<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type='text/xsl' href='http://myinsecurity.spaces.live.com/mmm2008-07-24_12.50/rsspretty.aspx?rssquery=en-US;http%3a%2f%2fmyinsecurity.spaces.live.com%2ffeed.rss' version='1.0'?><rss version="2.0" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:msn="http://schemas.microsoft.com/msn/spaces/2005/rss" xmlns:live="http://schemas.microsoft.com/live/spaces/2006/rss" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:cf="http://www.microsoft.com/schemas/rss/core/2005" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Microsoft Malaysia Security Advisor Page              e·van·gel·ist</title><description>Noun  ~ a preacher, sometimes itinerant</description><link>http://myinsecurity.spaces.live.com/</link><language>en-US</language><pubDate>Sat, 20 Sep 2008 09:33:21 GMT</pubDate><lastBuildDate>Sat, 20 Sep 2008 09:33:21 GMT</lastBuildDate><generator>Microsoft Spaces v1.1</generator><docs>http://www.rssboard.org/rss-specification</docs><ttl>60</ttl><live:identity><live:id>3655282381092027437</live:id><live:alias>myinsecurity</live:alias></live:identity><image><title>Microsoft Malaysia Security Advisor Page              e·van·gel·ist</title><url>http://blufiles.storage.live.com/y1pbHmH55J4323JfL0cu3vDESAe8IOI7BL7nOVsyikJmaAsdSbgHiN58oOZLvfP1kpk</url><link>http://myinsecurity.spaces.live.com/</link></image><cf:listinfo><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="typelabel" label="Type" /><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="tag" label="Tag" /><cf:group element="category" label="Category" /><cf:sort element="pubDate" label="Date" data-type="date" default="true" /><cf:sort element="title" label="Title" data-type="string" /><cf:sort ns="http://purl.org/rss/1.0/modules/slash/" element="comments" label="Comments" data-type="number" /></cf:listinfo><item><title>Technocrati</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!220.entry</link><description> &lt;br&gt;&lt;a href="http://technorati.com/claim/eeed9z4vkr" rel=me&gt;Technorati Profile&lt;/a&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Technocrati&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><category>None</category><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!220.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!220.entry</guid><pubDate>Sat, 20 Sep 2008 09:33:03 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!220/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!220.entry#comment</wfw:comment><dcterms:modified>2008-09-20T09:33:03Z</dcterms:modified></item><item><title>Deep Packet Inspection: Big Brother Technology for ISP's</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!217.entry</link><description>&lt;p&gt;&lt;img src="http://www.globalsecurity.org/space/facility/images/buckley-afb_2sws-radomes.jpg"&gt;  &lt;p&gt;  &lt;p&gt;These 'big brother' or 'eavesdropping' technology has long been use by the military of the United States.  &lt;p&gt;Notoriously known as Echelon, a remnant of the Cold War is now still being operated.  &lt;p&gt;From Wikipedia: &lt;blockquote&gt; &lt;p&gt;ECHELON is a name used in global media and in popular culture to describe a &lt;a href="http://en.wikipedia.org/wiki/Signals_intelligence"&gt;signals intelligence&lt;/a&gt; (SIGINT) collection and analysis network operated on behalf of the five signatory states to the &lt;a href="http://en.wikipedia.org/wiki/UK-USA_Security_Agreement"&gt;UK-USA Security Agreement&lt;/a&gt; (&lt;a href="http://en.wikipedia.org/wiki/Australia"&gt;Australia&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Canada"&gt;Canada&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/New_Zealand"&gt;New Zealand&lt;/a&gt;, the &lt;a href="http://en.wikipedia.org/wiki/United_Kingdom"&gt;United Kingdom&lt;/a&gt;, and the &lt;a href="http://en.wikipedia.org/wiki/United_States"&gt;United States&lt;/a&gt;, known as AUSCANZUKUS).&lt;a href="http://en.wikipedia.org/wiki/ECHELON#cite_note-0"&gt;[1]&lt;/a&gt; &lt;p&gt;The system has been reported in a number of public sources.&lt;a href="http://en.wikipedia.org/wiki/ECHELON#cite_note-1"&gt;[2]&lt;/a&gt; Its capabilities and political implications were investigated by a committee of the &lt;a href="http://en.wikipedia.org/wiki/European_Parliament"&gt;European Parliament&lt;/a&gt; during 2000 and 2001 with a report published in 2001.&lt;a href="http://en.wikipedia.org/wiki/ECHELON#cite_note-EP-2"&gt;[3]&lt;/a&gt;&lt;/blockquote&gt; &lt;p&gt;On the civilian side, same technology have been deployed in the US or other countries to sniff packets in real time ~ big brother.  &lt;p&gt;Michael Kassner wrote a very interesting article on Deep Packet Inspection and its potential abused by government through ISP's.  &lt;p&gt;User's privacy is at stake here. &lt;blockquote&gt; &lt;p&gt;Anyone who uses the Internet needs to be aware of &lt;a href="http://en.wikipedia.org/wiki/Deep_packet_inspection"&gt;Deep Packet Inspection&lt;/a&gt; (DPI), its uses, and potential misuses. You may recognize DPI as what ISPs use to conform to &lt;a href="http://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act"&gt;CALEA&lt;/a&gt;, the U.S. government-ordered Internet wire-tapping directive. If that’s not enough, DPI, albeit behind the scenes, allows ISPs to block, shape, and prioritize traffic, which is now fueling the “&lt;a href="http://en.wikipedia.org/wiki/Network_neutrality"&gt;Net Neutrality&lt;/a&gt;” versus traffic priority debate. So, what is DPI and how does it work?&lt;/blockquote&gt; &lt;p&gt;&lt;u&gt;&lt;strong&gt;So what is DPI?&lt;/strong&gt;&lt;/u&gt; &lt;p&gt;DPI is next-generation technology that’s capable of inspecting every byte of every packet that passes through the DPI device, that means packet headers, types of applications, and actual packet content. Up until now, this wasn’t possible with IDS/IPS systems or stateful firewalls. The difference being, DPI has the ability to inspect traffic at layers 2 through 7, hence the “deep” in DPI. A simple analogy would be that of snail mail. IDS/IPS firewalls would be the mail sorters who just read the letter’s address, knowing nothing about the letter’s content. Inspecting Internet traffic from layers 2 through 7 would correspond to the person who actually reads the letter and understands the contents. &lt;p&gt;To recap, DPI allows people controlling the device to know everything, including the payload of each packet in the data stream. For example, if an unencrypted e-mail is scanned, the actual body of the e-mail can be reassembled and read. Nate Anderson wrote an excellent Ars Technica article “&lt;a href="http://arstechnica.com/articles/culture/Deep-packet-inspection-meets-net-neutrality.ars/1"&gt;Deep Packet Inspection Meets Net Neutrality, CALEA&lt;/a&gt;.” The following quote appears in that article: &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;“Deep packet inspection refers to the fact that these boxes don’t simply look at the header information as packets pass through them. Rather, they move beyond the IP and TCP header information to look at the payload of the packet. The goal is to identify the applications being used on the network, but some of these devices can go much further; those from a company like Narus, for instance, can look inside all traffic from a specific IP address, pick out the HTTP traffic, then drill even further down to capture only traffic headed to and from Gmail, and can even reassemble e-mails as they are typed out by the user.”&lt;/em&gt;&lt;/blockquote&gt; &lt;p&gt;Mr. Anderson also explains what happens at layer 7: &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;“Layer 7 is the application layer, the actual messages sent across the Internet by programs like Firefox or Skype or Azureus. By stripping off the headers, deep packet inspection devices can use the resulting payload to identify the program or service being used. Procera, for instance, claims to detect more than 300 application protocol signatures, including BitTorrent, HTTP, FTP, SMTP, and SSH. Ellacoya reps tell Ars that their boxes can look deeper than the protocol, identifying particular HTTP traffic generated by YouTube and Flickr, for instance. Of course, the identification of these protocols can be used to generate traffic shaping rules or restrictions.”&lt;/em&gt;&lt;/blockquote&gt; &lt;p&gt;What makes DPI all the more impressive is that the packet analysis happens in real time, with data stream throughput approaching 20-30 Gb. See where I’m going with this? With no loss of throughput, ISPs are able to insert these devices directly in their data streams, forcing all traffic to pass through the devices. &lt;a href="http://www.proceranetworks.com/"&gt;Procera&lt;/a&gt;, &lt;a href="http://www.narus.com/"&gt;Narus&lt;/a&gt;, and &lt;a href="http://www.arbornetworks.com/"&gt;Ellacoya&lt;/a&gt; are front-runners in development of this technology, having placed equipment throughout the world. &lt;p&gt;&lt;strong&gt;DPI’s potential uses&lt;/strong&gt; &lt;p&gt;DPI technology is unique in that as of now it’s the only way to accomplish certain governmental security directives. DPI also has the potential to do a great deal of good. For example, DDoS attacks are virtually impossible to thwart. Conceivably if DPI were in place and configured correctly it would detect the DDoS packets and filter them out. Some more potential uses are listed below: &lt;ul&gt; &lt;li&gt;&lt;strong&gt;Network security&lt;/strong&gt;: DPI’s ability to inspect data streams at such a granular level will prevent viruses and spyware from either gaining entrance to a network or leaving it.  &lt;li&gt;&lt;strong&gt;Network access&lt;/strong&gt;: DPI creates conditions where network access rules are easy to enforce due to the deep inspection of packets.  &lt;li&gt;&lt;strong&gt;CALEA compliance&lt;/strong&gt;: DPI technology augments traffic access points (TAP) technology used initially for governmental surveillance equipment.  &lt;li&gt;&lt;strong&gt;SLA enforcement&lt;/strong&gt;: ISPs can use DPI to ensure that their acceptable use policy is enforced. For example, DPI can locate illegal content or abnormal bandwidth usage.  &lt;li&gt;&lt;strong&gt;QoS&lt;/strong&gt;: P2P traffic gives ISPs a great deal of trouble. DPI would allow the ISP to instigate traffic control and bandwidth allocation.  &lt;li&gt;&lt;strong&gt;Tailored service&lt;/strong&gt;: DPI allows ISPs to create different services plans, which means users would pay for a certain amount of bandwidth and traffic priority. This one is controversial and affects Net Neutrality.  &lt;li&gt;&lt;strong&gt;DRM enforcement&lt;/strong&gt;: DPI has the ability to filter traffic to remove copyrighted material. There’s immense pressure from the music and movie industries to make ISPs responsible for curtailing illegal distribution of copyrighted material. &lt;/ul&gt; &lt;p&gt;The above applications have the potential to give users a better Internet experience. Yet it wouldn’t take much mission creep to create major privacy concerns. I would feel remiss if I didn’t point them out and help everyone understand the ramifications. &lt;p&gt;&lt;strong&gt;Possible misuses of DPI&lt;/strong&gt; &lt;p&gt;DPI is another innovative technology that has ISPs arguing with privacy advocates. ISPs and DPI developers are adamant that the technology is benign and will create a better Internet experience. However, privacy groups have two major concerns: little or no oversight and the potential for losing still more individual privacy. Many experts find the following uses of DPI to be especially troubling: &lt;ul&gt; &lt;li&gt;&lt;strong&gt;Traffic shaping&lt;/strong&gt;: Traffic shaping is where certain traffic or entities get priority and a predetermined amount of bandwidth. With the increasing number of bandwidth-hungry applications, ISPs are having to make decisions on whether to increase available bandwidth with infrastructure build out or increase control of the existing bandwidth. Installing a DPI system is usually the choice as it’s cheaper and has a more predictable RoI. Albeit cheaper, it’s riskier, and I suspect that’s why the Net Neutrality debate is going on right now.  &lt;li&gt;&lt;strong&gt;Behavioral targeting (BT)&lt;/strong&gt;: BT uses DPI technology for the sole purpose of harvesting user information anonymously (supposedly) and selling it to interested parties who use the information to create ads that are targeted to the individual. &lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Final thoughts&lt;/strong&gt; &lt;p&gt;This is a very complex subject, having the potential to change everyone’s view of the Internet. An optimist would say that DPI will help enhance the experience, even producing  ads that are relevant to each individual user. Whereas a pessimist would say it’s “big brother” technology that only benefits ISPs. I don’t think anyone is sure how the Internet will look when the dust settles about DPI, but it should be interesting. &lt;p&gt;I hope that I was able to increase awareness of how ISPs using a DPI device can intercept, read, and interpret every one of your Internet-destined packets. An ulterior motive for explaining DPI is that in my next article I’d like to discuss behavioral targeting, a very controversial technology that uses DPI. I also want to discuss what, if any, options are available to prevent DPI from scanning your Internet traffic.&lt;img src="http://i.i.com.com/cnwk.1d/i/tr/Mugshots/NewsletterMugs110-85/Kassner_Michael_85-110.jpg"&gt; &lt;em&gt;Michael Kassner has been involved with wireless communications for 40 plus years, starting with amateur radio (K0PBX) and now as a network field engineer and independent wireless consultant. Current certifications include Cisco ESTQ Field Engineer, CWNA, and CWSP.&lt;/em&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Deep+Packet+Inspection%3a+Big+Brother+Technology+for+ISP's&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!217.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!217.entry</guid><pubDate>Fri, 01 Aug 2008 03:23:50 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!217/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!217.entry#comment</wfw:comment><dcterms:modified>2008-08-01T03:23:50Z</dcterms:modified></item><item><title>The Last Lecture: Professor Randy Pausch</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!216.entry</link><description>&lt;p&gt;God takes away the good ones first, so living will take note and learn from them. Last Friday,25th of July 2008, the renowned and respected Prof Dr Randy Pausch passed away after a long battle with pancreatic cancer.He was 47. He is survived by his wife and children Dylan, Logan, and Chloe. &lt;p&gt;His contribution, not only to Carnegie Mellon University, but the world showed his dedication in teaching others and the value of humanity. He was the founder of Alice program, an animated educational system for high school and college students. &lt;p&gt;  &lt;p&gt; &lt;div style="padding-right:0px;display:inline;padding-left:0px;padding-bottom:0px;margin:0px;padding-top:0px"&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt; &lt;p&gt;Rest in Peace. &lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+The+Last+Lecture%3a+Professor+Randy+Pausch&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!216.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!216.entry</guid><pubDate>Mon, 28 Jul 2008 17:04:37 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!216/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!216.entry#comment</wfw:comment><dcterms:modified>2008-07-28T17:04:37Z</dcterms:modified></item><item><title>Microsoft: Forget iPhone; we're still No. 2 in business</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!214.entry</link><description>&lt;h2&gt;&lt;/h2&gt; &lt;h1&gt;&lt;/h1&gt; &lt;h4&gt;The big(ger) dog gets growly&lt;/h4&gt; &lt;p&gt;  &lt;p&gt;July 21, 2008 (Computerworld) Companies -- lots of them -- are still buying &lt;a href="http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Microsoft+Windows+Mobile"&gt;Windows Mobile&lt;/a&gt; smart phones, and &lt;a href="http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Microsoft+Corporation"&gt;Microsoft Corp.