Advertisement
Promo

Security threats Toolkit

Microsoft to simplify security alerts

Joe Wilcox, CNET News.com CNET News

Published: 20 Nov 2002 11:41 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is promising customers that it will simplify the security alerts it routinely issues on problems affecting its products.

The company notified customers of pending changes to security alert bulletins in an email sent on Tuesday to the Microsoft Security Notification Service mailing list.

"Customer feedback tells us that, while technical professionals value our security bulletins, many end-users find them overly detailed and confusing," Steve Lipner, director of Microsoft Security Assurance, wrote in the email. He also noted that many people receive notices that would be "of interest only to developers or system administrators."

To address both issues, Microsoft plans to "create a less technical end-user security bulletin that we will host, while continuing to offer more technical alerts for technology professionals. The new end-user security bulletins will describe straightforward steps that customers can take to help keep their systems secure," Lipner wrote.

Those bulletins, like the more business-oriented ones, will be available at Microsoft's security Web site.

"In addition, before year's end, we will create a new End User Security Notification Service that will notify customers of security issues in end-user-oriented products and provide a link to the appropriate end-user security bulletin," Lipner wrote.

Microsoft stepped up its emphasis on security in January, when chairman Bill Gates sent an email to employees making security the company's No. 1 priority -- ahead of adding new product features.

The company then unleashed a torrent of security alerts, after Microsoft developers uncovered problems during several intensive rounds of code reviews. So far this year, Microsoft has issued 64 security bulletins, exceeding by October the number of alerts sent out in all of 2001. Each bulletin can sometimes describe two, three or more separate security problems.

Analysts gave Microsoft high marks for attempting to clean up its security bulletins, which they agreed are too difficult for most people to decipher.

"Existing Microsoft security bulletins assume that the reader is a programmer," said independent security consultant Richard Smith. "Of course, most Microsoft customers are not programmers and therefore need simpler explanations of security problems."

According to Robert McLaws, President of Interscape Technologies, "Computer security is not just an IT concern, but as of right now the only way to get security bulletins is through their (Microsoft's) IT assistance channels.

"Security alerts targeted to laypeople is definitely a good idea, although I'm sure it will be difficult for tech people to simplify the concepts into nontech terms. It is definitely a step in the right direction," McLaws said.

Besides changes to alerts, Microsoft also is revamping how security alerts are rated. The company had been rating severity of security problems as "low," "moderate" or "critical."

Many people "find that the ratings fail to clearly identify the most serious issues," Lipner wrote. "There is also a widespread feeling that the Severity Ratings are difficult to understand and apply."

Microsoft has added a fourth severity designation, "important," and posted clearer explanations what each of the four ratings mean.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
28 out of 62 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters