Trustworthy Yet? An examination of Microsoft’s Trustworthy Computing initiative, and what it means to enterprise security practitioners.

Slides:



Advertisements
Similar presentations
Patch Management Patch Management in a Windows based environment
Advertisements

By Bruce Ellis Western Governors University. Demonstrate the need for updating information systems Build security awareness Inform management of the risk.
TechNet MSDN Briefings Najaar 2004 TechNet MSDN Briefings Najaar 2004.
Introduction to Systems Management Server 2003 Tyler S. Farmer Sr. Technology Specialist II Education Solutions Group Microsoft Corporation.
USING EMET TO DEFEND AGAINST TARGETED ATTACKS PRESENTED BY ROBERT HENSING – SENIOR CONSULTANT – MICROSOFT CORPORATION MICHAEL MATTES – SENIOR CONSULTANT.
JD Edwards & Co. Microsoft Corp. Sun Microsystems, Inc.
Windows 7 Project and Heartbleed Update Sian Shumway Director, IT Customer Service.
SAGE-AU Adelaide Windows Update Services Michael Kleef IT Pro Evangelist Microsoft Corporation Level 200.
MICROSOFT PLATFORM  Microsoft is a platform company is committed to providing a rich ecosystem for building and managing connected systems.  Microsoft.
Project Overview Sun Microsystems Analysis Term Paper Alexander Shusta.
NaTasha Cherry Gates plans huge push for next Windows October 6, 2005.
Protection Through Software and Services James Hamilton General Manager Microsoft Corporation.
Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches.
Desktop Computers CIS100 – Introduction to Computers.
Cliff Evans Security and Privacy Lead Trustworthy Computing Group Microsoft UK.
Patch Management Strategy
IT:Network:Microsoft Applications
Security Risk Management Marcus Murray, CISSP, MVP (Security) Senior Security Advisor, Truesec
Windows Server Licensing
1 Windows Server Roadmap Update. 2 Agenda Windows Server Market Trends A Look Ahead NAP Collaboration Announcement Windows Server 2003 R2 Product Update.
 When Bill Gates saw how successful the apple “Lisa” computer and “Mac” computer were doing he decided to create an operating system with a GUI himself.
Technology from Microsoft David Overton Head of Technology for Small Business
Transition to Managed Services 0 Microsoft E-Learning IT Infrastructure Partnership Team August 26, 2008.
 Protect customers with more secure software  Reduce the number of vulnerabilities  Reduce the severity of vulnerabilities  Address compliance requirements.
CIS 375—Web App Dev II Microsoft’s.NET. 2 Introduction to.NET Steve Ballmer (January 2000): Steve Ballmer "Delivering an Internet-based platform of Next.
Security Overview for Microsoft Infrastructures Fred Baumhardt and James Noyce Infrastructure Solutions and Security Solutions Teams Microsoft Security.
The Trustworthy Computing Security Development Lifecycle Steve Lipner Director of Security Engineering Strategy Security Business and Technology Unit.
| Copyright© 2010 Microsoft Corporation. Exploring Office 365 What are ‘cloud services’ and are they right for me? I have an English accent I have an.
Raven Services Update December 2003 David Wallis Senior Systems Consultant Raven Computers Ltd.
Virtual techdays INDIA │ 9-11 February 2011 Security Discussion: Ask the Experts M.S.Anand │ MTC Technology Specialist │ Microsoft Corporation Anirudh.
Copyright © Microsoft Corp 2006 Pragmatic Secure Design: Attack Surface Reduction Shawn Hernan Security Program Manager Security Engineering and Communication.
Nakita herring A211/27/12.   In this power point I will be talking about Bill Gates and Steve Jobs. Outline.
Engineering Workshops IPv6 and Microsoft Windows Bill Cerveny.
WINDOWS MANAGEMENT 1 Case Studies: Implementing SMS 2003 November 20, 2003 Microsoft SMS 2003 Launch Event.
ICT development office ICT research, planning and training dept. Network development and administration dept. System development and operation dept. President.
Windows Operating system
Raj Natarajan National Technology Specialist Microsoft Australia.
Security Assessment Tools Paula Kiernan Senior Consultant Ward Solutions.
DIANA M ISHAK Server Product Manager. READY TO GROW! Steve Ballmer Microsoft CEO.
Vlad Mazek Own Web Now Corp CEO, MCSE, MCSA, CISSP (877) Portions reproduced with permission from Dean Calvert.
Benjamin Naden Windows Client Group Manager, Microsoft Singapore.
Catherine Lian Managing Director, Dell Indonesia
Managing the Heartbeat of Change Dave Coplin, Enterprise Strategy Consultant, Microsoft.
Advancing Security Progress and Commitment Stuart Okin Chief Security Advisor – Microsoft UK Delivering on security (an update on progress)
Be Microsoft’s first and best customer Enabling world-class and predictable customer, client, and partner experience Protecting Microsoft’s physical and.
Pieter Hancke Senior Consultant Microsoft Consulting Services Session Code: WCL303.
Copyright © Microsoft Corp 2006 The Security Development Lifecycle Eric Bidstrup, CISSP Group Program Manager Security Engineering and Communication.
Windows Small Business Server 2003 R2 Powering Small Businesses.
Microsoft Blake Coats Cory Clifford Nick Crandall.
DATA MANAGEMENT AND IT IN BA/BE STUDIES DR. SHIVPRAKASH MANAGING DIRECTOR SYNCHRON RESEARCH SERVICES PVT. LTD., INDIA.
History of Windows Operating System. Windows 1.0 Debuted in 1985 First version of Windows that was set up to use bitmap displays and mouse pointing devices.
How We Got Here PC and Internet changed the rules –Viruses, information sharing, “outside” and “inside” indistinguishable –Vulnerability research for.
History of Computers Past and Present.
Internal developer tools and bug tracking Arabic / Hebrew Windows 3.1Win95 Japanese Word, OneNote, Outlook
Applicatieplatform congres 12 & 13 maart. Microsoft Application Platform A Lifecycle View Sam Guckenheimer Group Product Planner Visual Studio Team System.
Quantifying Cyber Security Risk in Dollars and Cents to Optimize Budgets CRM008 Speakers: Chris Cooper, VP, Operational Risk Officer; RGA Reinsurance Company.
Redmond Protocols Plugfest 2016 Steve May Windows Telemetry & Privacy WDG Enterprise & Security.
Secure Connected Infrastructure
Enterprise-level Identity Protection
Microsoft a Cisco – optimalizácia IT služieb
The Microsoft® Security Development Lifecycle (SDL)
Microsoft’s Security Strategy
Chapter 4 Computer Software McGraw-Hill/Irwin
Evolution of Microsoft Windows: 1985 ~ 2009
Enterprise Program Management Office
Презентация құру тәсілдері
Security in the Real World – Plenary Day One
Implementing Security Patch Management
In the attack index…what number is your Company?
Steve Lipner Executive Director, SAFECode 16 May 2019
Presentation transcript:

Trustworthy Yet? An examination of Microsoft’s Trustworthy Computing initiative, and what it means to enterprise security practitioners

Our Panelists

KEN TYMINSKI CISO Prudential Financial of America

JOSEPH COOPER, CISSP Chairman & CEO Digital Defense

JONATHAN PERERA Senior Director of Product Management Microsoft’s Security & Technology Unit

Microsoft’s Beginnings

Gates’ Mandate “Trustworthy Computing is computing that is as available, reliable and secure as electricity, water services and telephony.” --Bill Gates, January 17, 2002

Trustworthy Milestones 2002 Retrained 11,000 developers and engineers Revamped MSRC Retrofitted XP (SP1) and Win2K (SP4) Released MBSA Replaced the complier in Win2003 Released Win2003 with services off by default Changed philosophy on shipping products

Trustworthy Milestones 2003 Released SQL Server 2000 SP3 Improved Exchange 2003 & Office 2003 Changed vulnerability announcements Launched ISA 2000 FP1 Released patching tools Acquired AV company, formed alliance

Trustworthy Ambitions Windows XP (beta; due summer ’04) Integrating WUS with Windows, other apps Active defenses, synergistic strategy Substantial more secure OSes & apps: Yukon (SQL), 2005; Longhorn (Windows), 2006

= Trustworthy Ambitions End goal: 2014 or longer

Microsoft is doing enough to improve its software security. Strongly Disagree 40% Somewhat Disagree 30% Strongly Agree 2% Somewhat Agree 18%

Will Trustworthy Computing eventually make a difference?

Redmond’s Assessment “I think we have made a good start in the last two years, and I believe we will have made enormous progress 10 years from now.” STEVE BALLMER CEO, Microsoft

Is Microsoft doing enough to improve the security of its products? Is it on the right track?

Patching

Patching Windows Is Best Characterized As: Unavoidable 46% An Overblown Problem 5% Onerous 48%

Microsoft Is Doing Enough To Ease The Patching Problem. Strongly Disagree 28% Somewhat Disagree 33% Strongly Agree 3% Somewhat Agree 20%

Is the Windows patching problem getting better?

Synergistic Security “There’s no one thing that’s going to solve this. Mitigation is part of it.” MIKE NASH Corporate VP, Microsoft SBU

Will Microsoft’s synergistic security strategy lead to better overall security for Windows and its other applications?

What does Microsoft need to do to win and retain the confidence of its enterprise customers?

Users Respond