&lt;/a&gt; doesn't want to let &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9108338"&gt;iPhone mania&lt;/a&gt; make them forget. &lt;p&gt;During Microsoft's most recent fiscal year, 325 enterprises purchased at least 500 Windows Mobile phones, with many buying many more, said Scott Rockfeld, group products manager for the mobile communications business at Microsoft, in a Friday interview.  &lt;p&gt;&amp;quot;From the armed forces to the U.S. Court System, people are not just trying Windows Mobile, they are buying them,&amp;quot; Rockfeld said, in apparent reference to a statement by Apple Inc. CEO Steve Jobs last month that 35% of Fortune 500 companies were beta-testing the &lt;a href="http://www.computerworld.com/action/inform.do?command=search&amp;amp;searchTerms=Apple+iPhone"&gt;iPhone&lt;/a&gt;.  &lt;p&gt;  &lt;p&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9110378&amp;amp;intsrc=news_ts_head" target="_blank"&gt;more...&lt;/a&gt; &lt;p&gt;  &lt;p&gt;My opinion, the Iphone is a fun phone, still a toy for the kids. Big boys still prefers Windows Mobile smart phones. &lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Microsoft%3a+Forget+iPhone%3b+we're+still+No.+2+in+business&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!214.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!214.entry</guid><pubDate>Tue, 22 Jul 2008 10:04:20 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!214/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!214.entry#comment</wfw:comment><dcterms:modified>2008-07-22T10:04:20Z</dcterms:modified></item><item><title>Storm Worm - wrecking havoc across the planet</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!213.entry</link><description>&lt;blockquote&gt; &lt;p&gt;&lt;img height=500 src="http://www.noaanews.noaa.gov/stories/images/perfectstorm-bw.gif" width=642&gt;                                                                    &lt;/blockquote&gt; &lt;p&gt;  &lt;p&gt;  &lt;p&gt;The Storm worm (not to be confused with &lt;a href="http://en.wikipedia.org/wiki/W32/Storm.worm"&gt;W32/Storm.worm&lt;/a&gt;) was first discovered on 17th of January 2007. It was named by the finish company F-Secure and it is a trojan malware that infects &lt;a href="http://www.microsoft.com/security/default.mspx" target="_blank"&gt;Microsoft&lt;/a&gt; operating system. It spreads via email, with these headings: &lt;li&gt;A killer at 11, he's free at 21 and kill again!  &lt;li&gt;U.S. Secretary of State &lt;a href="http://en.wikipedia.org/wiki/Condoleezza_Rice"&gt;Condoleezza Rice&lt;/a&gt; has kicked German Chancellor &lt;a href="http://en.wikipedia.org/wiki/Angela_Merkel"&gt;Angela Merkel&lt;/a&gt; &lt;li&gt;British Muslims Genocide  &lt;li&gt;Naked teens attack home director.  &lt;li&gt;230 dead as storm batters Europe.  &lt;li&gt;Re: Your text  &lt;li&gt;Radical Muslim drinking enemies's blood.  &lt;li&gt;Chinese/Russian missile shot down Chinese/Russian satellite/aircraft  &lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Saddam_Hussein"&gt;Saddam Hussein&lt;/a&gt; safe and sound!  &lt;li&gt;Saddam Hussein alive!  &lt;li&gt;Venezuelan leader: &amp;quot;Let's the War beginning&amp;quot;.  &lt;li&gt;&lt;a href="http://en.wikipedia.org/wiki/Fidel_Castro"&gt;Fidel Castro&lt;/a&gt; dead.  &lt;li&gt;If I Knew &lt;p&gt;When an attachment is opened, the malware installs the wincom32 service, and injects a payload, passing on &lt;a href="http://en.wikipedia.org/wiki/Packet_(information_technology)"&gt;packets&lt;/a&gt; to destinations encoded within the malware itself. According to Symantec, it may also download and run the Trojan.Abwiz.F trojan, and the W32.Mixor.Q@mm &lt;a href="http://en.wikipedia.org/wiki/Computer_worm"&gt;worm&lt;/a&gt;.&lt;sup&gt;&lt;a href="http://en.wikipedia.org/#cite_note-Symantec-9"&gt;[10]&lt;/a&gt;&lt;/sup&gt; The Trojan piggybacks on the &lt;a href="http://en.wikipedia.org/wiki/E-mail_spam"&gt;spam&lt;/a&gt; with names such as &amp;quot;postcard&lt;a href="http://en.wikipedia.org/wiki/.exe"&gt;.exe&lt;/a&gt;&amp;quot; and &amp;quot;Flash Postcard.exe,&amp;quot; with more changes from the original wave as the attack mutates.&lt;sup&gt;&lt;a href="http://en.wikipedia.org/#cite_note-InfoWeek-8"&gt;[9]&lt;/a&gt;&lt;/sup&gt; Some of the known names for the attachments include:&lt;sup&gt;&lt;a href="http://en.wikipedia.org/#cite_note-Symantec-9"&gt;[10]&lt;/a&gt;&lt;/sup&gt; &lt;ul&gt; &lt;li&gt;Postcard.exe  &lt;li&gt;ecard.exe  &lt;li&gt;FullVideo.exe  &lt;li&gt;Full Story.exe  &lt;li&gt;Video.exe  &lt;li&gt;Read More.exe  &lt;li&gt;FullClip.exe  &lt;li&gt;GreetingPostcard.exe  &lt;li&gt;MoreHere.exe  &lt;li&gt;FlashPostcard.exe  &lt;li&gt;GreetingCard.exe  &lt;li&gt;ClickHere.exe  &lt;li&gt;ReadMore.exe  &lt;li&gt;FlashPostcard.exe  &lt;li&gt;FullNews.exe  &lt;li&gt;NflStatTracker.exe  &lt;li&gt;ArcadeWorld.exe  &lt;li&gt;ArcadeWorldGame.exe &lt;/ul&gt; &lt;p&gt;  &lt;p&gt;more information &lt;a href="http://en.wikipedia.org/wiki/Storm_Worm" target="_blank"&gt;here&lt;/a&gt;,&lt;a href="http://www.f-secure.com/v-descs/small_dam.shtml" target="_blank"&gt;here&lt;/a&gt; and &lt;a href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojdorffam.html" target="_blank"&gt;here&lt;/a&gt;.&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Storm+Worm+-+wrecking+havoc+across+the+planet&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!213.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!213.entry</guid><pubDate>Tue, 22 Jul 2008 09:54:56 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!213/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!213.entry#comment</wfw:comment><dcterms:modified>2008-07-22T09:54:56Z</dcterms:modified></item><item><title>Microsoft Security Assessment Tool for Governments (MSATg)</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!212.entry</link><description>&lt;p&gt;The Microsoft Security Assessment Tool 3.75G (g for government version) is a revised version of the Microsoft Security Assessment Tool (MSAT) developed by Microsoft’s Trustworthy Computing Group.  MSAT is comprehensive toolset to help security organizations within governments become more aware of the evolving security threat landscape that could impact their organizations. &lt;p&gt;The tool employs a holistic approach to measuring security postures by covering topics across people, process, and technology. Findings are coupled with prescriptive guidance and recommended mitigation efforts, including links to more information for additional industry guidance. These resources can help maintain awareness of specific tools and methods changing the security posture of the IT environment. &lt;p&gt;The new Microsoft Security Assessment Tool conducts an assessments focused on 4 primary areas: &lt;p&gt;•       Infrastructure Security &lt;p&gt;•       Application Security &lt;p&gt;•       Security Operations &lt;p&gt;•       People, Process, Policy &lt;p&gt;After completing each Assessment, a detailed report of the results is available to review. &lt;p&gt;The questions identified in the survey portion of the tool and the associated answers are derived from commonly accepted best practices around security, both general and specific. The questions and the recommendations that the tool offers are based on standards such as ISO 17799 and NIST-800.x, as well as recommendations and prescriptive guidance from Microsoft’s Trustworthy Computing Group and additional security resources valued in the industry. &lt;p&gt;The MSAT v3.75g is now be available to SCP Participants.  The “g” version will remove the feature that allows for uploading and sharing the results with Microsoft and comparing those with other companies.  This version will have the added ability to compile results on a user agency’s own servers and compare results between departments. Also as a part of this version, we provide instructions on developing a standard baseline and how this standard baseline can be distributed to other agencies to conduct an assessment comparison. &lt;p&gt;The MSAT 3.75G version is now available in the following languages: &lt;p&gt;Canadian French, French, German, Russian, Italian, Spanish (Latin America), Spanish (Spain), Portuguese (Portugal), Portuguese (Brazil), Chinese (Simple), Chinese (Mandarin), Japanese, Swedish, Norwegian, Danish, English (US), and English (UK.)&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Microsoft+Security+Assessment+Tool+for+Governments+(MSATg)&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><category>Tools</category><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!212.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!212.entry</guid><pubDate>Sun, 13 Jul 2008 05:10:20 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!212/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!212.entry#comment</wfw:comment><dcterms:modified>2008-07-13T05:10:20Z</dcterms:modified></item><item><title>Microsoft Security Tuesday/Wednesday</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!210.entry</link><description>&lt;p&gt;  &lt;table style="width:531.2pt;border-collapse:collapse" cellspacing=0 cellpadding=0 width=708 border=0&gt; &lt;tbody&gt; &lt;tr style="height:38.85pt"&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:black 1pt solid;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:black 1pt solid;width:60.45pt;padding-top:0in;border-bottom:black 1pt solid;height:38.85pt" valign=top width=81&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Bulletin Number&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:black 1pt solid;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:medium none;width:66.55pt;padding-top:0in;border-bottom:black 1pt solid;height:38.85pt" valign=top width=89&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Maximum Severity&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:black 1pt solid;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:medium none;width:266.3pt;padding-top:0in;border-bottom:black 1pt solid;height:38.85pt" valign=top width=355&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Affected Products&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:black 1pt solid;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:medium none;width:137.9pt;padding-top:0in;border-bottom:black 1pt solid;height:38.85pt" valign=top width=184&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Impact&lt;/span&gt; &lt;tr style="height:27.75pt"&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;padding-bottom:0in;border-left:black 1pt solid;width:60.45pt;padding-top:0in;border-bottom:black 1pt solid;height:27.75pt" valign=top width=81&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;MS08-037&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;padding-bottom:0in;border-left:medium none;width:66.55pt;padding-top:0in;border-bottom:black 1pt solid;height:27.75pt" valign=top width=89&gt; &lt;p&gt;&lt;b&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Important&lt;/span&gt;&lt;/b&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;padding-bottom:0in;border-left:medium none;width:266.3pt;padding-top:0in;border-bottom:black 1pt solid;height:27.75pt" valign=top width=355&gt; &lt;p&gt;&lt;span style="color:#404040"&gt;Windows 2000, Windows XP, Windows Server 2003, Windows Server 2008. &lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;padding-bottom:0in;border-left:medium none;width:137.9pt;padding-top:0in;border-bottom:black 1pt solid;height:27.75pt" valign=top width=184&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Spoofing&lt;/span&gt; &lt;tr style="height:25.4pt"&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:black 1pt solid;width:60.45pt;padding-top:0in;border-bottom:black 1pt solid;height:25.4pt" valign=top width=81&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;MS08-038&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:medium none;width:66.55pt;padding-top:0in;border-bottom:black 1pt solid;height:25.4pt" valign=top width=89&gt; &lt;p&gt;&lt;b&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Important&lt;/span&gt;&lt;/b&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:medium none;width:266.3pt;padding-top:0in;border-bottom:black 1pt solid;height:25.4pt" valign=top width=355&gt; &lt;p&gt;&lt;span style="color:#404040"&gt;Windows Vista and Windows Server 2008&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:medium none;width:137.9pt;padding-top:0in;border-bottom:black 1pt solid;height:25.4pt" valign=top width=184&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Remote Code Execution&lt;/span&gt; &lt;tr style="height:25.4pt"&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;padding-bottom:0in;border-left:black 1pt solid;width:60.45pt;padding-top:0in;border-bottom:black 1pt solid;height:25.4pt" valign=top width=81&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;MS08-039&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;padding-bottom:0in;border-left:medium none;width:66.55pt;padding-top:0in;border-bottom:black 1pt solid;height:25.4pt" valign=top width=89&gt; &lt;p&gt;&lt;b&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Important&lt;/span&gt;&lt;/b&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;padding-bottom:0in;border-left:medium none;width:266.3pt;padding-top:0in;border-bottom:black 1pt solid;height:25.4pt" valign=top width=355&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Exchange Server 2003 and Exchange Server 2007&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;padding-bottom:0in;border-left:medium none;width:137.9pt;padding-top:0in;border-bottom:black 1pt solid;height:25.4pt" valign=top width=184&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Elevation of Privilege&lt;/span&gt; &lt;tr style="height:65.75pt"&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:black 1pt solid;width:60.45pt;padding-top:0in;border-bottom:black 1pt solid;height:65.75pt" valign=top width=81&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;MS08-040&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:medium none;width:66.55pt;padding-top:0in;border-bottom:black 1pt solid;height:65.75pt" valign=top width=89&gt; &lt;p&gt;&lt;b&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Important&lt;/span&gt;&lt;/b&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:medium none;width:266.3pt;padding-top:0in;border-bottom:black 1pt solid;height:65.75pt" valign=top width=355&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;SQL Server 7.0, SQL Server 2000, SQL Server 2005, MSDE 1.0, MSDE 2000, SQL Server 2005 Express, SQL Server 2005 Express with Advanced Services, WMSDE, Windows Internal Database (WYukon)&lt;span style="background:yellow"&gt;&lt;/span&gt;&lt;/span&gt; &lt;td style="border-right:black 1pt solid;padding-right:5.4pt;border-top:medium none;padding-left:5.4pt;background:#fde9d9;padding-bottom:0in;border-left:medium none;width:137.9pt;padding-top:0in;border-bottom:black 1pt solid;height:65.75pt" valign=top width=184&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Elevation of Privilege&lt;/span&gt;&lt;/tbody&gt;&lt;/table&gt; &lt;p&gt;  &lt;p style="margin:0in 0in 0pt"&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Summaries for these new bulletins may be found at the following pages:&lt;/span&gt; &lt;p style="margin:0in 0in 0pt"&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt; &lt;/span&gt; &lt;p style="margin:0in 0in 0pt;text-indent:0in;tab-stops:.5in"&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/MS08-jul.mspx"&gt;http://www.microsoft.com/technet/security/bulletin/MS08-jul.mspx&lt;/a&gt;    &lt;/span&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt; &lt;/span&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;Microsoft Windows Malicious Software Removal Tool&lt;/span&gt; &lt;p&gt;&lt;span style="color:#404040"&gt; &lt;/span&gt; &lt;p&gt;&lt;span style="color:#404040"&gt;Microsoft is releasing an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Server Update Services (WSUS), Windows Update (WU) and the Download Center. Note that this tool will NOT be distributed using Software Update Services (SUS). Information on the Microsoft Windows Malicious Software Removal Tool can be located here: &lt;a href="http://go.microsoft.com/fwlink/?LinkId=40573"&gt;http://go.microsoft.com/fwlink/?LinkId=40573&lt;/a&gt; &lt;/span&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt; &lt;/span&gt; &lt;p&gt;&lt;span style="font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;High-Priority Non-Security Updates&lt;/span&gt; &lt;p&gt;&lt;span style="font-weight:normal;font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt; &lt;/span&gt; &lt;p&gt;&lt;span style="font-weight:normal;font-size:11pt;color:#404040;font-family:'Calibri','sans-serif'"&gt;High priority non-security updates Microsoft releases to be available on Microsoft Update (MU), Windows Update (WU) or Windows Server Update Services (WSUS) will be detailed in the following KB Article: &lt;a href="http://support.microsoft.com/?id=894199"&gt;http://support.microsoft.com/?id=894199&lt;/a&gt;  &lt;/span&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Microsoft+Security+Tuesday%2fWednesday&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!210.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!210.entry</guid><pubDate>Sun, 13 Jul 2008 05:03:11 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!210/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!210.entry#comment</wfw:comment><dcterms:modified>2008-07-13T05:03:25Z</dcterms:modified></item><item><title>Microsoft Security Taxonomy 2.0</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!209.entry</link><description>&lt;h4&gt;From a counterpart's blog..Microsoft Italia....&lt;/h4&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/feliciano_intini/default.aspx" target="_blank"&gt;Feliciano Intini&lt;/a&gt; has effortlessly compiled Microsoft security web sites. &lt;p&gt;. &lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" height=398 alt=DID src="http://blufiles.storage.msn.com/y1ps6HxBLtAdhAJpd2Ukrqq3Wl5rvJUteqp_RhGkmj8fHdGX-Kj4pQ1CwmFK1EqktLi?PARTNER=WRITER" width=219 border=0&gt; &lt;p&gt;&lt;u&gt;Microsoft Security Experts Blogs&lt;/u&gt; (in alphabetic order): &lt;p&gt;&lt;a href="http://blogs.msdn.com/aaron_margosis"&gt;Aaron Margosis&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/voy/"&gt;Cyril Voisin&lt;/a&gt; [UPD-08-04] &lt;p&gt;&lt;a href="http://blogs.msdn.com/david_leblanc"&gt;David LeBlanc&lt;/a&gt; [UPD-08-04] &lt;p&gt;&lt;a href="http://blogs.msdn.com/ericfitz"&gt;Eric Fitzgerald&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/security"&gt;Jeff Jones&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/kaiaxford"&gt;Kai Axford&lt;/a&gt; &lt;p&gt;&lt;a href="http://www.identityblog.com/"&gt;Kim Cameron&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/tietoturvan_weblogi/"&gt;Kimmo Bergius&lt;/a&gt; [UPD-08-04] &lt;p&gt;&lt;a href="http://blogs.technet.com/markrussinovich"&gt;Mark Russinovich&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.msdn.com/michael_howard"&gt;Michael Howard&lt;/a&gt; &lt;p&gt;· (BK) &lt;a href="http://www.microsoft.com/MSPress/books/5957.asp"&gt;Writing Secure Code 2nd Ed&lt;/a&gt; &lt;p&gt;· (BK) &lt;a href="http://books.mcgraw-hill.com/getbook.php?isbn=0072260858"&gt;19 Deadly Sins of Software Security&lt;/a&gt; &lt;p&gt;· (BK) &lt;a href="http://www.microsoft.com/MSPress/books/8753.asp"&gt;The Security Development Lifecycle&lt;/a&gt; &lt;p&gt;· (BK) &lt;a href="http://www.microsoft.com/MSPress/books/10723.aspx"&gt;Writing Secure Code for Windows Vista&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/robert_hensing"&gt;Robert Hensing&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/rhalbheer/"&gt;Roger Halbheer&lt;/a&gt; [UPD-08-04] &lt;p&gt;&lt;a href="http://blogs.technet.com/steve_lamb"&gt;Steve Lamb&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/steriley"&gt;Steve Riley&lt;/a&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/ms_schweiz_security_blog/"&gt;Urs P. Küderli&lt;/a&gt; [UPD-08-04] &lt;p&gt;&lt;a href="http://blogs.msdn.com/vbertocci"&gt;Vittorio Bertocci&lt;/a&gt; &lt;p&gt;· (BK) &lt;a href="http://www.amazon.com/dp/0321496841"&gt;Understanding Windows CardSpace&lt;/a&gt; [UPD-08-03] &lt;p&gt;&lt;a href="http://blogs.technet.com/mamykin/"&gt;Vladimir Mamykin&lt;/a&gt; [UPD-08-04]  &lt;p&gt;&lt;b&gt;0.0 &lt;/b&gt;&lt;b&gt;Microsoft Strategy &amp;amp; Initiatives&lt;/b&gt; &lt;p&gt;0.1 &lt;b&gt;Security &amp;amp; Privacy&lt;/b&gt; &lt;p&gt;&lt;b&gt;0.1.1 &lt;/b&gt;&lt;b&gt;Trustworthy Computing (TwC)&lt;br&gt;&lt;/b&gt;(W3) &lt;a href="http://www.microsoft.com/mscorp/twc/default.mspx"&gt;Trustworthy Computing homepage&lt;/a&gt; [UPD-08-04]&lt;b&gt;&lt;/b&gt; &lt;p&gt;&lt;b&gt;0.1.1.1 &lt;/b&gt;&lt;b&gt;End to End Trust&lt;br&gt;&lt;/b&gt;(W3) &lt;a href="http://www.microsoft.com/mscorp/twc/endtoendtrust/default.mspx"&gt;End to End Trust homepage&lt;/a&gt; [UPD-08-04]&lt;b&gt;&lt;/b&gt; &lt;p&gt;0.2 &lt;b&gt;Interoperability&lt;br&gt;&lt;/b&gt;(W3) &lt;a href="http://www.microsoft.com/interop/"&gt;Interoperability homepage&lt;/a&gt; [UPD-08-04]&lt;b&gt;&lt;/b&gt; &lt;p&gt;&lt;b&gt;0.2.1 &lt;/b&gt;&lt;b&gt;Interoperability Principles&lt;br&gt;&lt;/b&gt;(W3) &lt;a href="http://www.microsoft.com/interop/principles/default.mspx"&gt;Interoperability Principles homepage&lt;/a&gt; [UPD-08-04]&lt;b&gt;&lt;/b&gt; &lt;p&gt;&lt;b&gt;&lt;/b&gt; &lt;p&gt;&lt;b&gt;1.0 &lt;/b&gt;&lt;b&gt;Internet Security&lt;/b&gt; &lt;p&gt;1.1 Identity Metasystem &amp;amp; Windows CardSpace&lt;br&gt;(SB) &lt;a href="http://www.identityblog.com/blog.php/"&gt;Kim Cameron’s Identity Blog&lt;/a&gt; [UPD-08-03]&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/vbertocci/"&gt;Vittorio Bertocci’s Vibro.NET blog&lt;/a&gt; [UPD-08-03]&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/card/default.aspx"&gt;CardSpace: Behind The Code&lt;/a&gt; [UPD-08-03]&lt;br&gt;(W3) &lt;a href="http://msdn2.microsoft.com/en-us/netframework/aa663320.aspx"&gt;Windows CardSpace MSDN Resources&lt;/a&gt; [UPD-08-03]&lt;br&gt;(W3) &lt;a href="http://netfx3.com/content/WindowsCardspaceHome.aspx"&gt;Windows CardSpace on Microsoft .NET Framework 3.0 Community&lt;/a&gt; [UPD-08-03]&lt;br&gt;(BK) &lt;a href="http://www.amazon.com/dp/0321496841"&gt;Understanding Windows CardSpace&lt;/a&gt; [UPD-08-03] &lt;p&gt;1.2 Online Services Security&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/msonline/default.aspx"&gt;Microsoft Online Services TechCenter&lt;/a&gt; [UPD-08-04]&lt;br&gt;(WP) &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=5736aaac-994c-4410-b7ce-bdea505a3413&amp;amp;displaylang=en"&gt;Security Features in Microsoft Online&lt;/a&gt; [UPD-08-04] &lt;p&gt;1.2.1 Windows Live Security&lt;br&gt;(B) &lt;a href="http://winliveid.spaces.live.com/"&gt;Windows Live ID Team Blog&lt;/a&gt; &lt;p&gt;&lt;b&gt;&lt;/b&gt; &lt;p&gt;&lt;b&gt;2.0 &lt;/b&gt;&lt;b&gt;Perimeter &amp;amp; Network Security&lt;/b&gt; &lt;p&gt;2.1 Forefront Edge Security (Internet Access Protection &amp;amp; Secure Remote Access)&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/forefront/edgesecurity/default.mspx"&gt;Forefront Edge Security homepage&lt;/a&gt; [UPD-08-04]  &lt;p&gt;2.1.1 Internet Security &amp;amp; Acceleration (ISA) Server&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/isaserver/default.mspx"&gt;ISA Server homepage&lt;/a&gt; [UPD-08-04] &lt;p&gt;2.1.1.1 Previous versions: ISA 2000, ISA 2004&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/isablog/default.aspx"&gt;ISA Server Product Team Blog&lt;/a&gt; &lt;p&gt;2.1.1.2 Internet Security &amp;amp; Acceleration (ISA) Server 2006&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/isablog/default.aspx"&gt;ISA Server Product Team Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/isa/default.mspx"&gt;ISA Server TechCenter&lt;/a&gt; [UPD-08-01]  &lt;p&gt;2.1.1.3 Forefront Threat Management Gateway (TMG)&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/stirling"&gt;Forefront Stirling Blog&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/stirling/default.aspx"&gt;Forefront &amp;quot;Stirling&amp;quot; TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;2.1.2 Internet Application Gateway (IAG)&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/forefront/edgesecurity/iag/default.mspx"&gt;IAG homepage&lt;/a&gt; [UPD-08-04] &lt;p&gt;2.1.2.1 Internet Application Gateway (IAG) 2007&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/forefront/edgesecurity/iag/default.mspx"&gt;IAG 2007 TechCenter&lt;/a&gt; [UPD-08-01] &lt;p&gt;2.1.2.2 Forefront Unified Access Gateway (UAG)&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/stirling"&gt;Forefront Stirling Blog&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/stirling/default.aspx"&gt;Forefront &amp;quot;Stirling&amp;quot; TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;2.2 Network Access Protection (NAP) Solution&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/nap/default.aspx"&gt;Network Access Protection Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/network/bb545879.aspx"&gt;NAP TechCenter&lt;/a&gt;&lt;br&gt;(BK) &lt;a href="http://www.microsoft.com/MSPress/books/11160.aspx"&gt;Windows Server® 2008 Networking and Network Access Protection (NAP)&lt;/a&gt; &lt;p&gt;2.3 Remote Access, VPN &amp;amp; Quarantine Services&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/rrasblog/default.aspx"&gt;Routing and Remote Access Blog&lt;/a&gt;&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/isablog/default.aspx"&gt;ISA Server Product Team Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/network/bb545655.aspx"&gt;Routing and Remote Access TechCenter&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/network/bb545442.aspx"&gt;VPN TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;2.3.1 ISA 2006 VPN/QS&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/library/bb794723.aspx"&gt;VPN Concepts in ISA Server 2006 &lt;/a&gt;[UPD-08-04] &lt;p&gt;2.3.2 Win2003 RAS/IAS/QS&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/network/bb643123.aspx"&gt;IAS TechCenter&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/WindowsServer/en/library/d98eb914-258c-4f0b-ad04-dc4db9e4ee631033.mspx?mfr=true"&gt;Win2003 Remote Access Quarantine homepage&lt;/a&gt; [UPD-08-04] &lt;p&gt;2.3.3 Win2008 NPS&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/network/bb629414.aspx"&gt;Win2008 NPS TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;2.4 Wireless Security&lt;br&gt;(B) &lt;a href="http://blogs.msdn.com/wndp/default.aspx"&gt;Windows Core Networking Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/network/bb530679.aspx"&gt;Wireless Networking TechCenter&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/security/guidance/networksecurity/wirelsec.mspx"&gt;Wireless and Mobile Security: Technical Resources&lt;/a&gt; [UPD-08-04] &lt;p&gt;2.5 IPSEC, “Server &amp;amp; Domain Isolation” Solution&lt;br&gt;(B) &lt;a href="http://blogs.msdn.com/wndp/default.aspx"&gt;Windows Core Networking Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/network/bb531150.aspx"&gt;IPSEC TechCenter&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/network/bb545651.aspx"&gt;Server &amp;amp; Domain Isolation TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;2.6 Windows Firewall &lt;p&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/network/bb545423.aspx"&gt;Windows Firewall TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;&lt;b&gt;3.0 &lt;/b&gt;&lt;b&gt;Operating System Security &lt;/b&gt; &lt;p&gt;3.1 Client Operating System Security&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/securitytipstalk"&gt;Security Tips &amp;amp; Talk Blog&lt;/a&gt; [UPD-08-03] &lt;p&gt;3.1.1 Windows 2000 client security&lt;br&gt;(WP) &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=15e83186-a2c8-4c8f-a9d0-a0201f639a56&amp;amp;displaylang=en"&gt;Windows 2000 Hardening Guide&lt;/a&gt; [UPD-08-02] &lt;p&gt;3.1.2 Windows XP security&lt;br&gt;(WP) &lt;a href="http://go.microsoft.com/fwlink/?linkid=14840"&gt;Windows XP Security Guide&lt;/a&gt; [UPD-08-02] &lt;p&gt;3.1.3 Windows Vista security&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/windowsvistasecurity/"&gt;Windows Vista Security Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/windowsvista/aa905062.aspx"&gt;Windows Vista Security TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(WP) &lt;a href="http://go.microsoft.com/fwlink/?LinkId=74028"&gt;Windows Vista Security Guide&lt;/a&gt; [UPD-08-02]&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/wga/default.aspx"&gt;Windows Genuine Advantage Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/genuine/"&gt;Genuine Microsoft Software&lt;/a&gt;&lt;br&gt;(WP) &lt;a href="http://www.microsoft.com/protect/promotions/us/wga_idc_us.mspx"&gt;IDC Study: The risks of obtaining and using pirated software&lt;/a&gt; &lt;p&gt;3.2 Server Operating System Security&lt;br&gt;(B) &lt;a href="http://blogs.technet.com/windowsserver/default.aspx"&gt;Windows Server Team Blog&lt;/a&gt; &lt;p&gt;3.2.1 Windows 2000 Server security&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/security/prodtech/Windows2000.mspx"&gt;Windows Server 2000 Security TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(WP) &lt;a href="http://go.microsoft.com/fwlink/?LinkId=14838"&gt;Securing Windows 2000 Server&lt;/a&gt; [UPD-08-02] &lt;p&gt;3.2.2 Windows Server 2003 security&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver/en/technologies/featured/gensec/default.mspx"&gt;Windows Server 2003 Security TechCenter&lt;/a&gt; [UPD-08-04]&lt;br&gt;(WP) &lt;a href="http://go.microsoft.com/fwlink/?LinkId=14846"&gt;Windows Server 2003 Security Guide&lt;/a&gt; [UPD-08-02] &lt;p&gt;3.2.3 Windows Server 2008 security&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/e7e522ac-b32f-42e1-b914-53ccc78d18161033.mspx?mfr=true"&gt;Win2008 Security &amp;amp; Protection TechCenter&lt;/a&gt; [UPD-08-04]&lt;br&gt;(WP) &lt;a href="http://technet.microsoft.com/en-us/library/cc264463.aspx"&gt;Windows Server 2008 Security Guide&lt;/a&gt; [UPD-08-04]&lt;br&gt;(BK) &lt;a href="http://www.microsoft.com/MSPress/books/11160.aspx"&gt;Windows Server® 2008 Networking and Network Access Protection (NAP)&lt;/a&gt;&lt;br&gt;(BK) &lt;a href="http://www.microsoft.com/MSPress/books/9549.aspx"&gt;Windows Server® 2008 PKI and Certificate Security&lt;/a&gt; &lt;p&gt;3.3 Windows Mobile Security&lt;br&gt;(B) &lt;a href="http://blogs.msdn.com/windowsmobile/default.aspx"&gt;Windows Mobile Team Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/windowsmobile/enterprise/security.mspx"&gt;Device Management &amp;amp; Data Security&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/security/guidance/networksecurity/wirelsec.mspx"&gt;Wireless and Mobile Security: Technical Resources&lt;/a&gt; [UPD-08-04]  &lt;p&gt;3.4 Server &amp;amp; Desktop Virtualization Security&lt;br&gt;(B) &lt;a href="http://blogs.technet.com/virtualization/"&gt;Windows Virtualization Team Blog&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/virtualization/default.aspx"&gt;Virtualization TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;3.5 Anti-Malware Solutions (for systems)&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/antimalware/default.aspx"&gt;Anti-Malware Engineering Team&lt;/a&gt; &lt;p&gt;3.5.1 Windows Defender&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/windows/products/winfamily/defender/default.mspx"&gt;Windows Defender homepage&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/windows/aa905112.aspx"&gt;Windows Defender TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;3.5.2 Forefront Client Security&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/clientsecurity/"&gt;Microsoft Forefront Client Security Team Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/clientsecurity/default.aspx"&gt;Forefront Client Security TechCenter&lt;/a&gt; [UPD-08-01]  &lt;p&gt;3.5.2.1Forefront “Stirling”&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/stirling"&gt;Forefront Stirling Blog&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/stirling/default.aspx"&gt;Forefront &amp;quot;Stirling&amp;quot; TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;3.5.3 Windows Live OneCare&lt;br&gt;(W3) &lt;a href="http://onecare.live.com/standard/en-us/default.htm"&gt;Windows Live OneCare homepage&lt;/a&gt; [UPD-08-04] &lt;br&gt;(SB) &lt;a href="http://windowsonecare.spaces.live.com/"&gt;Windows Live OneCare Team Blog&lt;/a&gt;&lt;br&gt;(SB) &lt;a href="http://safetycenter.spaces.live.com/"&gt;Windows Live Safety Center Team Blog&lt;/a&gt;&lt;br&gt;(SB) &lt;a href="http://familysafety.spaces.live.com/"&gt;Windows Live OneCare Family Safety Blog&lt;/a&gt; &lt;p&gt;&lt;b&gt;4.0 &lt;/b&gt;&lt;b&gt;Application Security&lt;/b&gt; &lt;p&gt;4.1 Application &amp;amp; Platform Core Security&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/sdl/"&gt;The Security Development Lifecycle Blog&lt;/a&gt;&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/threatmodeling/"&gt;Microsoft Application Threat Modeling Blog&lt;/a&gt;&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/ace_team/"&gt;ACE Team (Security, Performance, and Privacy) Blog&lt;/a&gt;&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/hackers/"&gt;&amp;quot;%41%43%45%20%54%65%61%6d&amp;quot; Blog&lt;/a&gt; &lt;p&gt;4.2 Client Applications Security &lt;p&gt;4.2.1 Office Security&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/security/prodtech/Office.mspx"&gt;Office Security TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(B) &lt;a href="http://office.microsoft.com/en-us/help/FX102376791033.aspx"&gt;Microsoft Office Team Blogs&lt;/a&gt; &lt;p&gt;4.2.1.1Previous versions: Office 2000, Office XP&lt;br&gt;(WP) &lt;a href="http://www.microsoft.com/technet/prodtechnol/office/office2003/operate/o3secdet.mspx"&gt;Office 2003 Security Whitepaper&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.2.1.2Office 2007 Security&lt;br&gt;(WP) &lt;a href="http://go.microsoft.com/fwlink/?LinkId=95736"&gt;2007 Microsoft Office Security Guide&lt;/a&gt; [UPD-08-02] &lt;p&gt;4.2.2 Internet Explorer Security&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/ie/default.aspx"&gt;Internet Explorer TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(B) &lt;a href="http://blogs.msdn.com/ie"&gt;Internet Explorer Team Blog&lt;/a&gt; &lt;p&gt;4.2.2.1Previous versions: IE 6.0 &lt;br&gt;(WP) &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=E550F940-37A0-4541-B5E2-704AB386C3ED&amp;amp;displaylang=en"&gt;Understanding Security in IE 6 in Windows XP SP2&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.2.2.2IE 7.0 Security&lt;br&gt;(WP) &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=6aa4c1da-6021-468e-a8cf-af4afe4c84b2&amp;amp;DisplayLang=en"&gt;IE 7 Desktop Security Guide&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.2.2.3IE 8.0 Security&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/windows/products/winfamily/ie/ie8/default.mspx"&gt;Internet Explorer 8 beta 1 homepage&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.2.3 Instant Messaging Security&lt;br&gt;(WP) &lt;a href="http://download.microsoft.com/download/4/8/6/4867a6c9-701a-4d4a-b1c6-85d9235c2ca3/Security_Considerations_for_IM.doc"&gt;Security Considerations for Instant Messaging in the Workplace&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.2.3.1Windows Live Messenger Security&lt;br&gt;(B) &lt;a href="http://messengersays.spaces.live.com/"&gt;Windows Live Messenger Team Blog&lt;/a&gt; &lt;p&gt;4.2.3.2Office Communicator 2007 Security&lt;br&gt;(B) &lt;a href="http://communicatorteam.com/default.aspx"&gt;Microsoft Office Communicator Team Blog&lt;/a&gt; &lt;p&gt;4.3 Server Applications Security &lt;p&gt;4.3.1 Exchange Security&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/exchange/default.aspx"&gt;Exchange Server TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(B) &lt;a href="http://msexchangeteam.com/"&gt;Microsoft Exchange Team Blog&lt;/a&gt; &lt;p&gt;4.3.1.1Previous versions: Exchange 2000, Exchange 2003 Security&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/library/bb123630(EXCHG.65).aspx"&gt;Exchange Server 2003 Security TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.1.2Exchange 2007 Security&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/library/aa996775(EXCHG.80).aspx"&gt;Exchange Server 2007 Security TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.2 SQL Security&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/sqlserver/default.aspx"&gt;SQL Server TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/security/prodtech/sQLserver.mspx"&gt;SQL Server Security TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(B) &lt;a href="http://blogs.msdn.com/sqlblog/"&gt;Microsoft SQL Server Support Blog&lt;/a&gt; &lt;p&gt;4.3.2.1Previous versions: SQL 2000 Security&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/prodtechnol/sql/2000/maintain/sp3sec04.mspx"&gt;Checklist: Securing SQL Server 2000&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.2.2SQL 2005 Security&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/sqlserver/bb331769.aspx"&gt;SQL Server 2005 Security TechCenter&lt;/a&gt; [UPD-08-04]  &lt;p&gt;4.3.2.3SQL 2008 Security&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/sqlserver/2008/en/us/security.aspx"&gt;SQL Server 2008 Security homepage&lt;/a&gt; [UPD-08-04] &lt;br&gt;(WP) &lt;a href="http://download.microsoft.com/download/a/c/d/acd8e043-d69b-4f09-bc9e-4168b65aaa71/SQL2008SecurityOverviewforAdmins.docx"&gt;SQL Server 2008 Security overview for DB administrators&lt;/a&gt; [UPD-08-04]  &lt;p&gt;4.3.3 IIS Security&lt;br&gt;(B) &lt;a href="http://blogs.iis.net/"&gt;IIS.net Blogs&lt;/a&gt; &lt;p&gt;4.3.3.1Previous versions: IIS 5.0 Security&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/security/prodtech/IIS.mspx"&gt;IIS Security Guidance&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.3.2IIS 6.0 Security&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver/en/library/ace052a0-a713-423e-8e8c-4bf198f597b81033.mspx?mfr=true"&gt;Security in IIS 6.0&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver/en/library/ace052a0-a713-423e-8e8c-4bf198f597b81033.mspx?mfr=true"&gt;Securing Web Sites and Applications&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.3.3IIS 7.0 Security&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/939d621e-c023-48f8-9503-47f24a6be7211033.mspx?mfr=true"&gt;IIS 7.0: Configure Web Server Security&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.4 Sharepoint Security&lt;br&gt;(B) &lt;a href="http://blogs.msdn.com/sharepoint/"&gt;Microsoft Office SharePoint Server Team Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/office/sharepointserver/default.aspx"&gt;MOSS TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.4.1Microsoft Office Sharepoint Server (MOSS) 2007&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/library/cc263215.aspx"&gt;MOSS Security TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.5 Unified Communications Solutions&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/uc/default.mspx"&gt;Unified Communications homepage&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.5.1 Office Communications Server (OCS) 2007 Security&lt;br&gt;(B) &lt;a href="http://communicationsserverteam.com/default.aspx"&gt;Microsoft Office Communications Server Team Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/office/ocs/default.aspx"&gt;OCS TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.3.6 Application Virtualization Security&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/appvirtualization/default.aspx"&gt;Application Virtualization TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.4 Anti-Malware Solutions (for Server applications)&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/antimalware/default.aspx"&gt;Anti-Malware Engineering Team&lt;/a&gt; &lt;p&gt;4.4.1 Forefront Server Security&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/fss/default.aspx"&gt;Microsoft Forefront Server Security Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/serversecurity/default.aspx"&gt;Forefront Server Security TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;4.4.1.1Microsoft Antigen&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/serversecurity/bb772732.aspx"&gt;Antigen TechCenter&lt;/a&gt; [UPD-08-01] &lt;p&gt;4.4.1.2Forefront Security for Exchange (Exchange 2007)&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/serversecurity/bb734822.aspx"&gt;Forefront Security for Exchange TechCenter&lt;/a&gt; [UPD-08-01]  &lt;p&gt;4.4.1.3Forefront Security for Office Communications Server&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/serversecurity/cc514240.aspx"&gt;Forefront Security for OCS TechCenter&lt;/a&gt; [UPD-08-04]  &lt;p&gt;4.4.1.4Forefront Security for Sharepoint (Office SharePoint Server 2007 and Microsoft Windows SharePoint Services 3.0)&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/serversecurity/bb734828.aspx"&gt;Forefront Security for Sharepoint TechCenter&lt;/a&gt; [UPD-08-01] &lt;p&gt;4.4.1.5Forefront “Stirling”&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/stirling"&gt;Forefront Stirling Blog&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/forefront/stirling/default.aspx"&gt;Forefront &amp;quot;Stirling&amp;quot; TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;&lt;b&gt;5.0 &lt;/b&gt;&lt;b&gt;User Security&lt;/b&gt; &lt;p&gt;5.1 Identity &amp;amp; Access Solutions&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/windowsserver2008/en/us/ida-home.aspx"&gt;Microsoft Identity &amp;amp; Access Solutions homepage&lt;/a&gt; [UPD-08-04] &lt;p&gt;5.1.1 Directory Services Security&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/246aa651-6858-4dc9-aade-6806065d0ea21033.mspx?mfr=true"&gt;Active Directory Domain Services (AD DS) in Win2008 TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/b7fb96ec-3f3f-4860-a1ab-eb43e54bbefc1033.mspx?mfr=true"&gt;Active Directory Lightweight Directory Services (AD LDS) in Win2008 TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/windowsserver/grouppolicy/default.aspx"&gt;Group Policy TechCenter&lt;/a&gt; [UPD-08-04]&lt;br&gt;(B) &lt;a href="http://blogs.technet.com/askds/"&gt;Ask the Directory Services Team blog&lt;/a&gt; [UPD-08-04] &lt;br&gt;(B) &lt;a href="http://blogs.technet.com/ad"&gt;Tim Springston’s Active Directory blog&lt;/a&gt; [UPD-08-03]  &lt;p&gt;5.1.2 Identity Lifecycle Manager (ILM) 2007&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/ILM/en/library/a4d5346d-418c-497c-bbab-ff49e94e982b1033.mspx?mfr=true"&gt;ILM 2007 TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;5.1.3 Active Directory Federation Services (AD FS)&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/ea38b9d3-5d81-45b7-b533-8b5e45b783fb1033.mspx?mfr=true"&gt;Active Directory Federation Services (AD FS) in Win2008 TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;5.1.4 Certificate Services and SmartCard&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/029151ce-13f5-44a9-9767-8d3f65b823d81033.mspx?mfr=true"&gt;Active Directory Certification Services (AD CS) in Win2008 TechCenter&lt;/a&gt; [UPD-08-04] &lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/pki/default.aspx"&gt;Windows PKI blog&lt;/a&gt;&lt;br&gt;(SB) &lt;a href="http://blogs.msdn.com/shivaram"&gt;SmartCard Infrastructure Blog&lt;/a&gt;&lt;br&gt;(BK) &lt;a href="http://www.microsoft.com/MSPress/books/9549.aspx"&gt;Windows Server® 2008 PKI and Certificate Security&lt;/a&gt; &lt;p&gt;&lt;b&gt;&lt;/b&gt; &lt;p&gt;&lt;b&gt;6.0 &lt;/b&gt;&lt;b&gt;Data Security &lt;/b&gt; &lt;p&gt;6.1 Data Encryption solutions&lt;br&gt;(WP) &lt;a href="http://www.microsoft.com/technet/security/guidance/clientsecurity/dataencryption/default.mspx"&gt;The Data Encryption toolkit for Mobile PCs&lt;/a&gt; [UPD-08-04] &lt;p&gt;6.1.1 Encrypting File System (EFS)&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/security/guidance/cryptographyetc/efs.mspx"&gt;The Encrypted File System&lt;/a&gt; [UPD-08-04] &lt;p&gt;6.1.1.1Previous versions: EFS in Win2000, WinXP, Win2003&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/library/bb457065.aspx"&gt;EFS in WinXP and Win2003&lt;/a&gt; [UPD-08-04] &lt;p&gt;6.1.1.2EFS in Windows Vista &amp;amp; Windows Server 2008&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/f843023b-bedd-40dd-9e5b-f1619eebf7821033.mspx?mfr=true"&gt;EFS in Win2008&lt;/a&gt; [UPD-08-04] &lt;p&gt;6.1.2 BitLocker&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/windowsvista/aa905065.aspx"&gt;BitLocker TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;6.2 Policy Enforcement solutions &lt;p&gt;6.2.1 Rights Management Server (RMS)&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/rmssupp/default.aspx"&gt;RMS: Protecting Your Assets.&lt;/a&gt; &lt;p&gt;6.2.1.1RMS in Windows Server 2003&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver/en/technologies/featured/rms/default.mspx"&gt;RMS in Win2003 TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;6.2.1.2RMS in Windows Server 2008&lt;br&gt;(W3) &lt;a href="http://technet2.microsoft.com/windowsserver2008/en/library/37c240d3-8928-4267-867b-4c005b72cca21033.mspx?mfr=true"&gt;RMS in Win2008 TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;6.3 Privacy Enhancing Technologies (PET)&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/privacyimperative/"&gt;The Data Privacy Imperative&lt;/a&gt; &lt;p&gt;6.3.1 Privacy Enhancements in Windows XP SP2 &lt;br&gt;(WP) &lt;a href="http://go.microsoft.com/fwlink/?LinkId=78326"&gt;Controlling Internet Communications in WinXP SP2&lt;/a&gt; [UPD-08-04] &lt;p&gt;6.3.2 Privacy Enhancements in Windows Vista&lt;br&gt;(WP) &lt;a href="http://www.microsoft.com/windowsvista/privacy/vistartm_full.mspx"&gt;Windows Vista Privacy Statement&lt;/a&gt; [UPD-08-04] &lt;br&gt;(WP) &lt;a href="http://go.microsoft.com/fwlink/?LinkId=78326"&gt;Controlling Internet Communications in Windows Vista&lt;/a&gt; [UPD-08-04] &lt;p&gt;&lt;b&gt;7.0 &lt;/b&gt;&lt;b&gt;Security Foundations – Technology&lt;/b&gt; &lt;p&gt;7.1 Security Update &amp;amp; Compliance Management solutions&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/msrc/"&gt;Microsoft Security Response Center&lt;/a&gt;&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/swi/default.aspx"&gt;Security Vulnerability Research &amp;amp; Defense&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/updatemanagement/default.aspx"&gt;Update Management TechCenter&lt;/a&gt; [UPD-08-04]&lt;br&gt;(SB) &lt;a href="http://blogs.technet.com/secguide/default.aspx"&gt;Solution Accelerators - Security &amp;amp; Compliance&lt;/a&gt;&lt;b&gt;&lt;/b&gt; &lt;p&gt;7.1.1 Windows Update, Microsoft Update &amp;amp; Automatic Update Agent&lt;br&gt;(B) &lt;a href="http://blogs.technet.com/mu/"&gt;Microsoft Update Team Blog&lt;/a&gt; &lt;p&gt;7.1.2 WSUS&lt;br&gt;(B) &lt;a href="http://blogs.technet.com/wsus/default.aspx"&gt;WSUS Product Team Blog&lt;/a&gt;&lt;br&gt;(B) &lt;a href="http://blogs.technet.com/sus/"&gt;WSUS Support Team Blog&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/wsus/default.aspx"&gt;WSUS TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;7.1.3 SMS &amp;amp; System Center Configuration Manager&lt;br&gt;(B) &lt;a href="http://blogs.technet.com/smsandmom/default.aspx"&gt;SMS &amp;amp; MOM Product Team Blog&lt;/a&gt; [UPD-08-04] &lt;p&gt;7.1.3.1 SMS 2003&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/sms/default.aspx"&gt;System Management Server 2003 TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;7.1.3.2 System Center Configuration Manager 2007 &lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/configmgr/default.aspx"&gt;System Center Configuration Manager 2007 TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;7.1.4 Microsoft Baseline Security Analyzer&lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/technet/security/tools/mpsa.mspx"&gt;MBSA homepage&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/security/cc184923.aspx"&gt;MBSA 2.1 homepage&lt;/a&gt; [UPD-08-04] &lt;p&gt;7.2 Security Monitoring &amp;amp; Auditing Solutions &lt;p&gt;7.2.1 System Center Operations Manager 2007 &lt;br&gt;(B) &lt;a href="http://blogs.technet.com/momteam/default.aspx"&gt;Operations Manager Product Team Blog&lt;/a&gt;&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/opsmgr/default.aspx?wt.svl=mom"&gt;System Center Operations Manager TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;7.3 Systems Management Solutions &lt;p&gt;7.3.1 System Center &lt;br&gt;(W3) &lt;a href="http://www.microsoft.com/systemcenter/en/us/default.aspx"&gt;System Center homepage&lt;/a&gt; [UPD-08-04] &lt;br&gt;(B) &lt;a href="http://blogs.technet.com/systemcenter/default.aspx"&gt;Nexus SC: The System Center Team Blog&lt;/a&gt; [UPD-08-04]&lt;br&gt;(W3) &lt;a href="http://technet.microsoft.com/en-us/systemcenter/default.aspx"&gt;System Center TechCenter&lt;/a&gt; [UPD-08-04] &lt;p&gt;7.4 Hardware &amp;amp; Physical Security &lt;p&gt;7.4.1 Physical Security&lt;br&gt;(WP) &lt;a href="http://technet.microsoft.com/en-us/library/cc537553.aspx"&gt;Physical Security at Microsoft&lt;/a&gt; [UPD-08-04] &lt;p&gt;7.4.2 Trusted Platform Module (TPM)&lt;br&gt;See Bitlocker topic. &lt;p&gt;&lt;b&gt;8.0 &lt;/b&gt;&lt;b&gt;Security Foundation – Processes&lt;/b&gt;&lt;br&gt;(B) &lt;a href="http://blogs.technet.com/mof/default.aspx"&gt;MOF and Service Management at Microsoft&lt;/a&gt; &lt;p&gt;8.1 Organizational Security &amp;amp; Policies &lt;p&gt;8.2 Operational Security &amp;amp; Procedures &lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Microsoft+Security+Taxonomy+2.0&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!209.