Latest Comments
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including..."
by Vincent Laing | Nov 13, 2008 4:01 PM

Microsoft to offer more security details in advance

  • Email a Friend
  • Print Page
Microsoft to offer more security details in advance
By Dan Kaplan
May 18, 2007 10:18 AM
Tags: Microsoft | to | offer | more | Patch | Tuesday | details | in | advance | notifications
While Microsoft informs administrators and end-users how many patches it plans to deliver and which platforms they affect, many security pros are left guessing just how significant the load will be.

The new advance notifications (ANS), scheduled to debut 7 June, will contain maximum severity rating, vulnerability impact, detection information and affected software for each bulletin. They will not be grouped by platform.

"We’ve received positive feedback on the ANS, but customers have told us additional information would be even more helpful," Mark Miller of the Microsoft Security Response Center said Wednesday on the team's blog.

Johannes Ullrich, CTO of the SANS Internet Storm Center, told SCMagazine.com that the changes will help organisations determine which fixes are most pressing.

"A lot of people use different patch schedules for ‘critical’ versus ‘important," he said. "Last week, they had five patches that were all [maximum severity rating of] critical. But you didn’t really know how many of the individual bulletins were critical."

Eric Schultze, chief security architect at Shavlik Technologies, told SCMagazine.com that the more detailed pre-release announcements will not give away any information that may help hackers prepare an attack.

"Overall, it will be an aid to system administrators," he said.

Still, despite the additional information, organisations will not know the full extent of what awaits them until the patches are officially delivered, Ullrich said.

"What people are looking for is how much work it will take to apply these patches, and that’s always hard to predict until you see them," he said.

Microsoft also announced a planned security bulletin redesign that seeks to move pertinent information to the top of the advisory, eliminate repetitive content and compile the affected products in a table instead of a list.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers