access BG Microsoft Corporation.
System Center Operations Manager 2007 Dave Northey Microsoft Ireland.
By Isaac Parenteau. Agenda  What is the certification?  What are the courses required for it?  Future Careers  Cost?
1 Managed Security. 2 Managed Security provides a comprehensive suite of security services to manage and protect your network assets –Managed Firewall.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
Technology from Microsoft David Overton Head of Technology for Small Business
1. Windows Vista Enterprise And Mid-Market User Scenarios 2. Customer Profiling And Segmentation Tools 3. Windows Vista Business Value And Infrastructure.
Tim Vander Kooi Systems
Successful Deployment and Solid Management … Close Relatives Tim Sinclair, General Manager, Windows Enterprise Management.
Virtual techdays INDIA │ 9-11 February 2011 Security Discussion: Ask the Experts M.S.Anand │ MTC Technology Specialist │ Microsoft Corporation Anirudh.
User Manager Pro Suite Taking Control of Your Systems Joe Vachon Sales Engineer November 8, 2007.
Windows Small Business Server 2003 Setting up and Connecting David Overton Partner Technical Specialist.
Client Management Challenge Microsoft Optimized Desktop System Center Client Management Solutions Future of Client Management Conclusion Agenda.
Microsoft Systems Management Strategy: System Center.
SAM for Virtualizatio n Presenter Name. Virtualization: a key priority for business decision makers Technavio forecasts that the global virtualization.
The Infrastructure Optimization Journey Kamel Abu Ayash Microsoft Corporation.
Future of the Server Room Tour. Ottawa Montreal Calgary Vancouver Toronto Future of Your Server Room Three Pillars of Windows Server 2008 Virtualization.
Identity Solution in Baltic Theory and Practice Viktors Kozlovs Infrastructure Consultant Microsoft Latvia.
Satisfy Your Technical Curiosity Specialists Enterprise Desktop -
Microsoft Management Seminar Series SMS 2003 Change Management.
Microsoft’s System Center
Rob Davidson, Partner Technology Specialist Microsoft Management Servers: Using management to stay secure.
Jorke Odolphi Product Technology Specialist WebCentral Using Microsoft Operations Manager To Monitor And Maintain Your Farm.
Reducing server sprawl and IT power/cooling costs Moving from reactive to proactive state Quickly troubleshooting PC and laptop issues Deploying new.
Managing Data Center Server Compliance Using System Center System Center Microsoft Corporation.
Be Microsoft’s first and best customer Enabling world-class and predictable customer, client, and partner experience Protecting Microsoft’s physical and.
Data Center Management Microsoft System Center. Objective: Drive Cost of Data Center Management 78% Maintenance 22% New Issue:Issue: 78% of IT budgets.
Managing your IT Environment. Microsoft Operations Manager 2005 Overview.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
Ellis Paul Technical Solution Specialist – System Center Microsoft UK Operations Manager Overview.
Minimising IT costs, maximising operational efficiency IO and NIMM: Now is the time Glyn Knaresborough Director of Strategic Consulting.
System Center Overview Andrew Driver Partner Technical Specialist Management and Security.
Microsoft Forefront and System Center Driving to Dynamic IT with System Center and Forefront Eric Berg Director of Product Management Server & Tools.
Master Expert Associat e Microsoft Certified Solutions Master (MCSM) Microsoft Certified Solutions Expert (MCSE) Microsoft Certified Solutions Associate.
Verktøy og muligheter. System Center Configuration Manager 2007.
Windows 2012R2 Hyper-V and System Center 2012
Hybrid Management and Security
Infrastructure, Data Center & Managed Services
IT Management, Simplified
Management of Virtual Environments
1/1/2019 8:36 AM System Center – Datacenter Management Technology Specialist Management Produkte Microsoft Deutschland.
Increase and Improve your PC management with Windows Intune
Agenda The current Windows XP and Windows XP Desktop situation
IT Management, Simplified
IT Management, Simplified
Presentation transcript:

Desired Configuration Management Kevin Parr, PMP Principal System Center Technology Specialist Heartland District Microsoft Corporation

Agenda −Discuss Microsoft's Systems Management Strategy with System Center −Learn how to use DCM to assess and report on compliance with System Center Configuration Manager 2007 −Design configuration items and baselines for an organization

Use knowledge-based, automated in-line tasks to deliver rapid, high quality service Use knowledge-based, automated in-line tasks to deliver rapid, high quality service Maximize the use of the IT department’s existing Windows Server expertise Maximize the use of the IT department’s existing Windows Server expertise Out of the box, build on deep domain knowledge from both Microsoft and our strong partner community Out of the box, build on deep domain knowledge from both Microsoft and our strong partner community Implement templated best practices through Solution Accelerators Implement templated best practices through Solution Accelerators Reduce complexity through seamless management of logical IT environments Reduce complexity through seamless management of logical IT environments Manage your virtual environments down to the application level Manage your virtual environments down to the application level Improve visibility and control through integrated management Improve visibility and control through integrated management Manage multi-hypervisor technologies and monitor cross-platform environments Manage multi-hypervisor technologies and monitor cross-platform environments Dynamic IT Management

System Center Solutions: People, Process, & Technology Desktop & Device Management Data Center Management Mid-Market Solutions Open Standards Virtualization Technology Windows Platform Infrastructure Products Microsoft Consulting Services Management Packs Partner Ecosystem Knowledge Solution Accelerators Connectors for Interoperability Microsoft Operations Framework (MOF/ITIL)

Hardware Provisioning Workload Provisioning PatchingMonitoring Disaster Recovery Backup Virtual machine management Server consolidation and resource utilization optimization Conversions: P2V and V2V Virtual machine management Server consolidation and resource utilization optimization Conversions: P2V and V2V Patch management and deployment OS and application configuration management Software upgrades Patch management and deployment OS and application configuration management Software upgrades Live host level virtual machine backup In guest consistency Rapid recovery Live host level virtual machine backup In guest consistency Rapid recovery End to end service management Server and application health monitoring & management Performance reporting and analysis End to end service management Server and application health monitoring & management Performance reporting and analysis

The Challenge Regulatory Compliance IT organizations spend between 5,000 and 20,000 person-hours a year trying to stay compliant with Sarbanes-Oxley’s requirements Source: Survey on Sarbanes-Oxley Compliance Practices Within IT Organizations and Businesses by French Caldwell, Christine Adams, and John Bace (Gartner, September 2006) … but almost 1/3 of U.S. organizations still say they are not compliant Source: “The Global State of Information Security 2006” (CIO and PricewaterhouseCoopers, September 15, 2006)

The Challenge Configuration Drift 40% of unplanned downtime is caused by Application failure (primarily configuration) Source: “Tearing down the Wall” (Gartner, 2002) … and 82% of organizations reported downtime significant enough to impact their business −Average cost of more than $10,000/hour −Average duration of 3-4 hours Source: “Executives say software to blame for most IT downtime” (IndustryWeek, July 2007)

Data Security with Microsoft – PCI Perspective ISA Server, IPSec, Windows Firewall, Group Policy, Configuration Manager DCM, Operations Manager ACS Forefront Client & Server, Windows Defender, Malicious Software Removal Tool, Security Development Lifecycle, Threat Modeling, Writing Secure Code Rights Management Server, Encrypted File System, Certificates/ PKI, VISTA Bitlocker Active Directory, Right Management Server, SQL Server, SharePoint Server, Microsoft Identity and Integration Server, Smart Cards, Certificate Lifecycle Manager Configuration Manager DCM, Operations Manager, Audit Collection Service (ACS); Forefront Client, Server & Edge, SQL Server, VISTA Event Log Manager Securing the Store Whitepaper, Regulatory Compliance Planning Guide, Security Awareness Material, Templates, Solution Deployment Guides & Accelerators Build and Maintain a Secure Network Protect Customer Data Maintain a Vulnerability Management Program Strong Access Control Measures Regularly Monitor and Test Networks Maintain an Information Security Policy

System Center Data Center Focus Areas Automated Provisioning and Updating of Physical and Virtual Environments Server Consolidation Through Virtualization Proactive Platform Monitoring Application & Service Level Monitoring Interoperable and Extensible Platform Configuration Controls and Reporting Centralized Security Auditing Comprehensive Security & Identity and Access Mgmt Business Continuity Through Virtualization Mgmt Backup and Recovery of Physical and Virtual Resources Disaster Recovery Configuration Management Configuration Management End to End to End Monitoring Server Compliance Server Compliance Data Protection and Recovery Data Protection and Recovery

Reduce Configuration Management Infrastructure Costs Simplified UI and Installation Simplified UI and Installation Branch office support Branch office support Greater levels of control (Scheduling, WoL) Greater levels of control (Scheduling, WoL) Built on Windows Management Infrastructure Built on Windows Management Infrastructure Simplicity Knowledge Driven Configuration Management IT policies for analyzing corporate and regulatory compliance IT policies for analyzing corporate and regulatory compliance Out of the box configuration policies for server workloads e.g. Exchange Out of the box configuration policies for server workloads e.g. Exchange License and asset inventory License and asset inventory Based on the Service Modeling Language (SML) Based on the Service Modeling Language (SML) Configuration Enabling the Mobile Enterprise Network Access Protection Network Access Protection Enterprise Vulnerability assessment Enterprise Vulnerability assessment Securely managing devices across the Internet Securely managing devices across the Internet Security Unified delivery of Windows Operating System for Clients and Servers One worldwide image to manage with Vista One worldwide image to manage with Vista Built on Windows Vista Deployment Technologies Built on Windows Vista Deployment Technologies Vista and Office 12 upgrade assessment and resolution planning Vista and Office 12 upgrade assessment and resolution planning Secure Online and Offline Provisioning Secure Online and Offline Provisioning Secure network storage of user state during Operating System deployment Secure network storage of user state during Operating System deployment Deployment Key Investments in System Center Configuration Manager 2007

The DCM Solution Regulatory Compliance Knowledge Microsoft supplied Configuration Packs −Regulations covered −Sarbanes-Oxley (SOX) −European Union Data Protection Directive (EUDPD) −Gramm-Leach Bliley Act (GLBA) −Federal Information Security Management Act (FISMA) −Health Insurance Portability and Accountability Act (HIPAA) −Products covered −Windows Server 2000 and 2003 −Windows XP and Vista −SQL Server 2000 and 2005 −Exchange Server 2003 Author, duplicate, or extend to meet individual organization policies

Microsoft licensed technology from Brabeion that provides a baseline of IT Controls for Microsoft platforms Aids in mapping these controls to required IT regulatory compliance frameworks: −COBIT −Control Objectives for Information and related Technology −ISO −International ISO and ISO Compliance PacksGLBA (Gramm-Leach-Bliley Act) HIPAA SOX(Sarbanes-Oxley) EUDPD (European Union Data Protection Directive) FISMA (Federal Information Security Management Act) Others

Identify required and prohibited configurations for clients, servers and applications and report on compliance against those definitions Improve availability, security, and performance by reducing problems associated with configuration drift Improve the help-desk’s ability to troubleshoot by providing defined configuration baselines Remediate non-compliance by deploying software, scripts, updates or task-sequences to corresponding dynamically created collections Desired Configuration Management

The DCM Solution Configuration Drift Create corporate policy and custom application configuration items (CIs) and baselines −Basic authoring UI for authoring by IT professionals −Published XML schema definition for authoring by LOB application developers −Homegrown or custom applications represent up to 90% of applications within large companies' infrastructure Source: “Executives say software to blame for most IT downtime” (IndustryWeek, July 2007)

Configuration Manager 2007 Operations Manager 2007 Exchange Server 2007 Exchange Server 2003 Vulnerability Assessment ISA Server 2006 Windows Server 2003 AD Windows Server 2003 DNS Windows Server 2003 WINS SharePoint Server 2007 SharePoint Server 2003 SQL 2000 SQL 2005 New Product RTM + 90 Days Desired Configuration Management Configuration Packs Configuration Packs

Server Compliance Configuration controls and centralized audit of system security Challenges Addressed SAS 70 is a huge initiative for us with regard to our data centers and all of our applications, and SOX is obviously important as well. With [System Center] my team has reduced the amount of time that we spend collecting security log information. For example, we just completed an investigation and pulled the security report in less than 5 minutes. In the past it would have taken days.” Jeff Skelton, Manager, Enterprise Management Center, Stewart Increasing compliance and audit requirements associated with business policies and regulatory requirements Security pressures in the data center Increasing compliance and audit requirements associated with business policies and regulatory requirements Security pressures in the data center Create, maintain and report on configuration controls for the data center environment Gather and report security related events Manage identities and access and improve security in the data center Create, maintain and report on configuration controls for the data center environment Gather and report security related events Manage identities and access and improve security in the data center Key Capabilities

Data Center Management Solutions Automated Provisioning and Updating of Physical and Virtual Environments Server Consolidation Through Virtualization Proactive Platform Monitoring Application & Service Level Monitoring Interoperable and Extensible Platform Configuration Controls and Reporting Centralized Security Auditing Comprehensive Security & Identity and Access Mgmt Business Continuity Through Virtualization Mgmt Backup and Recovery of Physical and Virtual Resources Disaster Recovery Configuration Management Configuration Management End to End to End Monitoring Server Compliance Server Compliance Data Protection and Recovery Data Protection and Recovery VirtualPhysical

System Center Roadmap 2007 SP1/R2 Rollup/SP SP V1 V5 V SP V R SP1