* Window Server 2003's security Web site
endif; ?>Whenever people gather to discuss Windows networking the subject of security is sure to come up.
Traditionally, Microsoft paid scant attention to security topics but the now justly famous Trustworthy Computing Initiative memo from Bill Gates truly seems to have caused the Redmond behemoth to turn 180 degrees, at least as far as security issues are concerned. Windows Server 2003, for example, has more security information available at its rollout than just about all other Microsoft operating systems put together.
There’s so much information available for the new operating system, in fact, that it would easily be possible to overlook important details. But someone has gathered it all together in one place. That someone is Microsoft and that place is the Technet Web site.
The place to begin is: https://www.microsoft.com/technet/security/prodtech/windows/win2003/ This dynamic site should always list the latest information as well as link to the most recent patches and hotfixes for the just released server operating system.
Currently it’s subdivided into three sections – “Troubleshoot and Maintain,” “Set Up, Configure, and Administer” and “Security Topics.”
“Troubleshoot and Maintain” is where you’ll find the latest information, the “must have” details to protect your network. Patches, hotfixes and advisories make up the bulk of the information you’ll see here but since there aren’t any yet for Windows Server 2003 (or, at least, there weren’t any last week when I looked!), there are links to discussions of new security features in the operating system:
*New Security Information in the Windows Resource Kit.
*Windows Server 2003 Public Key Infrastructure (PKI) Operations Guide.
*Implementing and Administering Certificate Templates in Windows Server 2003.
*Key Archival and Management in Windows Server 2003.
There’s also a link to a tool for Internet Information Server which gives Web site managers the ability to turn off unneeded features and restrict the kind of HTTP requests that the server will process.
That’s not much, but I’d actually like to see this part remain stagnant. That would mean that the “daily security vulnerability” that’s almost a feature of Windows 2000 would be finally replaced by a relatively secure operating system.
To keep the system secure, you’ll need to thoroughly understand the second part of the security Web site – the “Set Up, Configure and Administer” part. This is further subdivided into two sections: “Practical Setup and Configuration” and “General Security Guides and Resources.”
The first part links to “how to” guides for the various security subsystems that are part of Windows Server 2003. You’ll need those, but you’ll also want to begin with two overview documents from the “General Security Guides and Resources” area: “Security Innovations in Windows Server 2003” (https://www.microsoft.com/windowsserver2003/techinfo/overview/secinnovation.mspx) and “Technical Overview of Windows Server 2003 Security Services” (https://www.microsoft.com/windowsserver2003/techinfo/overview/security.mspx).
These give you, respectively, a business view and a technical view of the security improvements in Windows Server 2003. Once you’re comfortable with what’s possible, go on to read the dozen or so “Best Practices” documents for a fuller understanding of current thinking as to which security features to implement.
After that you can head over to the “how to” area to discover the correct deployment techniques and strategies.
This site has enough information so that you should never be at a loss for information that will help improve both your understanding of security as well as how to effectively implement a secure computing environment. Microsoft has indeed changed, and for the better.