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!209.entry</guid><pubDate>Tue, 08 Jul 2008 09:47:24 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!209/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!209.entry#comment</wfw:comment><dcterms:modified>2008-07-08T09:47:24Z</dcterms:modified></item><item><title>Cisco, IBM, Intel, Juniper and Microsoft fight cyber terror together</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!207.entry</link><description>&lt;span style="font-size:11pt;font-family:'Calibri','sans-serif'"&gt;Five major network hardware, software and services vendors are &lt;a href="http://www.networkworld.com/community/node/29380"&gt;banding together to improve IT security&lt;/a&gt; by promoting faster responses to threats. &lt;br&gt;&lt;br&gt;Industry Consortium for Advancement of Security on the Internet (ICASI) is a nonprofit organization created by &lt;a href="http://www.networkworld.com/subnets/cisco/"&gt;Cisco&lt;/a&gt;, &lt;a href="http://www.networkworld.com/news/financial/ibm.html"&gt;IBM&lt;/a&gt;, &lt;a href="http://www.networkworld.com/news/financial/intel.html"&gt;Intel&lt;/a&gt; , &lt;a href="http://www.networkworld.com/news/financial/juniper.html"&gt;Juniper&lt;/a&gt; and &lt;a href="http://www.networkworld.com/subnets/microsoft/"&gt;Microsoft&lt;/a&gt; to address what it calls multi-product security threats. &lt;br&gt;&lt;br&gt;The companies say ICASI will let vendors and customers work together on global IT security threats and resolve them in a government-neutral way. Last month, a group of countries banded together to create the International Multilateral Partnership Against Cyber Terrorism (&lt;a href="http://www.networkworld.com/news/2008/051308-us13-million-grant-approved-to.html"&gt; IMPACT&lt;/a&gt;), funded by private businesses as well as governments and based in Malaysia. The center is to offer emergency response, training and other resources. &lt;br&gt;&lt;br&gt;“To date there has not been a trusted vendor environment that allows companies to identify, assess, and mitigate multi-product, global security challenges together on the customers' behalf,” the group says in a statement. “ICASI aims to fill this void.” Related Content &lt;br&gt;&lt;br&gt;ICASI will target “global, multivendor cyber threats” to reduce their impact on end users. The group’s statement says these attacks target multiple products or protocols in products, giving them a broader impact. These attacks pose problems not only for end user customers, but also for vendors, the group says. &lt;br&gt;&lt;br&gt;By working together the vendors hope to block this class of threat more quickly and blunt their effects on the security of customer networks. To that end, ICASI will develop efficient and effective practices for responding to these threats. &lt;br&gt;&lt;br&gt;The hope is that with the group creating a forum of trust among members, they will share critical data about specific attacks more readily and thwart them more quickly. ICASI says it wants to set security response standards that it can share with the industry in general. &lt;br&gt;&lt;br&gt;ICASI’s statement says it may work with other firms committed to similar goals, but does not say whether they will be full members. &lt;br&gt;&lt;br&gt;Formation of the group was announced at the FIRST Conference in Vancouver for IT incident-response and security teams.&lt;br style=""&gt;&lt;br style=""&gt; &lt;p&gt;&lt;em&gt;This story appeared on Network World at&lt;br&gt;&lt;/em&gt;&lt;a href="http://www.networkworld.com/news/2008/062707-icasi-cyber-terror.html"&gt;&lt;em&gt;http://www.networkworld.com/news/2008/062707-icasi-cyber-terror.html&lt;/em&gt;&lt;/a&gt;&lt;/span&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Cisco%2c+IBM%2c+Intel%2c+Juniper+and+Microsoft+fight+cyber+terror+together&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!207.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!207.entry</guid><pubDate>Tue, 08 Jul 2008 06:30:29 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!207/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!207.entry#comment</wfw:comment><dcterms:modified>2008-07-08T06:30:29Z</dcterms:modified></item><item><title>Security virtual labs at HELLO SECURE WORLD</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!205.entry</link><description>&lt;p&gt;Check out the latest (but not so recent) Virtual labs, Videos and more &lt;p&gt;&lt;a href="http://www.microsoft.com/click/hellosecureworld/default.mspx"&gt;http://www.microsoft.com/click/hellosecureworld/default.mspx&lt;/a&gt; &lt;p&gt;I'm not a developer, so XSS really doesn't interest me. Videos are cool, but I've seen better.  &lt;p&gt;It's running on &lt;a href="www.microsoft.com/silverlight" target="_blank"&gt;Silver Light&lt;/a&gt;, so do install it, else you won't be able to access the content.  &lt;p&gt;To run the lab, you will also need to install (risky and dangerous) ActiveX. Pop-up blocker must also be disabled.  &lt;p&gt;  &lt;p&gt;So, what's in the virtual lab? &lt;ul&gt; &lt;li&gt;Cross Site Scripting &lt;li&gt;SQL Injection&lt;/ul&gt; &lt;p&gt;  &lt;p&gt;There's also links to MS Dev blog,like Steve Riley and Kai Axford.&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Security+virtual+labs+at+HELLO+SECURE+WORLD&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><category>Computer and Internet</category><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!205.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!205.entry</guid><pubDate>Wed, 18 Jun 2008 06:53:06 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!205/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!205.entry#comment</wfw:comment><dcterms:modified>2008-06-18T06:53:06Z</dcterms:modified></item><item><title>Security Videos - Securitytube.net</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!201.entry</link><description>&lt;p&gt;  &lt;p&gt;&lt;font face=Arial size=3&gt;When it comes to Security, nothing beats classroom training. However, if cost is a hurdle, you may want to check out security videos on Securitytube.net. It's a library of security videos presented by h8x0r and security consultants alike. Like &lt;a href="http://www.youtube.com" target="_blank"&gt;Youtube&lt;/a&gt;&lt;/font&gt; &lt;font face=Arial size=3&gt;but focuses on security.&lt;/font&gt; &lt;p&gt;&lt;font face=Arial size=3&gt;My personal favorite:&lt;/font&gt; &lt;p&gt; &lt;div style="padding-right:0px;display:inline;padding-left:0px;padding-bottom:0px;margin:0px;padding-top:0px"&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt; &lt;p&gt; History of Hacking Series Part  1 &lt;p&gt;&lt;font face=Arial size=3&gt;Tons of Security related videos. Check it out!&lt;/font&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Security+Videos+-+Securitytube.net&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!201.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!201.entry</guid><pubDate>Fri, 06 Jun 2008 12:57:46 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!201/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!201.entry#comment</wfw:comment><dcterms:modified>2008-06-06T12:57:46Z</dcterms:modified></item><item><title>Data Wiping Tool - Derik's Boot and Nuke</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!200.entry</link><description>&lt;p&gt;        &lt;font face=Arial color="#000000" size=3&gt;So I have discuss extensively on Full Disk Encryption,protecting your data that is residing in storage,be it USB or Hard Disk etc. But what if the data has reach its end-of-life, what do you do with a server or computer that no longer serve its purpose and is to be discarded? Unless the data is encrypted, then it could just be discarded. However, encryption is still considered a 'luxury' or an 'ideal' for many. &lt;/font&gt; &lt;p&gt;&lt;font face=Arial color="#000000" size=3&gt;       In my beloved country of mine, Malaysia, there is no Data Privacy Law. For the Financial Institution which is governed by the Bank Negara, in all of the IT Guideline, there is no chapter of 'Data Sanitization. Banks,Insurance companies with old pc may simply sell of their out dated PC's,servers with the hard disk intact without sanitizing the data first.&lt;/font&gt; &lt;p&gt;&lt;font face=Arial color="#000000" size=3&gt;       Knowing this, my response was to introduce a policy of &lt;strong&gt;'Data Wiping'&lt;/strong&gt; to my previous company. I included a chapter in the companies 'Information Security Policy', that required all desktop,server,storage devices to be sanitized prior to decommissioning. The policy I introduced also covered vendors,contractors etc which did business with my company. This also includes sanitizing computers and servers which my company used during our annual Disaster Recovery Test;which is usually conducted at a vendor's premises. &lt;/font&gt; &lt;p&gt;&lt;font face=Arial color="#000000" size=3&gt;      The tool I have used before is a no-brainer, simple to use, require no installation and best of all, for a IT Department on tight budget or the curse of having a Scrooge for CIO. Its called &lt;strong&gt;Darik (the creator) Boot and Nuke&lt;/strong&gt;. The name says it all, boot up the desktop,laptop or server you intent to wipe, and nuke (wipe) it. You need to download the iso image, either burn it to a DVD,USB or a 3.5 floppy. The image will be loaded up when the system is boot up and a menu will allow you to choose the format of wiping, either a DoD (US Defense Department, RCMP (Royal Canadian Mounted Police),Guttman etc.&lt;/font&gt;  &lt;p&gt;    &lt;a href="http://blu1.storage.msn.com/y1pY0NNtWyQ_Cs4ZN-VAdMY5VUIOBDsq7tooraqt4FYOWGTyM0YZwRrVDY7QQzRBJ1WmT9QqU2jT7CHuf1AVXfMZYXnU1H7moCR?PARTNER=WRITER"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" height=210 alt="ss 1" src="http://blu1.storage.msn.com/y1pY0NNtWyQ_CvnLG_6hQx7wsfbktxi7-WTqnzteezdp_g4C_sckVFCXnAkWAnqo8ExUGsB2SHW1hRjvrZ5BPfFX8auwo6ciS5d?PARTNER=WRITER" width=244 border=0&gt;&lt;/a&gt;  Extractor &lt;p&gt;    &lt;a href="http://txxujw.blu.livefilestore.com/y1plDwUW6l9Ls3ohwDOe8C_QO5N8xJggbf5oGQxgzrtnvzTIFffLKe4AhUstpPNeMPH-ElvW2f16390UqDKJKYUEnKxvGomNzL-?PARTNER=WRITER"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" height=138 alt="screenshot 4" src="http://blu1.storage.msn.com/y1pY0NNtWyQ_CseXE6rL7zBW0QFr_UgL_70kBCNhlDEDRT3WRBl2SuUATjdyMFIYCmG_aFZBDrrnzDE30oHBj1QAQmd-fDiFS0D?PARTNER=WRITER" width=244 border=0&gt;&lt;/a&gt; Starting screen &lt;p&gt;  &lt;p&gt;    &lt;a href="http://txxujw.blu.livefilestore.com/y1plDwUW6l9Ls2wnXoAtUGH-VtpA0vXlY_2TV3FzplN3phDIZgMnpRNZvtj1T4EO9rhuHChMmeCLZ6gO0zHFuNYWj0FZ82BmFe-?PARTNER=WRITER"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" height=138 alt="screenshot 2" src="http://blu1.storage.msn.com/y1pY0NNtWyQ_CupIn_4mNhgG1KizbSQx-bxvzqF3nMYNdjvKRRSfw67ipWQ-RYcVprNLahJzc-gxJFuWS4JzDAURBAqfeqQyZqq?PARTNER=WRITER" width=244 border=0&gt;&lt;/a&gt; Choosing wiping method &lt;p&gt;    &lt;a href="http://txxujw.blu.livefilestore.com/y1plDwUW6l9Ls087otIRqKJ6LGqOJtfDKfEObxY8Qag_2096MUxxWBH5Xo9Q5kAx16VxLTftFU7HgUG4Tbc2SyIARA-T1Uvpo7q?PARTNER=WRITER"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" height=138 alt="screenshot 3" src="http://blu1.storage.msn.com/y1pY0NNtWyQ_CuCwaWh2OYFxjzSf5VoIvf3izeTbhm4IfEwU55IXnti5BiGXIAZXQABhG3nAe26Z6wG2QW-TTiXQaQfVKpSb4eu?PARTNER=WRITER" width=244 border=0&gt;&lt;/a&gt; Selecting drive to be wiped &lt;p&gt;    &lt;a href="http://txxujw.blu.livefilestore.com/y1plDwUW6l9Ls3p9svb5iOEtUeNk6OxHLWJdzwQ9RioxDJqSSmZtq97Zf6no10yZ7kex8nAYjrcoSYpPgD5bSyzXbFqaJYmWNX9?PARTNER=WRITER"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" height=138 alt="screenshot 5" src="http://blu1.storage.msn.com/y1pY0NNtWyQ_CsjUBOzA2YJqj7oFI0qmZDGcPIBhTMKPRNgwX08l2FqYqdtEIXlmHHWLtBuZby7-TUxZfsm5_NX72WOTO5itZD9?PARTNER=WRITER" width=244 border=0&gt;&lt;/a&gt; Wiping in action &lt;p&gt;    &lt;a href="http://txxujw.blu.livefilestore.com/y1plDwUW6l9Ls2vWs_O_NLJI4i6NL6nfA1BZOFITzMf1QxvLm6-vSWnWXil0ftN7vk5z9ydxEtWgA46ozaADtbC7jQnn6nLSiFW?PARTNER=WRITER"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px" height=138 alt="screenshot 6" src="http://blu1.storage.msn.com/y1pY0NNtWyQ_Cuzzm-OtsdVYDiCQeMUuvlLrgDFDdCI2tNProRlJf9EAndNIdSWnzGETqsLldiPOXbiajldwg1JS73SbzKsPl85?PARTNER=WRITER" width=244 border=0&gt;&lt;/a&gt; Success &lt;p&gt;&lt;font face=Arial size=3&gt;The tool is not only restricted for organization, however individuals who are aware and concern about their privacy. Before you sell that old piece of hard disk on Ebay or Lelong.com.my, be sure the wipe it clean. &lt;/font&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Data+Wiping+Tool+-+Derik's+Boot+and+Nuke&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!200.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!200.entry</guid><pubDate>Fri, 06 Jun 2008 12:24:50 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!200/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!200.entry#comment</wfw:comment><dcterms:modified>2008-06-06T12:24:50Z</dcterms:modified></item><item><title>Malaysian Prime Minister Official Website Defaced</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!177.entry</link><description>&lt;div&gt;&lt;font size=3&gt;      &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size=3&gt;    So the goverment finally decided to raise the petrol price for Malaysians. Apart from causing massive traffic jams around the nation, the decision has also drawn  protest from the undeground world. The Malaysian's PM Official website has just been defaced. I did save the print screen. Here's the link. &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font size=3&gt;&lt;/font&gt; &lt;/div&gt;
&lt;div&gt;&lt;a href="http://www.pmo.gov.my/website/webdbase.nsf/w_4?openForm&amp;amp;url=http://www.geocities.com/nmapx/manifesto.txt" target="_blank"&gt;PMO Defaced&lt;/a&gt;&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;      &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Malaysian+Prime+Minister+Official+Website+Defaced&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><category>Computers and Internet</category><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!177.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!177.entry</guid><pubDate>Thu, 05 Jun 2008 06:03:45 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!177/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!177.entry#comment</wfw:comment><dcterms:modified>2008-06-05T06:03:45Z</dcterms:modified></item><item><title>Feds encrypt 800,000 laptops; 1.2 million to go</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!172.entry</link><description>&lt;div&gt;&lt;font color="#ffff00"&gt;     A proactive move by the US Goverment. Private sector in the US has long mandated the use of FDE for laptops. The US goverment recieved up to 80% discount from FDE vendors for the initiave. My only hope that my local goverment and even local private sector follows this proactive informtion protection effort. &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font color="#ffff00"&gt;&lt;/font&gt; &lt;/div&gt;
&lt;div&gt;&lt;font color="#ffff00"&gt;&lt;/font&gt; &lt;/div&gt;
&lt;div&gt;&lt;font color="#ffff00"&gt;An excerpt from Infoworld:&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font color="#ffff00"&gt;&lt;br clear=all&gt;
&lt;p&gt;U.S. government agencies are scrambling to plug one of their biggest security holes: sensitive information -- names, addresses and Social Security numbers, for example -- stored on laptops, handhelds, and thumb drives.
&lt;p&gt;
&lt;table align=right&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;

&lt;a href="http://ad.doubleclick.net/jump/idg.us.info.print_this/printThis;pos=imu;pkey=application_development;pkey=applications;pkey=business;pkey=data_management;pkey=networking;pkey=hardware;pkey=platforms;pkey=professional_services;pkey=security;pkey=web_services;pkey=standards;pkey=storage;pkey=security;pkey=telecom;pkey=wireless;skey=application_servers;tile=4;sz=336x280;abr=!ie4;abr=!ie5;abr=!ie6;ord=6767042800294347?"&gt;&lt;img src="http://ad.doubleclick.net/ad/idg.us.info.print_this/printThis;pos=imu;pkey=application_development;pkey=applications;pkey=business;pkey=data_management;pkey=networking;pkey=hardware;pkey=platforms;pkey=professional_services;pkey=security;pkey=web_services;pkey=standards;pkey=storage;pkey=security;pkey=telecom;pkey=wireless;skey=application_servers;tile=4;sz=336x280;abr=!ie4;abr=!ie5;abr=!ie6;ord=6767042800294347?" width=336 height=280 border=0 alt=""&gt;&lt;/a&gt;&lt;br clear=all&gt;&lt;/tbody&gt;&lt;/table&gt;In the last year, agencies have purchased 800,000 licenses for encryption software through the federal Data at Rest (DAR) Encryption &lt;a href="http://www.gsa.gov/Portal/gsa/ep/contentView.do?programId=8399&amp;amp;channelId=-18846&amp;amp;ooid=22458&amp;amp;contentId=23207&amp;amp;pageTypeId=8169&amp;amp;contentType=GSA_BASIC&amp;amp;programPage=/ep/program/gsaBasic.jsp&amp;amp;P=SBUY" target="_blank"&gt;&lt;u&gt;&lt;font color="#000080"&gt;program&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;, which is run jointly by the General Services Administration and the U.S. Department of Defense.
&lt;p&gt;&amp;quot;Sales have been very brisk,&amp;quot; says Fred Schobert, CTO for integrated technology services at the General Services Administration's Federal Acquisition Service. &amp;quot;We've been somewhat overwhelmed.&amp;quot;
&lt;p&gt;The government's fast adoption rate of encryption software comes after numerous &lt;a href="http://www.networkworld.com/slideshows/2008/052208-laptop-losers.html?ts0hb=&amp;amp;story=wknd_laptop" target="_blank"&gt;&lt;u&gt;&lt;font color="#000080"&gt;headline-grabbing security breaches&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;. Laptop encryption has also been on the rise among corporations, including the likes of &lt;a href="http://www.networkworld.com/news/2008/011708-emc-cso.html" target="_blank"&gt;&lt;u&gt;&lt;font color="#000080"&gt;EMC&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; and &lt;a href="http://www.networkworld.com/news/2008/012908-ibm-encryption-deployment.html" target="_blank"&gt;&lt;u&gt;&lt;font color="#000080"&gt;IBM&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;.
&lt;p&gt;It's been two years since &lt;a href="http://www.networkworld.com/news/2006/080706-teens-charged-in-va-laptop.html" target="_blank"&gt;&lt;u&gt;&lt;font color="#000080"&gt;teens stole a laptop&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; from the home of a U.S. Department of Veterans' Affairs employee's home, putting at risk for identity theft a database of 26.5 million names and Social Security numbers for 26.5 million veterans and military personnel. 
&lt;p&gt;But this year alone, laptops with personally identifiable information have been stolen from Bolling Air Force Base, a Marine Corps base in Okinawa, Japan and the National Institutes of Health in Bethesda, Md. In all of these cases, data that wasn't encrypted on these laptops could have been used by thieves for identity theft, according to a list of known security breaches compiled by the Privacy Rights &lt;a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm" target="_blank"&gt;&lt;u&gt;&lt;font color="#000080"&gt;Web site&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;. &lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font color="#ffff00"&gt;&lt;a href="http://www.infoworld.com/archives/emailPrint.jsp?R=printThis&amp;amp;A=/article/08/05/23/Feds-encrypt-800000-laptops_1.html" target="_blank" rel=nofollow&gt;more here from InfoWorld&lt;/a&gt;&lt;/font&gt;&lt;/div&gt;
&lt;div&gt;&lt;font color="#ffff00"&gt;&lt;/font&gt; &lt;/div&gt;
&lt;div&gt;&lt;font color="#ffff00"&gt;&lt;/font&gt; &lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Feds+encrypt+800%2c000+laptops%3b+1.2+million+to+go&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><category>Hardware Security</category><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!172.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!172.entry</guid><pubDate>Mon, 26 May 2008 07:39:54 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!172/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!172.entry#comment</wfw:comment><dcterms:modified>2008-05-26T07:39:54Z</dcterms:modified></item><item><title>Server Lost during Renovation</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!151.entry</link><description>&lt;br style="color:rgb(255, 255, 0)"&gt;&lt;span style="color:rgb(255, 255, 0)"&gt;I know how easy it is to lose a laptop, that's so common. But how do you lose a server?&lt;/span&gt;&lt;br style="color:rgb(255, 255, 0)"&gt;&lt;span style="color:rgb(255, 255, 0)"&gt;HSBC stated that the server had 'multiple layers' of security.&lt;/span&gt;&lt;br style="color:rgb(255, 255, 0)"&gt;&lt;span style="color:rgb(255, 255, 0)"&gt;I'm guessing Full Disk Encryption, Token-Key access etc.&lt;/span&gt;&lt;img src="http://shared.live.com/HjKMzTS-xzcms40!CabizA/emoticons/smile_teeth.gif" title=Open-mouthed alt=Open-mouthed style="vertical-align:middle;color:rgb(255, 255, 0)"&gt;&lt;span style="color:rgb(255, 255, 0)"&gt; &lt;/span&gt;&lt;br style="color:rgb(255, 255, 0)"&gt;&lt;br style="color:rgb(255, 255, 0)"&gt;&lt;span style="color:rgb(255, 255, 0)"&gt;All the more reason to have a 'Defense-in-Depth' appproach to security. &lt;/span&gt;&lt;br style="color:rgb(255, 255, 0)"&gt;&lt;span style="color:rgb(255, 255, 0)"&gt;While firewall, IPS etc reduces the risk of attacks from network, those controls do little to protect physical treat like server theft. &lt;/span&gt;&lt;br style="color:rgb(255, 255, 0)"&gt;&lt;br style="color:rgb(255, 255, 0)"&gt;&lt;span style="color:rgb(255, 255, 0)"&gt;I used to work in a shipping company where not only desktops and laptops were chained to the desk, but servers in server room were 'chained' too. &lt;/span&gt;&lt;br style="color:rgb(255, 255, 0)"&gt;&lt;span style="color:rgb(255, 255, 0)"&gt;The server room had CCTV and a full time guard was placed to guard the server room,and this was only a shipping company. &lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;h1&gt;HSBC lost server with customer data&lt;/h1&gt;
			
			
        	        	&lt;div&gt;
        		
								  		   			  	 By Computerworld UK Staff
    	 		,
	 	 Computerworld UK

    , 05/09/2008
          	&lt;/div&gt;
						
						        		
			
    		
		&lt;div&gt;
		&lt;div&gt;     		   			                 	          	          	         &lt;/div&gt;
		&lt;div style="float:right"&gt;&lt;font size=1&gt;&lt;/font&gt;&lt;br&gt;&lt;/div&gt;
		&lt;p&gt;HSBC has admitted losing a server containing data on 159,000 customers.
&lt;p&gt;The server went missing on 26 April from its Kwun Tong district branch in Hong Kong during renovation work on 26 April. The
   server held customer names, account numbers, transaction amounts and transaction types, the banking giant confirmed.


&lt;p&gt;HSBC said the server is protected by &amp;quot;multiple layers of security&amp;quot; and the risk of data breaches and fraud is &amp;quot;deemed to be
   low&amp;quot;.

&lt;p&gt;It also said the server contained no PIN codes or online banking login credentials.

&lt;p&gt;The bank said it has reported the incident to the police, the Hong
Kong Monetary Authority, and the Hong Kong privacy commissioner.
&lt;p&gt;The Hong Kong incident is the latest security foul-up involving HSBC. In April, HSBC admitted it lost an unencrypted disc
   containing 370,000 customer details in the post.

&lt;p&gt;HSBC has also struggled with its Secure e-payments system, with three outages reported this year that left merchants stranded
   and unable to process payments.

						&lt;p&gt;
&lt;font size=-1&gt;All contents copyright 1995-2008 Network World, Inc. &lt;a href="http://www.networkworld.com/"&gt;http://www.networkworld.com&lt;/a&gt;&lt;/font&gt;
&lt;/div&gt;&lt;br&gt; &lt;br&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Server+Lost+during+Renovation&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!151.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!151.entry</guid><pubDate>Sun, 18 May 2008 02:54:57 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!151/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!151.entry#comment</wfw:comment><dcterms:modified>2008-05-18T03:41:50Z</dcterms:modified></item><item><title>Security Assessment Tool - MSAT</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!149.entry</link><description> 

&lt;p style="margin-bottom:12pt;line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;      Firewall and Anti-Virus are
commonly found in any of todays organization. This was not true back in the
80's or even 70's. Thanks to virus writer and script kiddies (and also the
media), attacks on networks and malicious codes has forced companies to include
Firewall and Anti-Virus as the 'must-have' in their LAN setup buy-list. Any
companies who operates without these two security apparatus would be chastised
and ridiculed.  Even the CEO who's totally clueless about IT will not
approve a LAN without a basic network firewall and anti-virus. People in
general has become more aware of the treats,either by first-hand experience or
even enlighten by the media. For the banking and financial industry, the push
for them to have these basic security apparatus comes from either
self-realization or better still, regulators. A bank or insurance company which
operates without a these two basics will immediately raised a red flag during
an audit exercise by the regulators, and the consequences would be very harsh,
either summoned or lose their licensed.&lt;br&gt;
&lt;br&gt;
    As we move on beyond 90's and into the 21st century, threats
have now evolved. Threats are multi-facet, blended and sophisticated.  the
term 'zero-day' attack also begin in the year 2000,refers to Zero-day exploits
generally circulate through the ranks of hackers until finally being released
on public forums. The term derives from the age of the exploit. A zero-day
exploit is usually unknown to the public and to the product vendor. What about
fishing attacks or spyware or botnet etc? Wireless attacks etc. &lt;br&gt;
&lt;br&gt;
   The threats has become more sophisticated and deadly, however, the
average IT Pro's knowledge on Information Security, has remain unchanged or
static. IT Pros are still deploying firewall and anti-virus as 'the only' line
of defense. CEO or business owners are still not keen on adding other security
apparatus to their line of defense like patch management, Intrusion Prevention
System, Wireless Firewall/IDS etc. &lt;br&gt;
&lt;br&gt;
   &lt;br&gt;
For these people, their practice of Security has always been and always be -
catching up with the treat. The idea of conducting Security Risk Assessment has
never cross their mind. &lt;br&gt;
&lt;b&gt;&lt;span style="color:rgb(79, 129, 189)"&gt;&lt;br&gt;
What is Security Risk Assessment?&lt;/span&gt;&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
&lt;a href="http://www.security-risk-analysis.com/introduction.htm" target="_blank"&gt;&lt;span style="color:blue"&gt;Security Risk Analysis&lt;/span&gt;&lt;/a&gt;&lt;br&gt;
&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;Security
risk analysis, otherwise known as risk assessment, is fundamental to the
security of any organization. It is essential in ensuring that controls and
expenditure are fully commensurate with the risks to which the organization is
exposed.&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;Security
in any system should be commensurate with its risks. However, the process to
determine which security controls are appropriate and cost effective, is quite
often a complex and sometimes a subjective matter. One of the prime functions
of security risk analysis is to put this process onto a more objective basis.&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt; &lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;There
are a number of distinct approaches to risk analysis. However, these
essentially break down into two types: quantitative and qualitative. &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt; &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;br&gt;
&lt;/span&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif';color:royalblue"&gt;Quantitative Risk Analysis &lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;This
approach employs two fundamental elements; the probability of an event
occurring and the likely loss should it occur. &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;Quantitative
risk analysis makes use of a single figure produced from these elements. This
is called the 'Annual Loss Expectancy (ALE)' or the 'Estimated Annual Cost
(EAC)'. This is calculated for an event by simply multiplying the potential
loss by the probability. &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;It
is thus theoretically possible to rank events in order of risk (ALE) and to
make decisions based upon this. &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;The
problems with this type of risk analysis are usually associated with the
unreliability and inaccuracy of the data. Probability can rarely be precise and
can, in some cases, promote complacency. In addition, controls and
countermeasures often tackle a number of potential events and the events
themselves are frequently interrelated. &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;Notwithstanding
the drawbacks, a number of organisations have successfully adopted quantitative
risk analysis. &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt; 
&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;b&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif';color:royalblue"&gt;Qualitative Risk Analysis &lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;This
is by far the most widely used approach to risk analysis. Probability data is
not required and only estimated potential loss is used. &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;Most
qualitative risk analysis methodologies make use of a number of interrelated
elements: &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:7.5pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt; &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="margin-left:1in;line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;THREATS&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt; &lt;/span&gt;

&lt;p style="margin-left:1in;line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;These are things that can go wrong or that can 'attack' the
system. Examples might include fire or fraud. Threats are ever present for
every system.&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="margin-left:2in;line-height:normal"&gt;&lt;span style="font-size:7.5pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt; &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="margin:0in 0in 0.0001pt 1in;line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;VULNERABILITIES &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="margin-left:1in;line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;These make a system more prone to attack by a threat or make
an attack more likely to have some success or impact. For example, for fire a
vulnerability would be the presence of inflammable materials (e.g. paper). &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="margin-left:2in;line-height:normal"&gt;&lt;span style="font-size:7.5pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt; &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="margin-left:1in;line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;CONTROLS&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt; &lt;/span&gt;

&lt;p style="margin-left:1in;line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;These are the countermeasures for vulnerabilities. There are
four types:&lt;/span&gt;&lt;span style="font-size:7.5pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt; &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="margin-left:2in;text-indent:-0.25in;line-height:normal"&gt;&lt;span style="font-size:10pt;font-family:'Courier New'"&gt;&lt;span style=""&gt;o&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal"&gt;   
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;Deterrent
controls reduce the likelihood of a deliberate attack &lt;/span&gt;

&lt;p style="margin-left:2in;text-indent:-0.25in;line-height:normal"&gt;&lt;span style="font-size:10pt;font-family:'Courier New'"&gt;&lt;span style=""&gt;o&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal"&gt;   
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;Preventative
controls protect vulnerabilities and make an attack unsuccessful or reduce its
impact &lt;/span&gt;

&lt;p style="margin-left:2in;text-indent:-0.25in;line-height:normal"&gt;&lt;span style="font-size:10pt;font-family:'Courier New'"&gt;&lt;span style=""&gt;o&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal"&gt;   
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;Corrective
controls reduce the effect of an attack &lt;/span&gt;

&lt;p style="margin-left:2in;text-indent:-0.25in;line-height:normal"&gt;&lt;span style="font-size:10pt;font-family:'Courier New'"&gt;&lt;span style=""&gt;o&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal"&gt;   
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;Detective
controls discover attacks and trigger preventative or corrective controls.&lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt; &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt; &lt;/span&gt;

&lt;p style="line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;These
elements can be illustrated by a simple relational model: &lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;/span&gt;

&lt;p style="margin-bottom:12pt;line-height:normal"&gt;&lt;span style="font-size:12pt;font-family:'Univers&amp;quot;,&amp;quot;sans-serif'"&gt;&lt;br&gt;
&lt;/span&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif'"&gt;&lt;br&gt;
&lt;b&gt;&lt;span style="color:rgb(79, 129, 189)"&gt;Dazed and Confused?&lt;br&gt;
&lt;br&gt;
&lt;/span&gt;&lt;/b&gt;&lt;span style="color:black"&gt;To the average IT Pro or even
non-technical, the above sounds so academic and so difficult to implement.
Rather, they would just prefer to leave their standard security defense as it
is rather than hiring a consultant to do a Risk Assessment,which would incur
additional cost to a very tight budgeted IT organization. &lt;br&gt;
&lt;br&gt;
Security Assessment is very crucial, it helps IT Pro's and Business Owners
understand what threats thier organization are exposed to, and more importantly
how to reduce the risk exposure, without over spending. In dealing with
threats, there is also the scenario of 'over spending'. This happens when
either the IT Pro or the Business Decision Makers are all too hype up about the
security threats, they start 'throwing money' at security, hoping that, thier
organization would be solid and sound like Fort Knox. Most often, despite the
investment, they still find themselves attack,and very often from areas which
are overlooked. The only people who are laughing all the way to the bank when
this happens,are the security vendors who sold them all the products. &lt;br&gt;
&lt;br&gt;
So, an assessment is very necessary and crucial. An assessment should be
conducted before even purchasing the two most basic security apparatus,
firewall and anti-virus. &lt;br&gt;
&lt;br&gt;
Are there some basic tools out there that could help IT Pro's and Business
Managers to do a self-security-risk-assessment, without having to be 'schooled'
first? A point-and-click tool that only requires, Yes and No and at most a 10
minutes blank-stare to get the answer. &lt;br&gt;
&lt;br&gt;
&lt;/span&gt;&lt;b&gt;&lt;span style="color:rgb(79, 129, 189)"&gt;Enter - &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size:13.5pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif';color:rgb(79, 129, 189)"&gt;Microsoft Security Assessment Tool.&lt;br style=""&gt;
&lt;/span&gt;&lt;/b&gt;&lt;p style="margin-bottom:12pt;line-height:normal"&gt;&lt;b&gt;&lt;span style="font-size:13.5pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif';color:rgb(79, 129, 189)"&gt;&lt;span style="font-weight:bold"&gt;&lt;/span&gt;&lt;span style="font-family:Arial Black"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:13.5pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif';color:rgb(79, 129, 189)"&gt;&lt;span style="color:rgb(0, 0, 0);font-family:Segoe UI"&gt;So to make IT Pro's and IT Managers life easier when it comes to conducting security assessment, I urge you to use the MSAT. It's free and its easy to use. &lt;br&gt;&lt;/span&gt;&lt;/span&gt;&lt;p style="margin-bottom:12pt;line-height:normal"&gt;It gives you an overview of where your organization is in terms of security, and where you want to go.&lt;table style="width:100%" cellpadding=0 cellspacing=0&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan=2 height=15&gt;&lt;br&gt;&lt;tr&gt;&lt;td valign=top&gt;&lt;table style="width:100%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Key Features:&lt;/strong&gt;&lt;tr&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;Recognize areas of business risk. &lt;li&gt;Identify Defense-in-Depth. &lt;li&gt;Generate reports that will identify areas of concern. &lt;li&gt;Analyze the results from the perspectives of technology, people, and processes.&lt;/ul&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;When to Use:&lt;/strong&gt;&lt;tr&gt;&lt;td&gt;&lt;div&gt;The
Security Assessment tool should be used to gather information and
provide recommendations and best practices for your customers. This
tool will not only identify specific security applications, but will
also focus on people and processes. It provides information on business
risk profile, infrastructure, applications, operations, and people. &lt;/div&gt;&lt;tr&gt;&lt;td style="padding-top:12px"&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt;&lt;tr&gt;&lt;td&gt;&lt;div&gt;This
application is designed to help organizations with fewer than 1,000
employees assess weaknesses in their current IT security environments.
It will help identify processes, resources, and technologies that are
designed to promote good security planning and risk mitigation
practices within the organization.&lt;/div&gt;&lt;tr&gt;&lt;td style="padding-top:12px"&gt;&lt;strong&gt;Estimated Time to Complete:&lt;/strong&gt;&lt;tr&gt;&lt;td&gt;&lt;div&gt;1-3 hours&lt;/div&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style="margin-bottom:12pt;line-height:normal"&gt;&lt;a target="_blank" rel=nofollow href="http://www.microsoft.com/downloads/details.aspx?FamilyId=6D79DF9C-C6D1-4E8F-8000-0BE72B430212&amp;amp;displaylang=en"&gt;Download It Here&lt;/a&gt;&lt;p style="margin-bottom:12pt;line-height:normal"&gt;- I know this pretty basic for some, but most orgnization hardly conducts any security assessment, and have been doing so for the longest time. &lt;br&gt;&lt;p style="margin-bottom:12pt;line-height:normal"&gt;Best approach to security, with your eyes wide open!&lt;br&gt;&lt;p style="margin-bottom:12pt;line-height:normal"&gt;&lt;br&gt;&lt;span style="font-size:13.5pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif';color:rgb(79, 129, 189)"&gt;&lt;span style="color:rgb(0, 0, 0);font-family:Segoe UI"&gt;&lt;/span&gt;&lt;/span&gt;&lt;p style="margin-bottom:12pt;line-height:normal"&gt;&lt;br&gt;&lt;span style="font-size:13.5pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif';color:rgb(79, 129, 189)"&gt;&lt;span style="color:rgb(0, 0, 0);font-family:Segoe UI"&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size:13.5pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif';color:rgb(79, 129, 189)"&gt;
&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12pt;font-family:'Times New Roman&amp;quot;,&amp;quot;serif';color:rgb(0, 0, 0)"&gt;&lt;/span&gt;

&lt;p style="color:rgb(0, 0, 0)"&gt; 

&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=3655282381092027437&amp;page=RSS%3a+Security+Assessment+Tool+-+MSAT&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=myinsecurity.spaces.live.com&amp;amp;GT1=myinsecurity"&gt;</description><comments>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!149.entry#comment</comments><guid isPermaLink="true">http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!149.entry</guid><pubDate>Tue, 06 May 2008 18:46:55 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://myinsecurity.spaces.live.com/blog/cns!32BA2BF586BBFC2D!149/comments/feed.rss</wfw:commentRss><wfw:comment>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!149.entry#comment</wfw:comment><dcterms:modified>2008-05-06T18:46:55Z</dcterms:modified></item><item><title>Europe asks ISPs to help battle cybercrime</title><link>http://myinsecurity.spaces.live.com/Blog/cns!32BA2BF586BBFC2D!146.entry</link><description>&lt;div&gt; &lt;/div&gt;
&lt;div&gt;It's only fair that ISP took the responsibility of securing the pipe instead of hand-off approach and allow just about anything to travel through thier infrastructure. &lt;/div&gt;
&lt;div&gt;The Council of Europe have unanimously agreed to get ISP's to commit to a certain security guidelines. The attack on Estonia, although many parties have played it down, is a very clear example of how a cyber attack can cause a total shutdown of an entire nation. &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;Here in Malaysia, the regulatory bodies have yet to even propose such rulings. Perhap the lax approach is due to the fact, the chances of what happen to Estonia is 1 in a 1,000,000. That is a very dangerous thought, however, at the pace the regulators are moving, one cannot help to assume the above reason. &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;
&lt;hr&gt;
&lt;/div&gt;
&lt;p&gt;&lt;span&gt;Security Focus.&lt;/span&gt;
&lt;p&gt;&lt;span&gt;Europe asks ISPs to help battle cybercrime&lt;/span&gt;&lt;br&gt;&lt;span&gt;Published: 2008-04-02&lt;/span&gt;&lt;br&gt;&lt;br&gt;&lt;a href="http://adserver.securityfocus.com/RealMedia/ads/click_lx.ads/www.securityfocus.com/brief/646915424/x30/default/empty.gif/63663265333731623437663439306330"&gt;&lt;img height=2 alt="" src="http://adserver.securityfocus.com/RealMedia/ads/Creatives/default/empty.gif" width=2 border=0&gt;&lt;/a&gt;&lt;span&gt;The Council of Europe plans to vote this week on drafted guidelines that call for more cooperation from Internet service providers (ISPs) in combatting online attacks.
&lt;p&gt;During the Council of Europe's Octopus 2008 Conference on Cybercrime -- which is taking place in Strasbourg, France -- participants will be &lt;a href="https://wcd.coe.int/ViewDoc.jsp?Ref=PR218(2008)&amp;amp;Language=lanEnglish&amp;amp;Ver=original&amp;amp;Site=DC&amp;amp;BackColorInternet=F5CA75&amp;amp;BackColorIntranet=F5CA75&amp;amp;BackColorLogged=A9BACE" target="_blank"&gt;&lt;u&gt;&lt;font color="#0066cc"&gt;asked to adopt&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; a set of guidelines to speed response to cyberattacks and share more information, especially between Internet service providers and government agencies. The guidelines have been proposed by Estonia and other nations following &lt;a href="http://www.securityfocus.com/brief/504"&gt;&lt;u&gt;&lt;font color="#0066cc"&gt;the attacks&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; on the northern European country last spring.
&lt;p&gt;&amp;quot;The draft guidelines build upon the existing Council of Europe Convention on Cybercrime -- to which many countries in Europe and beyond have acceded -- and call for formal partnerships between Internet service providers (ISPs) and law enforcement,&amp;quot; the Council of Europe said in a statement published about the conference.
&lt;p&gt;In late April and early May 2007, massive denial-of-service attacks &lt;a href="http://www.securityfocus.com/news/11503"&gt;&lt;u&gt;&lt;font color="#0066cc"&gt;hobbled online communications&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; in Estonia, a nation that depends on the Internet for much of its commerce and access to government. The attacks &lt;a href="http://www.securityfocus.com/brief/504"&gt;&lt;u&gt;&lt;font color="#0066cc"&gt;began on April 28&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;, following violent clashes between the Estonian police and ethnic Russians in the country over the removal of a Red Army monument that symbolizes the defeat of Nazi Germany by the Soviet Union during World War II, but is also a reminder to Estonians of the more than four decades that the Soviets occupied the nation. Following the incident, the North Atlantic Treaty Organization (NATO) -- of which Estonia is a member -- &lt;a href="http://www.securityfocus.com/brief/527"&gt;&lt;u&gt;&lt;font color="#0066cc"&gt;began evaluating&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; whether such attacks should trigger the treaty's clause for common defense, &lt;a href="http://www.nato.int/docu/basictxt/treaty.htm" target="_blank"&gt;&lt;u&gt;&lt;font color="#0066cc"&gt;Article 5&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;.
&lt;p&gt;The latest guidelines, and the request for ISPs to share data with government, worries many privacy experts, according to &lt;a href="http://www.iht.com/articles/2008/03/30/technology/cyber31.php" target="_blank"&gt;&lt;u&gt;&lt;font color="#0066cc"&gt;a report&lt;/font&gt;&lt;/u&gt;&lt;/a&gt; on the issue by the International Herald Tribune. More information on the conference is available from the &lt;a href="http://www.coe.int/t/dc/files/themes/cybercrime/default_EN.asp?" target="_blank"&gt;&lt;u&gt;&lt;font color="#0066cc"&gt;Council or Europe's Web site&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;.
&lt;p&gt;&lt;em&gt;If you have tips or insights on this topic, please &lt;a href="mailto:news-editor@securityfocus.com"&gt;&lt;u&gt;&lt;font color="#0066cc"&g