Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


June 2002

Leveraging Microsoft Security


RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

STPP lets enterprises build a stronger wall against intruders

Microsoft products are the choice targets of many security attacks, and the prevalence of Microsoft products in corporate IT environments means that system security is of utmost importance to every enterprise. Through its Strategic Technology Protection Program (STPP), Microsoft has committed to help enterprises attain a higher level of security.

Microsoft's two-phase intent with STPP is to help customers secure their systems, then help them keep their systems secure. Microsoft immediately delivered on STPP's first phase by offering free virus-related telephone support (866-727-2338) and distributing the Microsoft Security Toolkit on CD-ROM and through download from Microsoft's Web site. To help customers keep their systems secure, Microsoft plans to conduct security-related training events and make security updates for products more manageable.

STPP can help systems administrators stay on top of security concerns. I installed the Security Toolkit CD-ROM provided with the Windows & .NET Magazine Lab's TechNet subscription on some supporting servers in the Lab to test the processes and tools available through STPP. I found that the toolkit will help organizations keep their data secure. The toolkit accurately identified and appropriately updated system components. The commonly executed fixes for the servers in the Lab's environment included the Microsoft Internet Information Services (IIS) 5.0 Security Update and Windows Media Player update from the Microsoft article "Windows Media Player .ASF Processor Contains Unchecked Buffer" (http://support.microsoft.com/default.aspx?scid=kb;en-us;q308567). The toolkit executed the IIS Lockdown Wizard and installed the Windows 2000 Critical Update Notification utility.

Critical Update Notification automatically checks for the availability of updates to your OS and lets you install them. Administrators face constant challenges in balancing daily tasks with the need to be proactive about security. For this reason, automating security updates makes a lot of sense. Critical Update Notification is the Security Toolkit's most compelling component because of the relatively hands-off manageability it affords.

Microsoft recommends that you install the Security Toolkit on every desktop and server in your enterprise. Although the toolkit is deployment-friendly, it still requires that you manage security from each server and desktop in your enterprise. A centralized distribution and control model would best serve management of security patches and update mechanisms.

Due in second quarter 2002 (but unavailable when I wrote this column) is Windows Update Corporate Edition, a new component of STPP that will leverage Active Directory (AD)—based networks to provide easier update management. This new solution lets an organization create an intranet-hosted Windows Update server that can synchronize its contents with information on Microsoft's public Windows Update service. Administrators control which updates download to the intranet server and which computers can download individual updates from the intranet server. In AD environments, the rules governing client behavior will be based on Group Policy; in non-AD environments, rules will depend on registry settings.

STPP shows that Microsoft is addressing the security of its OSs. I'll continue using Critical Update Notification on Internet-connected systems in the Lab, but I look forward to the administrative relief in Windows Update Corporate Edition.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
CES 2009: Ballmer Announces Windows 7, Windows Live, Live Search Milestones

During his first-ever Consumer Electronics Show (CES) 2009 keynote address last night in Las Vegas, Microsoft CEO Steve Ballmer announced the pending public availability of a feature-complete Windows 7, the final version of Windows Live Essentials, and ...

10 Reasons to Deploy Windows Vista

The decision to upgrade your XP systems to Vista is simple when you consider features such as easier backup, a great desktop search, and vastly improved security options. ...

10 Reasons Not to Deploy Windows Vista

The decision to upgrade to Vista has to make business sense, but many companies find the costs in training and application compatibility problems outweigh any benefits Vista brings. ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Security Summit

Virtualization Forum: Optimizing Storage, Networks, Desktops, and Security

Cloud Computing Forum: Integrating Software, Server and Storage as a Service into Your Enterprise IT Delivery Model

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing