Latest news
Responding In Kind
The Code Red and Nimda worms revealed severe problems in Microsoft's security alerting system. Despite the availability of patches weeks before either worm hit the Internet, few users--particularly enterprises--deployed them.
The problem was twofold: Some users found Microsoft's advisories difficult to understand or didn't receive them at all; others had a difficult time obtaining and verifying the patch. The situation prompted a complete revamping of the Microsoft Security Response Center (MSRC), the gateway for vulnerability reports and security fixes.
"We always took security seriously and were committed to it, but much more of the company takes it much more seriously in the aftermath of Code Red and Nimda," says Steve Lipner, director of security assurance, who oversees the MSRC. "We know it's important to get it all right and get it out to our customers, and everyone knows what can happen if we don't get it out."
All vulnerability reports filed with MSRC are put through a sophisticated triage and tracking process. The vulnerability report is sent to the appropriate development team, which is responsible for replicating the problem and developing a fix for it. At the same time, an independent engineering team does an evaluation to verify the problem and potential remedies.
Once a patch is created, it goes through a vetting process to ensure it works as intended.
[ Read more ]
Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





