Microsoft security documents available online

Opinion
Jan 11, 20053 mins

* A Microsoft security resource

Microsoft has been heavily criticized over the years for distributing operating systems that lack a security kernel; however, in recent years, the giant company has made public commitments to improving security from the ground up. Indeed, Windows XP Pro seems to be the company’s most stable operating system yet.

Recently, as I was preparing references for a lecture on operating systems security, I came across a site on Microsoft TechNet that may be helpful to readers of this column. The “Security Guidance” page is at:

https://www.microsoft.com/technet/security/guidance/default.mspx

It provides links to six major areas of white papers, checklists, and other useful documentation on security from the Microsoft perspective:

* Security Guidance Center Home

* Security Topics

* Products and Technologies

* How-Tos

* Checklists

* Modules

The first page is an overview that features some of the topics in the more detailed sections.

“Security Topics” provides links to lists of articles bearing on:

* Architecture and Design

* Assessment

* Auditing and Monitoring

* Cryptography, Certificates, and Secure Communications

* Desktop Security

* Developing Secure Applications

* Disaster Recovery

* Identity Management

* Network Security

* Patch Management

* Policies and Procedures

* Server Security

* Threats and Countermeasures

“Products and Technologies” links to articles about Microsoft products, ranging from its operating systems to Active Directory to IIS to Office.

“How-Tos” goes to an index of articles cross-indexed according to these classes: assessment; cryptography, certificates, and secure communications; desktop security; developing secure applications; disaster recovery; identity management; network security; patch management; and server security. Many of the listed articles are appropriate for several of the categories.

“Checklists” include a number of lists cross-indexed by the following categories: architecture and design, developing secure applications, network security, securing a Windows Server 2003 Server, securing Windows XP, and server security.

Finally, the “Modules” page includes these guides:

* Antivirus Defense-in-Depth 

* Backup and Restore 

* Identity and Access Management Series 

* Securing a Windows Server 2003 Server 

* Securing Windows XP 

* Securing Wireless LANs with Certificate Services 

* Securing Wireless LANs with PEAP and Passwords 

* Security Risk Management 

* The Patch Management Process

This page also points to 64 individual white papers on a wide range of security topics.

I looked at only a few documents in this vast collection, so I cannot claim to have evaluated all of them or even a significant sample; however, those I did examine seemed acceptably clear and concise. Specifically, I looked at “How to Use MBSA,” “How to Implement Patch Management,” “Checklist: Managed Code,” (which unfortunately begins, “This checklist is a companion to the odules…”), “Checklist: Securing Your Network,” and “Securing Your Network.” The latter included references to several Cisco security documents – a generosity of spirit that encourages me to think that Microsoft is indeed changing its ways for the better.