Posted by: kurtsh | October 31, 2008

RELEASE: IT Compliance Management Guide is now available!

clip_image001[6]

Address your GRC needs by leveraging
your existing Microsoft investment!

This Solution Accelerator can save you time and money by shifting your governance, risk, and compliance (GRC) efforts from people to technology. Use its configuration guidance to help efficiently address your organization’s GRC objectives with Microsoft technology you may already own.

This Accelerator helps you better understand how an IT process framework can help you implement GRC controls in your Microsoft infrastructure.

The IT Compliance Management Guide includes a Microsoft® Operations Framework (MOF) 4.0 companion guide that is based on the Regulatory Compliance Planning Guide.

The IT Compliance Management Resources workbook saves you time by bringing together the information you need. It provides an extensive inventory of GRC-related configuration tasks and guidance organized by Microsoft product name.

DOWNLOAD HERE:
http://go.microsoft.com/fwlink/?linkid=56419

————–

clip_image001[8]Manage IT compliance with Microsoft Operations Framework (MOF) 4.0

The IT Compliance Management Guide helps you address GRC requirements and organization-wide governance initiatives by using an approach based on MOF 4.0. MOF is a free IT service life cycle process model that addresses the control objectives of GRC authority documents and frameworks such as COBIT and ISO 27002.

MOF provides a process model to help you manage change and configuration throughout the IT service life cycle.

————–

clip_image001[10]Configure Microsoft products to address GRC requirements

Numerous resources are available to help address GRC requirements for Microsoft products and solutions.

The IT Compliance Management Guide ships with the IT Compliance Management Resources workbook, which provides job aids to locate these resources and conduct changes to your IT infrastructure.

 

 

————–

Benefits:

  • Views compliance obligations through a ‘lens’ of 8 authority documents. The example authority documents include SOX, GLBA, HIPAA, EUDPD, PCI DSS, ISO 27002, COBIT 4.1, and AICPA GAPP.
  • Takes advantage of your current Microsoft investment. Configure Microsoft products in your environment to address GRC objectives.
  • Reviewed by auditing firm Grant Thornton LLP. "The Microsoft Operations Framework (MOF) referenced in the guide is both a reasonable and extensible framework by which an organization may manage GRC requirements and solutions."
  • Reduces complexity. Provides guidance to consolidate and address GRC requirements from multiple authority documents such as regulations, publications, and agreements.
  • Clarifies configuration requirements. Includes a Microsoft Excel® workbook with a detailed inventory list and job aids.
  • Free. The IT Compliance Management Guide is a free download.

Additional Information

Posted by: kurtsh | October 30, 2008

WEB: Microsoft’s IT Governance and Compliance site

image Is your organization concerned with Regulatory Compliance?

The Solution Accelerators – Security and Compliance team provides guidance and tools to manage compliance infrastructure and to institute sound principles of IT service governance.

There are a variety of Compliance related assets that are available for download on our IT Governance & Compliance site:

  • IT Compliance Management Guide
    This Solution Accelerator can help you shift your governance, risk, and compliance (GRC) efforts from people to technology. Use its configuration guidance to help efficiently address your organization’s GRC objectives.
  • Microsoft® Operations Framework (MOF) 4.0
    MOF 4.0 delivers practical guidance for everyday IT practices and activities, helping users establish and implement reliable, cost-effective IT services for governance, risk, and compliance (GRC) activities.
  • Security Compliance Management Toolkit
    This toolkit provides proven methods that your organization can use to effectively monitor the compliance state of recommended security baselines for Windows Vista®, Windows® XP Service Pack 2 (SP2), and Windows Server® 2003 SP2.
  • Security Risk Management Guide
    The Security Risk Management Guide helps customers plan, build, and maintain a successful security risk management program.

Microsoft’s IT Governance & Compliance site:
http://technet.microsoft.com/en-us/regulatorycompliance/default.aspx

Posted by: kurtsh | October 30, 2008

INFO: Microsoft Research’s Awards & Contributions

image I just caught wind of the awards that Microsoft Research (the second largest research lab of any private sector company) have received.  Check some of the awards given to our researchers.  I’d only heard of many of these back when I was in college.

For example… Gary Starkweather’s National Academy of Engineering award.
(For those who didn’t know, Gary invented the laser printer.  He’s since retired.)

AWARDS:
http://research.microsoft.com/aboutmsr/pastpresentfuture/awards.aspx

————————

So what exactly does all this research do?  Where does it turn up?  How does Microsoft & the world take advantage of all this “thinking”?  Here’s a few of my favorites:

  • Outlook 2007/Exchange Server 2007
    Computational puzzles for fighting spam. Outlook E-Mail Postmark applies a computational puzzle that acts as a spam deterrent to e-mail messages it sends. The puzzle is read by a receiving Exchange Server 2007 server as a check for the reliability of the incoming message, improving mail legitimacy and security.
  • Office OneNote 2007
    Phonetic audio search enables users to search for spoken keywords in audio recordings. By means of phonetic speech recognition, the audio search technology allows OneNote 2007 users to locate meeting recordings in which a certain topic is talked about, and to narrow down where exactly in the recording the words were said.
  • Halo 3
    TrueSkill is a skill-based ranking system for Xbox LIVE developed at Microsoft Research. The system identifies and tracks the skills of gamers to be able to assign them into competitive matches.
  • Microsoft Surface
    Multitouch and object recognition. A hardware- and software-based method for separately recognizing multiple objects that are placed on a display surface.
  • Audio watermarking and identification. Audio watermarking and identification technology licensed to Harper Security Consulting AS of Norway helps its forensic tracking of digitally distributed content. The licensed technology consists of digital audio watermarking and fingerprinting software tools that provide for the marking and decoding of audio files.

CONTRIBUTIONS:
http://research.microsoft.com/aboutmsr/pastpresentfuture/contributions.aspx

image I just received this recent Gartner Report titled “Microsoft’s System Center Operations Manager 2007 – Still Making Progress in the Market?” authored by David Williams (www.gartner.com) that evaluates System Center Operations Manager 2007. 

It’s a third‐party view that offers recommendations for current and prospective customers looking for information on the adoption and success rate of SCOM 2007.  You can find the full, independent report at:

DOWNLOAD:
http://mediaproducts.gartner.com/reprints/microsoft/vol10/article2and3/article2and3.html

clip_image001IT organizations are looking for a straightforward and cost-effective way to manage their infrastructure, provide unified management of physical and virtual machines, consolidate underutilized physical servers, and rapidly provision new virtual machines by leveraging the expertise and investments in Microsoft Windows Server technology.

Join Larry Orecklin, General Manager of System Center for the Windows and Enterprise Management Division and Chris Tillier, Microsoft’s Senior Technology Specialist for an open, interactive dialogue with fellow technical decision managers.  Learn how you can use management and virtualization to simplify, automate, centralize your IT infrastructure and manage both the physical and virtual components with familiar tools.

At this exclusive event, you will hear about:

  • Overview of the Dynamic Data Center
  • Windows Server 2008 Hyper-V, server virtualization
  • Managing the Virtualized Data Center with Systems Center
  • Managing Virtual Desktops (VDI) and Virtual Applications

8:30-9:00

Registration and Breakfast

9:00-9:15

Introductions and kick off

9:15-10:00

Envisioning Center Demonstration
“Day in the Life” demonstration of how automation, security, and management save the day (in addition to time and money!)

10:00-11:15

Meeting and exceeding your Service Level Targets with:

  • Service Level Monitoring
  • Dynamic Allocation of Resources
  • Asset Intelligence
  • Centralized reporting
  • Backup and Virtualization
  • Reducing or keeping IT costs down

11:15-12:15

Microsoft Virtualization 360

  • Managing Virtual Desktops (VDI) and Virtual Applications
  • Windows Server 2008 Hyper-V
  • Managing the “virtual mess”

12:30-1:30
Closing

Lunch, Q&A and xBox 360 Raffle

AUDIENCE:
CTO/Technical Decision Makers
Senior IT Managers

DATE/TIME:
December 11, 2008
8:30 am – 1:30pm

LOCATION:
3 Park Plaza
Suite 1600
Irvine, CA 92614

REGISTRATION: 
If you are a customer of mine and you’re interested in attending, please contact me to register for this event.  Admission will not be permitted without registration.

Microsoft SQL Server 2005 Reporting Services Add-in for SharePoint Technologies (Reporting Services Add-in) allows you to take advantage of SQL Server 2005 Service Pack 2 (SP2) report processing and management capabilities within Windows SharePoint Services 3.0 or Microsoft Office SharePoint Server 2007. The download provides the following functionality:

  • A Report Viewer Web Part that provides report viewing capability, export to other rendering formats, page navigation, search, print, and zoom.
  • Web application pages so that you can create subscriptions and schedules, and manage reports, models, and data sources.
  • Support for using standard Windows SharePoint Services features including document management, collaboration, security, and deployment with report server content types.

The Reporting Services Add-in works together with SP2, which is required on the report server. SP2 provides the following functionality for a report server that is configured for SharePoint integrated mode:

  • Synchronization from SharePoint content database to the report server database.
  • A custom security extension that uses SharePoint permissions to control access to report server operations.
  • A new delivery extension that you can use in subscriptions to deliver reports to SharePoint libraries.
  • A revised Reporting Services Configuration tool that you can use to configure a report server for SharePoint integrated operations.
  • A new SOAP endpoint for managing report server content in SharePoint integrated mode.

DOWNLOAD:
http://www.microsoft.com/downloads/details.aspx?FamilyID=1e53f882-0c16-4847-b331-132274ae8c84&DisplayLang=en

————–

For those of you looking for something for SQL Server 2008, there’s a Beta available for the SQL Server 2008 Reporting Services Addin for Sharepoint:

REGISTRATION:
http://connect.microsoft.com/SQLServer/content/content.aspx?ContentID=7767

In the wake of the MS08-067 rapid deployment, I see fit to point to Jeff Jones’ most recent publication (today!) of his highly respected security report comparing operating system security vulnerabilities & days-of-risk across platforms.  Download it and see the risks across platforms for yourself.

(From http://blogs.technet.com/security/archive/2008/10/27/download-h1-2008-desktop-vuln-report.aspx)

imageThis report looks at all of the vulnerabilities fixed by Apple, Microsoft, Red Hat and Ubuntu during the first half of 2008. At the vendor level, the report examines all vulnerabilities as well as Days of Risk (DoR) associated with those vulnerabilities. The report further drills down to examine just those issues affecting the commonly installed desktop operating system components.

The key findings for 1H08:

  • The four vendors fixed a total 585 vulnerabilities in 1H08. 26.8% affected multiple vendors and of those, only 8 were fixed on the same day – the rest had an average 35 day delay between the first available fix and the last available fix..
  • Microsoft had the lowest average Days of Risk for all vulnerabilities fixed at 24.22 days, with the next closest vendor at 72 days.
  • For desktop OS vulnerabilities, Windows Vista had the fewest vulnerabilities in 1H08 at 21. The next lowest number was Windows XP SP2 at 26.
  • Windows Vista customers experienced full or partial mitigation for 46% of the 26 vulnerabilities affecting Windows XP SP2 in 1H08, but also experienced one additional vulnerability in new code.

In addition to these measurements for the vendors and products, the body of the report also provides weighted analysis which provides a lesser consideration for lower severity issues. Please read the full report for details.

Posted by: kurtsh | October 27, 2008

BETA: New Xbox Experience Preview program

imageUPDATE: Whoops.  The program registration is full.  Sorry.

<taken from Major Nelson’s blog>

I know that many of you are excited to get your hands on the New Xbox Experience, which will go live all Xbox LIVE regions wide on November 19th. Well, we’re just as excited to as you are so I am happy to announce that I’ve been working on a little project that I think may interested you.

Working with various teams across Xbox, we’ve developed a program to allow a select few of you early access to NXE. How do you get chosen? The first step is to head on over to Microsoft Connect, sign in with your Windows LIVE ID and join the "Xbox 360 Fall 2008 Preview Program" by clicking on this link, https://connect.microsoft.com/InvitationUse.aspx?ProgramID=2631&InvitationID=XBOX-G37M-QYWQ&SiteID=719.

Once you do that, you need to fill out the "Xbox 360 Fall Flash Preview Sign Up" survey in order to be considered for receiving the Preview System Update. We’re asking a few questions about where you live, your home network, ISP connection and a few other pieces of information. We are looking for a good cross-section of our members in order to get the best feedback we can.
The LIVE Service team will then review all of the applications and if you’re selected we’ll send you an email notifying you of your acceptance in the program.  A couple of points before you head off to register:

  • We’re looking for a few thousand participants, so your chances of making it in are good
  • This opportunity is open to all Xbox LIVE Members in regions where Xbox LIVE is available
  • Just completing the survey does not automatically get you access to the NXE. We’ll be making final selections from from the completed surveys.
  • Xbox LIVE Gold and Silver members can sign up.  Priority will be given to Gold members in the selection process.

If you are accepted, you’ll hear from us in about a week. Make sure your information on Connect is updated so we can email you.

Good luck!

image  If you own a Windows Mobile powered device, you really need to check this thing out.

Celio Corporation has created a device called a “Redfly”.  This is essentially a wireless thin client for your Windows Mobile phone.  Let me say that again: 

IT’S A WIRELESS THIN CLIENT FOR THE WINDOWS MOBILE PHONE IN YOUR POCKET.

Imagine this scenario:

  • imageSIMPLE TO TURN ON:
    You open a small laptop like device and power it on.  It wirelessly connects to the Windows Mobile phone in your pocket and displays the PHONE’S DISPLAY in an adjusted, huge 800×480 resolution!
  • FULL KEYBOARD & MOUSE:
    There is a touch pad that you can use to control a mouse cursor, or you can plug in a USB mouse into the back or you can use a Bluetooth mouse.
  • FULL SCREEN CONVENIENCE:
    You start to use the familiar interface:
    • When you open Internet Explorer, it surfs the Internet without scrolling
    • When you open Citrix/Terminal Client/LogMeIn it connects into your remote server with ease, full screen and mouse usability.
    • When you open Powerpoint, you can project the display using the VGA connector in the back – and use your phone itself as a Powerpoint clicker.
    • When you type in Word, it feels like a normal word processor.
    • When you view Adobe Acrobat attachments from mail it looks normal and displays in full resolution.
    • When you respond to emails, you can type entire responses instead of typing short replies.
  • GREAT BATTERY LIFE:
    You also notice the battery lasts for 8 hours
  • SIMULTANEOUS PHONE CHARGING:
    You can tether your phone to the device to allow it to be used without draining the power of the phone, and better yet, actually charge the phone while it’s connected to the larger Redfly battery over USB.

Now imagine it costs only $199 for a limited time. (Until Oct 31st) 

That’s Redfly.  It’s a fantastic executive alternative to laptops that provides:

  • a Windows laptop experience
  • connects wirelessly to your phone
  • leverages the Internet connectivity of your phone
  • delivers a large display & USB ports for a mouse
  • VGA port for projection

LINK: 
http://www.celiocorp.com

Our regional developer evangelists all maintain blogs with information for developers.   If you’re a developer you may want to plug into these as they’re full of local information for Los Angeles & Irvine developers.

Blogs:

Lynn Langit

http://blogs.msdn.com/SoCalDevGal

West Region

Woody Pewitt

http://blog.pewitt.org

West Region

Kevin Boyle

http://blog.boilerproductions.com 

West Region

David Chou

http://blogs.msdn.com/dachou

West Region

Scott Kerfoot

http://blogs.msdn.com/socalarchitect/

West Region

« Newer Posts - Older Posts »

Categories