{"id":96,"date":"2012-01-08T20:26:02","date_gmt":"2012-01-08T20:26:02","guid":{"rendered":"http:\/\/cybersecurity.bellevue.edu\/?p=96"},"modified":"2012-01-08T20:26:02","modified_gmt":"2012-01-08T20:26:02","slug":"ten-years-of-trustworthy-computing","status":"publish","type":"post","link":"https:\/\/cybersecurity.bellevue.edu\/index.php\/2012\/01\/08\/ten-years-of-trustworthy-computing\/","title":{"rendered":"Ten Years of Trustworthy Computing"},"content":{"rendered":"<p>I have to admit it, I\u2019m proud of Microsoft.\u00a0 After taking a beating for many years, Microsoft has gotten security right.\u00a0 It\u2019s embedded in their development lifecycle and their update strategy has become a de facto standard. \u00a0Many companies now provide regular patches and have made it easy for end users to ensure their applications are up-to-date.<\/p>\n<p>Ten years ago on January 15, 2002, Bill Gates released a <a href=\"http:\/\/www.microsoft.com\/mscorp\/execmail\/2002\/07-18twc.mspx\" target=\"_blank\">historical memo <\/a>announcing the new strategy of \u201cTrustworthy Computing.\u201d This required security to be a priority and that secure practices be embedded throughout the development and maintenance of their products. \u00a0This started a history of openness for Microsoft on many security initiatives. You can view the history of Trustworthy Computing at <a href=\"http:\/\/www.microsoft.com\/about\/twc\/en\/us\/history.aspx\" target=\"_blank\">http:\/\/www.microsoft.com\/about\/twc\/en\/us\/history.aspx<\/a>.<\/p>\n<p>Even though they don\u2019t share their source code, they do share many other things such as their <a href=\"http:\/\/www.microsoft.com\/security\/sdl\/default.aspx\" target=\"_blank\">Security Development Lifecycle<\/a>.\u00a0 This is the process for assuring that security is considered as an application is being developed.\u00a0 Microsoft requires their developers follow this process and understand the concepts of developing secure products. \u00a0In my opinion, all development efforts should have this requirement, but it seems that it continues to be lacking.<\/p>\n<p>Also part of the Trustworthy computing initiative started ten years ago is Microsoft\u2019s update strategy. Initially, patches were released as they were ready. That caused problems for systems administrators, so Microsoft decided to roll out patches once a month on the second Tuesday.\u00a0 That practice continues today. \u00a0To ensure there are no surprises, Microsoft even provides advanced notification a week before, which provides a high-level overview of what to expect.\u00a0 The Microsoft Security Bulletins page (<a href=\"http:\/\/technet.microsoft.com\/en-us\/security\/bulletin\" target=\"_blank\">http:\/\/technet.microsoft.com\/en-us\/security\/bulletin<\/a>) shows current and past updates.<\/p>\n<p>Microsoft, you\u2019ve come a long way baby.\u00a0 You are a leader who has taken their role seriously and provided many good products, resources, and references. You continue to live and breathe Trustworthy Computing.\u00a0 I just hope you can keep it up.<\/p>\n<p>References:<\/p>\n<ul>\n<li>History of Trustworthy Computing: <a href=\"http:\/\/www.microsoft.com\/about\/twc\/en\/us\/history.aspx\" target=\"_blank\">http:\/\/www.microsoft.com\/about\/twc\/en\/us\/history.aspx<\/a><\/li>\n<li>Microsoft Security Development Lifecycle (SDL): <a href=\"http:\/\/www.microsoft.com\/security\/sdl\/default.aspx\" target=\"_blank\">http:\/\/www.microsoft.com\/security\/sdl\/default.aspx<\/a><\/li>\n<li>Microsoft Security Bulletins: <a href=\"http:\/\/technet.microsoft.com\/en-us\/security\/bulletin\" target=\"_blank\">http:\/\/technet.microsoft.com\/en-us\/security\/bulletin<\/a><\/li>\n<li>Microsoft Safety &amp; Security Center: <a href=\"http:\/\/www.microsoft.com\/security\/default.aspx\" target=\"_blank\">http:\/\/www.microsoft.com\/security\/default.aspx<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>I have to admit it, I\u2019m proud of Microsoft.\u00a0 After taking a beating for many years, Microsoft has gotten security right.\u00a0 It\u2019s embedded in their development lifecycle and their update strategy has become a de facto standard. \u00a0Many companies now provide regular patches and have made it easy for end users to ensure their applications [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[3],"tags":[],"class_list":["post-96","post","type-post","status-publish","format-standard","hentry","category-security-management"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/96","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/comments?post=96"}],"version-history":[{"count":2,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/96\/revisions"}],"predecessor-version":[{"id":98,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/posts\/96\/revisions\/98"}],"wp:attachment":[{"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/media?parent=96"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/categories?post=96"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurity.bellevue.edu\/index.php\/wp-json\/wp\/v2\/tags?post=96"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}