, 2003-09-15
The software-maker's dismal security record seems to have left it immune to criticism and shame.
Expand all |
Post comment
Does Microsoft Give a Damn?
2003-09-15
Anonymous (6 replies)
Anonymous (6 replies)
Does Microsoft Give a Damn?
2003-09-15
Anonymous (1 replies)
Anonymous (1 replies)
Don't Hold Strong Opinions About Something You Do Not Understand
2003-09-15
Anonymous (5 replies)
Anonymous (5 replies)
Don't Hold Strong Opinions About Something You Do Not Understand
2003-09-17
Billgatezebub is TEH DEVIL (1 replies)
Billgatezebub is TEH DEVIL (1 replies)
Useless rhetoric
2003-09-15
Anonymous (2 replies)
Anonymous (2 replies)
If only Linux required as little as 38 fixes.
2003-09-18
Scott G (3 replies)
Scott G (3 replies)
If only Windows allowed scripting w/o the security headaches.
2003-09-18
Anonymous (1 replies)
Anonymous (1 replies)
If only Linux required as little as 38 fixes.
2003-09-19
Anonymous (3 replies)
Anonymous (3 replies)
Of Course They Dont::Does Microsoft Give a Damn?
2003-09-18
Linux, Torvald. Mr. Linux Torvald to you. (1 replies)
Linux, Torvald. Mr. Linux Torvald to you. (1 replies)
Does Microsoft Give a Damn?
2003-09-19
Anonymous (1 replies)
Anonymous (1 replies)
Only two Suse patches?!?
2003-09-19
Anonymous (1 replies)
Anonymous (1 replies)

Some may say, it cannot be done. I say it can and have been doing such for a few years now. Blaster, Goner, Sobig, Klez have all been trapped by the multiple levels of impact on the organization I support because I do not trust any single level of protection. Does it cost? Sure. But, management here has found that while other organizations are busy recoverying from various levels of compromise, we are spending out time reporting our overall security posture, potental areas where there could be a compromise, recommendations to improve protection before any compromise, and monitoring the rates of identification and detection through our various protection mechanisms. We have not had to recover a single system because there has been no compromise.
I am not so arrogant to believe that we will never have an infection. But we have our controls set up such that we believe we can mitigate any enterprise outage. The investment of time has been worth it. We have not had to spend long hours cleaning our network from the last infestation, nor did we spend excruciating hours scrambling with the recent revelation either.
The best thing we can do is to remain vigilent, set levels of compensating controls, monitor, and patch as necessary...like we do with all the other OSs that we support and work with.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/185/22310#22310