ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Microsoft unveils new security initiatives

Martin LaMonica CNET News.com

Published: 04 Jun 2003 08:28 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has opened up its drive to improve software security with a redesigned software patch management system and a partnership with VeriSign to authenticate Web services.

The company pledged on Tuesday to improve its system for sending out security fixes, or patches, to existing products. Ninety-five percent of attacks happen after a patch for a known software vulnerability has been issued, said Scott Charney, chief trustworthy computing strategist at Microsoft, during a keynote speech at the software maker's TechEd conference in Dallas.

By the end of the year, the company intends to consolidate from eight to two the number of ways that patches are distributed to customers. One of the two new systems will address changes to the Windows operating system, while the other will apply to Microsoft's business applications. Eventually, Microsoft will consolidate its patch management into a single tool that can work across all the company's products, Charney said.

In addition, Microsoft plans to ensure that Windows fixes add themselves automatically to the operating system's internal registry, rather than to different parts of the system. By introducing consistency and by making sure that all patches register as present within the software, there's a better chance that fixes will be implemented correctly, the company expects.

Improved patch installation is one facet of Microsoft's "Trustworthy Computing" initiative, which debuted last year. As part of that initiative, the company delayed the shipment of several high-profile products, including its Windows Server 2003 operating system and Visual Studio.Net development tools, in order to perform audits and code reviews, according to the company.

Charney said that the secure computing effort is ongoing. "We are now doing security audits on all our products as part of development. We have to do that, because the bad guys will innovate just like we do."

As expected, Microsoft also detailed on Tuesday a partnership with VeriSign, which will allow customers to use the security company's digital certificate service to authenticate a person's identity over a network of servers running Windows Server 2003. The service, which should also work over Wi-Fi wireless networks, is set to become available by the end of 2003, according to the allies.

Also at TechEd, Microsoft launched two training and certificate programs specially tailored to security concerns in an effort to reduce vulnerabilities that arise from poor application configuration.

Both programmes are extensions to the software maker's certified credentials for systems administrators and engineers that address the design of secure networks. One of the exams is administered by the Computing Technology Industry Association (CompTIA), a computer industry trade organisation.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
21 out of 55 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Visual Basic/SQL Server Support/Development - East London - 35k!

You will also be responsible for performing day to day maintenance and patch management and general application support. An experienced Visual Basic ...

IT Desktop Support - Helpdesk Support - 2nd line - Reading - 30k

Security Kaspersky, Sophos, Checkpoint Administration, MIMEsweeper Administration - Networking Cable & Patch Management , Network Protocols TCP/IP ...

Systems Administrator/ MCSE/ Server2003/ AD/ Exchange/ London/Retail

Systems Administrator/ MCSE/ Server2003/ AD/ Exchange/ MOM/ WINS/ TCP/IP/ Shift Work/ Patch Management/ Print Server Management. My client is looking ...

Discussions

RichardThurston RichardThurston

Government help

Friday 16 May 2008, 8:35 AM

2 comments
barrie barrie

Windows Driver Updates

Friday 16 May 2008, 3:14 AM

2 comments
jgj jgj

"what more do you need?"

Thursday 15 May 2008, 9:19 PM

5 comments
jgj jgj

"what more do you need?"

Thursday 15 May 2008, 9:19 PM

5 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal