<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">ACE Team - Security, Performance &amp; Privacy</title><subtitle type="html" /><id>http://blogs.msdn.com/ace_team/atom.xml</id><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/default.aspx" /><link rel="self" type="application/atom+xml" href="http://blogs.msdn.com/ace_team/atom.xml" /><generator uri="http://communityserver.org" version="2.1.61025.2">Community Server</generator><updated>2009-06-19T18:29:00Z</updated><entry><title>Dogfooding: How Microsoft IT Information Security Dogfoods: Product Influence</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/10/30/dogfooding-how-microsoft-it-information-security-dogfoods-product-influence.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/10/30/dogfooding-how-microsoft-it-information-security-dogfoods-product-influence.aspx</id><published>2009-10-31T00:40:00Z</published><updated>2009-10-31T00:40:00Z</updated><content type="html">&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hi Steven Michalove here, I’m a principal program manager on Microsoft IT’s &lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt; (InfoSec) group. For the last of couple weeks, we’ve been talking about Microsoft IT’s (MSIT) dogfooding process, known as the First &amp;amp; Best program. Concluding this dogfooding blog series, I would like to share with you how we help influence the development of products from an information security risk perspective. If you missed the prior blogs, read Mark Smith’s &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx" mce_href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx"&gt;&lt;FONT size=2 face="Segoe UI"&gt;blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; for an overview of the process, Don Nguyen’s &lt;/FONT&gt;&lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 1: Conduct a Security Design Review" href="http://blogs.msdn.com/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx"&gt;blog&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt; for &lt;I&gt;Phase 1&lt;/I&gt; and Price Oden’s recent &lt;/FONT&gt;&lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 2: Perform an Assessment of the Features Only" href="http://blogs.msdn.com/ace_team/archive/2009/10/26/dogfooding-how-microsoft-it-information-security-dogfoods-phase-2-perform-an-assessment-of-the-features-only.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/archive/2009/10/26/dogfooding-how-microsoft-it-information-security-dogfoods-phase-2-perform-an-assessment-of-the-features-only.aspx"&gt;blog&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt; for &lt;I&gt;Phase 2&lt;/I&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;A little background on me, I am a subject matter expert that works with security features in the Windows OS. Our team mission is to deploy controls that mitigate security risks for Microsoft. In the last few years I have been working in the area of Desktop Encryption and the deployment of BitLocker&lt;SUP&gt;TM&lt;/SUP&gt; internally within Microsoft. As part of the First &amp;amp; Best program, we act as early adopters and influencers of specific features like BitLocker&lt;SUP&gt;TM&lt;/SUP&gt;. Our role stretches throughout the entire lifecycle of a product release to test, pilot, and improvements to a product while at the same time making a measureable impact on reducing risk.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Additionally, I am a deployer of new security technologies where I get an early look at Microsoft technologies. Basically we get the bits earlier than our customer and we can log bugs and feature requests directly with our internal product developers. Since we deploy and also evaluate the deployment early, we get a look at the features while there’s still an opportunity to both test the technology and provide input into the features themselves. We generally give three kinds of feedback and the focus may change depending on where in the development lifecycle the product or feature may be. Those three kinds of feedback usually are 1) Technical errors that often indicate some kind of bug or programming error, 2) Manageability issues and documentation that influence enterprise scale deployments and 3) Feature feedback and requests. Along with providing feedback to the product teams, we’ll often brainstorm and discuss options with the developers. Our feedback really depends upon the product lifecycle, specifically how early in the process we are involved. Additionally, often times we will also develop shared goals and pilot programs (both mandatory and optional) with target numbers. For example, we may say we want to install 1000 systems with a pre-Beta build and turn on a specific feature. We’ll then build the measurement instrumentation to support the shared goals and recruit users to help.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;An example of MSIT’s involvement with influencing a product is the move from Vista to Windows 7 specifically around enterprise manageability and deployment ease of BitLocker&lt;SUP&gt;TM&lt;/SUP&gt;. The Vista splitloader that’s needed for BitLocker&lt;SUP&gt;TM&lt;/SUP&gt; is 1.5G. However, it can be hard to retrofit onto a system with existing drives. In Windows 7 not only did we shrink that to 100Mb (depending on certain options) but also, with MSIT’s input, improved the shrink API code base to help make the shrink operation itself more reliable. So while these improvements did not influence the BitLocker™ feature itself, it improved the deployment footprint of the feature.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;The dogfooding process is an iterative approach. We’ve been early adopters of our own technology for quite some time. Some questions we ask ourselves are, “what will our universe will look like in three to five years; will we see new technologies and threats; if we could achieve a dream state, what would that be?” If you’re thinking about implementing a dogfooding program in your own company, here are a few things to consider. Primary on the list is management support. The total cost of ownership is much higher as you test technologies in the production environment. For example, we have more versions of operating systems deployed than most companies, even more than our &lt;/FONT&gt;&lt;A title="Technical Adoption Program" href="http://msdn.microsoft.com/en-us/isv/bb190413.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/isv/bb190413.aspx"&gt;TAP customers&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt;, since we get software very early in the pre-release cycle. Most companies would not consider these early versions production ready for at scale deployments. We do it differently and deploy these early versions into our production environments at scale to aid in the product development lifecycle – we take the first and best objective into our operation and make it part of our overall footprint. That is how Microsoft does IT. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;&lt;FONT face="Segoe UI"&gt;Making the decision to use the production IT environment as an incubator for new technologies is a business decision. We have to both support and upgrade, as well as migrate and deploy, constantly. This can be expensive and that’s where having a strong business sponsorship is necessary. Seek specific measurable outcomes and boundaries. Agreeing on quantitative shared goals and resourcing them is a constant challenge but it needs to be a continuous process. Next, setup a mechanism to recycle the knowledge you gain. If early deployments teach you something, make sure you have the knowledge management in place to leverage this through to the production (finished, released product) systems deployments. &lt;INS dateTime=2009-11-02T11:03 cite="mailto:Steven%20Michalove"&gt;&lt;/INS&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Eventually a “dogfood” cycle ends and things move to a full production environment. You can gain a lot of speed with your early learnings. Set yourself up for that. Lastly, be prepared to deal with outages and bugs in early versions; software is unpredictable at scale so you need to have a plan “B” prepared so you can back out or limit unintended consequences. You can almost always be sure the thing you least expect will be discovered in pre-release versions, plan ahead and be prepared for the unexpected. The upside is because Microsoft IT uses early versions the released versions are stable and predictable.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hope you have enjoyed our dogfooding blog series. Watch my recent video, "&lt;A id=ctl00_MainPlaceHolder_Starter_TitleLink title="Dogfooding: Deplyoment &amp;amp; Product Influence" href="http://edge.technet.com/Media/Dogfooding-Deplyoments--Product-Influence/" target=_blank mce_href="http://edge.technet.com/Media/Dogfooding-Deplyoments--Product-Influence/"&gt;Dogfooding: Deplyoment &amp;amp; Product Influence&lt;/A&gt;,"&amp;nbsp;as I discuss in more detail on&amp;nbsp;our dogfooding process.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;- Steven Michalove &lt;BR&gt;Principal Program Manager&amp;nbsp; &lt;BR&gt;&lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com/"&gt;Microsoft Information Security&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9915567" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author><category term="dogfooding" scheme="http://blogs.msdn.com/ace_team/archive/tags/dogfooding/default.aspx" /></entry><entry><title>Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 2: Perform an Assessment of the Features Only</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/10/26/dogfooding-how-microsoft-it-information-security-dogfoods-phase-2-perform-an-assessment-of-the-features-only.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/10/26/dogfooding-how-microsoft-it-information-security-dogfoods-phase-2-perform-an-assessment-of-the-features-only.aspx</id><published>2009-10-26T18:03:00Z</published><updated>2009-10-26T18:03:00Z</updated><content type="html">&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hi Price Oden here, I’m a principal senior security architect on the Microsoft IT &lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank&gt;&lt;FONT size=2 face="Segoe UI"&gt;Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; (InfoSec) group. Dogfooding is part of Microsoft IT’s culture.&amp;nbsp; It’s where Microsoft IT (MSIT) plays an important role and service for Microsoft’s enterprise customers.&amp;nbsp; Despite the challenges of mixing testing and production on the same network and environment, MSIT trials new products at large scale in a production environment to identify and address deployment, operational and functional issues before those products reach Microsoft’s enterprise customers.&amp;nbsp; In this blog, I’ll talk about the next phase of our dogfooding process, &lt;I&gt;Phase 2: Perform an Assessment of the Features Only&lt;/I&gt;. To get an &lt;I&gt;overview&lt;/I&gt; of the dogfooding process, read Mark Smith’s &lt;/FONT&gt;&lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods" href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx" target=_blank&gt;&lt;FONT size=2 face="Segoe UI"&gt;blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; and also read about &lt;I&gt;Phase 1&lt;/I&gt; in Don Nguyen’s &lt;/FONT&gt;&lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 1: Conduct a Security Design Review" href="http://blogs.msdn.com/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx" target=_blank&gt;&lt;FONT size=2 face="Segoe UI"&gt;blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;In phase 2, after the ACE Team performs a security design review, the Security Operations Planning and Strategy Team which I’m a part of, we conduct an assessment of the features only.&amp;nbsp; For this assessment, we assess security-related features and technologies in upcoming Microsoft software products to determine how they help us in MSIT’s efforts to reduce risks in the enterprise.&amp;nbsp; Our team works with the product groups to obtain the design and functional specs and early beta builds.&amp;nbsp; If the product or feature is a good candidate, we’ll dive into technical details with the product group.&amp;nbsp; In addition, if necessary we’ll install and configure the product and tests use cases.&amp;nbsp; One example that our team was involved with was the &lt;A href="http://www.microsoft.com/windows/enterprise/products/windows-7/features.aspx#bitlocker" target=_blank&gt;Windows 7 BitLocker to Go&lt;/A&gt;&lt;SUP&gt;TM &lt;/SUP&gt;feature.&amp;nbsp; An industry trend is the explosion of removable media used in the enterprise. We prescribed &lt;A title="Windows 7 BitLocker to Go" href="http://www.microsoft.com/windows/enterprise/products/windows-7/features.aspx#bitlocker" target=_blank&gt;Windows 7 BitLocker to Go&lt;/A&gt;&lt;SUP&gt;TM &lt;/SUP&gt;as an excellent risk mitigator to protect removable media.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Many enterprises are early adopters so if you’re thinking about starting a dogfooding process in your own organization, here’s a couple of things to consider.&amp;nbsp; Rollouts to test drive new technologies can carry much of the same resource expenditure that deploying any product would have.&amp;nbsp; Therefore it may be prudent to go into all deployments with a commitment to eventual production use; you can focus on a measured rollout that occurs at a non-disruptive pace.&amp;nbsp;&amp;nbsp; Additionally, having a vision in place is extremely valuable to guide the decision process of which technologies to deploy.&amp;nbsp; Against the backdrop of a vision, each technology can be assessed to determine if it moves the organization closer to reaching its vision and if the candidate technology strategic or not.&amp;nbsp; With that assessment, the organization may decide to be conservative with regards to how much financial commitment it makes in non-strategic technologies so that it doesn’t become entrenched and prohibit replacement when a strategic technology becomes available.&amp;nbsp; Regardless, once a decision is made to deploy, the deployment itself needs to be &lt;I&gt;well planned&lt;/I&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;To hear more details about this phase of our dogfooding process, watch our recent video, “&lt;/FONT&gt;&lt;A title="Dogfooding Security-Related Features" href="http://edge.technet.com/Media/Dogfooding-Security-Related-Features/" target=_blank&gt;&lt;FONT size=2 face="Segoe UI"&gt;Dogfooding Security-Related Features&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;” where Yale Li, senior security architect, and I share some of our experiences.&amp;nbsp; Next time Steven Michalove will discuss how we influence products in the next phase of the dogfooding process...stay tuned.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.msinfosec.com/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Price Oden &lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt;Principal Senior Security Architect &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9913062" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author><category term="dogfooding" scheme="http://blogs.msdn.com/ace_team/archive/tags/dogfooding/default.aspx" /></entry><entry><title>Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 1: Conduct a Security Design Review</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx</id><published>2009-10-19T20:31:00Z</published><updated>2009-10-19T20:31:00Z</updated><content type="html">&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hi Don Nguyen here, I’m a senior security engineer with the Microsoft &lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security's&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; (InfoSec), &lt;/FONT&gt;ACE&lt;FONT size=2 face="Segoe UI"&gt; Team.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Continuing with our blog series on dogfooding, today I will be talking about &lt;I&gt;phase 1: conduct a security design review&lt;/I&gt;, of our formal dogfooding process called, the First &amp;amp; Best program. In case you missed it, read Mark Smith’s recent blog &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx" mce_href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx"&gt;&lt;FONT size=2 face="Segoe UI"&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; where he provides an overview of our dogfooding process.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;In phase 1 of our dogfooding process, a security design review is conducted and it’s performed by our own assessment team, the &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/ace_team/" target=_blank mce_href="http://blogs.msdn.com/ace_team/"&gt;ACE team&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt;. In a security design review we’re looking at additional features that might affect our policies. So basically a new feature can change our policy and if needed, we may need to modify the policy. From our review, any finding that may affect policy is communicated to our policy group. This helps ensure our internal policies are evolving along with our new technologies. For example, SQL 2005 provided a transparent data encryption to meet our internal security standard for sensitive data encryption. We assessed the encryption method and updated our policies to accept this method. The same can also be true the other way around, where we have a security policy and the product/feature may be suited at a consumer-level, but can’t be deployed in our enterprise environment per our security policies.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Also in this phase a risk assessment is performed. Anytime you add or change feature sets, the relative risk associated with the change needs to be reviewed and also existing risks will need to be assessed. Additionally with new products, new network risks can be introduced and we want to ensure these risks are identified and addressed. When we perform a risk assessment which enables the new features, this can increase risks to the network, however, this helps us determine security controls needed to mitigate a risk. Mitigation is provided to the product teams. After the assessment is completed, we provide feedback to the product teams from the context of an enterprise environment and how Microsoft IT will deploy a product, usually the enterprise features specifically.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;In the&amp;nbsp;end, success in the dogfooding program is really, seeing the overall successes over time, seeing products evolve and become more secure. Getting the opportunity to make a product more secure, working with the product teams and making a product more “enterprise-ready” is really &lt;I&gt;key&lt;/I&gt;. If you’re interested in starting a dogfooding program in your own organization, here are some things you can consider: &lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT size=2 face="Segoe UI"&gt;Determine if your organization wants to run beta software in a production environment. Make sure the beta software has feature/updates that your organization can utilize. Don’t try to beta test everything, only things that you actually expect to use as an enterprise. We test everything, but that’s our core business.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size=2 face="Segoe UI"&gt;Identify what you want to dogfood and create a dogfood plan with a start and end date per beta product/project.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size=2 face="Segoe UI"&gt;Establish a deliverable, basically a migration roadmap from when a product is beta to RTM (release to market).&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Check out my recent &lt;A title="Dogfooding: Evaluating Risk" href="http://edge.technet.com/Media/Dogfooding-Evaluating-Risk/" target=_blank mce_href="http://edge.technet.com/Media/Dogfooding-Evaluating-Risk/ "&gt;video&lt;/A&gt; where I talk more about this phase. Next time we will discuss the next phase of our dogfooding process, stay tuned…&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Don Nguyen&lt;BR&gt;Senior Security Engineer&lt;BR&gt;Microsoft &lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com/"&gt;Information Security&lt;/A&gt;, ACE Team&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9909406" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author><category term="dogfooding" scheme="http://blogs.msdn.com/ace_team/archive/tags/dogfooding/default.aspx" /></entry><entry><title>Risk Management in Risk Tracker</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/10/15/risk-management-in-risk-tracker.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/10/15/risk-management-in-risk-tracker.aspx</id><published>2009-10-15T21:19:00Z</published><updated>2009-10-15T21:19:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Hey there, my name is Sarah Pickard and I am a Senior Program Manager on the Microsoft Information Security Risk Management team.&amp;nbsp; You have seen some &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/securitytools/archive/2009/09/29/risk-tracker-v1-0-release.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;blogs by Vineet Batta&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; on the external release of Risk Tracker which is an application Information Security uses to - - well, track risk.&amp;nbsp;&amp;nbsp; To find out more information about Risk Tracker and how my teams uses it, please see the posted &lt;/FONT&gt;&lt;A href="http://edge.technet.com/Media/How-Microsoft-Uses-Risk-Tracker-to-Reduce-Risk/"&gt;&lt;FONT size=3 face=Calibri&gt;videos&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;In upcoming blogs I will give more information about how we have entered and structured risk data in Risk Tracker, how we have started tracking risk mitigating projects in Risk Tracker, and how ultimately we expect that Risk Tracker will help Information Security address the most risk with the least amount of resources.&amp;nbsp; As we all know, more with less is the name of the game. Feel free to contact me (&lt;/FONT&gt;&lt;A href="mailto:spickard@microsoft.com"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;spickard@microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;) with questions.&amp;nbsp; I look forward to chatting with you all.&amp;nbsp; Sarah&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9907853" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author></entry><entry><title>Dogfooding: How Microsoft IT's Information Security Dogfoods</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/10/08/dogfooding.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/10/08/dogfooding.aspx</id><published>2009-10-09T02:51:00Z</published><updated>2009-10-09T02:51:00Z</updated><content type="html">&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hello Diane here.&amp;nbsp; Do you ever wonder how Microsoft’s IT &lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security&lt;/A&gt; (InfoSec) is involved in the dogfooding process?&amp;nbsp; This week we’re kicking off our blog series on dogfooding.&amp;nbsp; It's a formal program&amp;nbsp;in Microsoft IT known as the&amp;nbsp;First &amp;amp; Best prgram.&amp;nbsp; Recently Mark Smith, senior program manager on Microsoft’s InfoSec group, in his &lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods" href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx" target=_blank mce_href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx"&gt;blog&lt;/A&gt; provides an overview of the First &amp;amp; Best program, along with his &lt;A title="Microsoft Information Security &amp;amp; Dogfooding" href="http://edge.technet.com/Media/Microsoft-Information-Security--Dogfooding/" target=_blank mce_href="http://edge.technet.com/Media/Microsoft-Information-Security--Dogfooding/"&gt;video&lt;/A&gt;.&amp;nbsp; In the next coming weeks, you’ll get a glimpse into our process&amp;nbsp; as we walk through the phases.&amp;nbsp;&amp;nbsp; Stay tuned.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Diane Talvo &lt;BR&gt;Security Awareness Program Manager &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9905201" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author><category term="dogfooding" scheme="http://blogs.msdn.com/ace_team/archive/tags/dogfooding/default.aspx" /></entry><entry><title>How to Integrate Risk Tracker with Internal HR Feeds</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/09/30/how-to-integrate-risk-tracker-with-internal-hr-feeds.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/09/30/how-to-integrate-risk-tracker-with-internal-hr-feeds.aspx</id><published>2009-10-01T01:36:00Z</published><updated>2009-10-01T01:36:00Z</updated><content type="html">&lt;p&gt;&lt;font size="2" face="Segoe UI"&gt;Organizations who would like to deploy the &lt;/font&gt;&lt;a href="http://edge.technet.com/Media/Risk-Tracker/" mce_href="http://edge.technet.com/Media/Risk-Tracker/"&gt;&lt;font size="2" face="Segoe UI"&gt;Risk Tracker v1.0&lt;/font&gt;&lt;/a&gt;&lt;font size="2" face="Segoe UI"&gt; application in their own environment, Vineet Batta, senior software developer on Microsoft’s IST team, shares how in his blog, “&lt;/font&gt;&lt;a title="How to Integrate Risk Tracker with Internal HR Feeds" href="http://blogs.msdn.com/securitytools/archive/2009/09/30/how-to-integrate-risk-tracker-with-internal-hr-feeds.aspx" target="_blank"&gt;How to Integrate Risk Tracker with Internal HR Feeds&lt;/a&gt;&lt;font size="2" face="Segoe UI"&gt;&lt;/font&gt;&lt;font size="2" face="Segoe UI"&gt;.”&amp;#160; Additionally, to get an an overview of this application and it’s key features, also read Vineet’s blog, “&lt;/font&gt;&lt;a title="Risk Tracker v1.0 Release" href="http://blogs.msdn.com/securitytools/archive/2009/09/29/risk-tracker-v1-0-release.aspx" target="_blank" mce_href="http://blogs.msdn.com/securitytools/archive/2009/09/29/risk-tracker-v1-0-release.aspx"&gt;Risk Tracker v1.0 Release&lt;/a&gt;&lt;font size="2" face="Segoe UI"&gt;&lt;/font&gt;&lt;font size="2" face="Segoe UI"&gt;.”&amp;#160; Visit the &lt;/font&gt;&lt;a title="Information Security Tools Blog" href="http://blogs.msdn.com/securitytools/default.aspx" target="_blank" mce_href="http://blogs.msdn.com/securitytools/default.aspx"&gt;Information Security Tools Blog&lt;/a&gt;&lt;font size="2" face="Segoe UI"&gt;&lt;/font&gt; for more information on security tools.&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="Segoe UI"&gt;-Diane Talvo      &lt;br /&gt;Security Awareness Program Manager       &lt;br /&gt;&lt;/font&gt;&lt;a title="Microsoft Information Security" href="http://www.msinfosec.com/" target="_blank" mce_href="http://www.msinfosec.com/"&gt;Microsoft Information Security&lt;/a&gt;&lt;font size="2" face="Segoe UI"&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9901557" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author></entry><entry><title>Risk Tracker v1.0 Release</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/09/29/risk-tracker-v1-0-release.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/09/29/risk-tracker-v1-0-release.aspx</id><published>2009-09-29T23:46:00Z</published><updated>2009-09-29T23:46:00Z</updated><content type="html">&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;The Microsoft &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/securitytools/default.aspx" mce_href="http://blogs.msdn.com/securitytools/default.aspx"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Information Security Tools (IST) team&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; releases Risk Tracker version 1.0 application.&amp;nbsp; Risk Tracker built on CISF (&lt;A title="Announcing the Connected Information Security Framework (CISF) and Risk Tracker" href="http://blogs.msdn.com/infosec/archive/2009/09/15/announcing-the-connected-information-security-framework-cisf-and-risk-tracker.aspx" target=_blank mce_href="http://blogs.msdn.com/infosec/archive/2009/09/15/announcing-the-connected-information-security-framework-cisf-and-risk-tracker.aspx"&gt;Connected Information Security Framework&lt;/A&gt;)&amp;nbsp;framework will help organizations manage, track and report on risks.&amp;nbsp; Vineet Batta, Senior Software Developer from Microsoft’s IST team, in his recent blog, “&lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=11945&amp;amp;postid=9900897" mce_href="http://blogs.msdn.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=11945&amp;amp;postid=9900897"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Risk Tracker v1.0 Release&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;” provides an overview of the features supported by this release (CTP).&amp;nbsp; If you haven’t seen it, watch the video “&lt;/FONT&gt;&lt;A href="http://edge.technet.com/Media/Risk-Tracker/" mce_href="http://edge.technet.com/Media/Risk-Tracker/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Risk Tracker: Reducing Risks at Microsoft&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;,” as Sarah Pickard, Senior Security Program Manager from Microsoft Information Security team and Mark Curphey, Product Unit Manager from Microsoft Information Security Tools (IST) team discuss how the business will use Risk Tracker and how it will help manage risk.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Read more about this application and other security tools on the &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/securitytools/default.aspx" mce_href="http://blogs.msdn.com/securitytools/default.aspx"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Information Security Tools Blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Diane Talvo &lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=2&gt;&lt;FONT face="Segoe UI"&gt;Security Awareness Program Manager &lt;BR&gt;&lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com/"&gt;&lt;FONT face="Segoe UI"&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9900988" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author><category term="Risk Tracker" scheme="http://blogs.msdn.com/ace_team/archive/tags/Risk+Tracker/default.aspx" /></entry><entry><title>Create a Response Time Graph</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/09/27/create-a-response-time-graph.aspx" /><link rel="enclosure" type="image/x-png" length="14344" href="http://blogs.msdn.com/ace_team/attachment/9900116.ashx" /><id>http://blogs.msdn.com/ace_team/archive/2009/09/27/create-a-response-time-graph.aspx</id><published>2009-09-28T06:30:00Z</published><updated>2009-09-28T06:30:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Spending my last 4 years helping Microsoft’s enterprise customers improve their line of business application performance, I have interacted with many project managers, business analysts as well as executive officers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Given the non-technical nature of their roles, the first thing that comes into their mind on the subject of application performance is, “How does my application perform under a certain workload?”&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The old saying “A Picture Is Worth A Thousand Words” can certainly be seen on a Response Time Graph. Below you will find a real-world sample I recently put together for a customer while working on their company portal. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;There are 2 things that are worthwhile to highlight here:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Somewhere between 420 to 450 concurrent users, the average homepage response time exceeded 3 seconds which is the company’s defined performance SLA upper limit.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Using data available from the graph, the homepage response times between 50 to 500 concurrent users are predictable.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This answered the project manager’s inquiry on “how does my application perform under X users”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;&lt;?xml:namespace prefix = v ns = "urn:schemas-microsoft-com:vml" /&gt;&lt;v:shapetype id=_x0000_t75 coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt;&lt;v:formulas&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt;&lt;/v:shapetype&gt;&lt;v:shape style="WIDTH: 390.75pt; HEIGHT: 219pt; VISIBILITY: visible" id=Chart_x0020_2 type="#_x0000_t75" o:gfxdata="UEsDBBQABgAIAAAAIQCDte0/HAEAAC4DAAATAAAAW0NvbnRlbnRfVHlwZXNdLnhtbKxSy07DMBC8&amp;#13;&amp;#10;I/EPlq8ocdoDQqhJDzyOwKF8wGJvEquObdluaf+ezevCIQjoxU/tzOzsbLanzrAjhqidLfkqLzhD&amp;#13;&amp;#10;K53Stin5++45u+MsJrAKjLNY8jNGvq2urza7s8fIqNrGkrcp+Xshomyxg5g7j5Z+ahc6SHQNjfAg&amp;#13;&amp;#10;99CgWBfFrZDOJrQpSz0GrzavJCBohewNQnqBjniENNp/OAhKyJZe47itcsLl7GEE6DWUHLw3WkKi&amp;#13;&amp;#10;DsTRqm/smatrLVE5eeiIM1cBPqm5zuQD7k2PJ36SMBVFMR3Wl5YRWyArZjGPWMPBJPZ0IpvGyQQ0&amp;#13;&amp;#10;8Xd9T47nVDl4E1vtlxiWjf2TTReb1mzMclASpQ/FsP6feYCZecWQ9uoLAAD//wMAUEsDBBQABgAI&amp;#13;&amp;#10;AAAAIQCtMD/xwQAAADIBAAALAAAAX3JlbHMvLnJlbHOEj80KwjAQhO+C7xD2btN6EJGmvYjgVfQB&amp;#13;&amp;#10;1mTbBtskZOPf25uLoCB4m2XYb2bq9jGN4kaRrXcKqqIEQU57Y12v4HTcLdYgOKEzOHpHCp7E0Dbz&amp;#13;&amp;#10;WX2gEVN+4sEGFpniWMGQUthIyXqgCbnwgVx2Oh8nTPmMvQyoL9iTXJblSsZPBjRfTLE3CuLeVCCO&amp;#13;&amp;#10;z5CT/7N911lNW6+vE7n0I0KaiPe8LCMx9pQU6NGGs8do3ha/RVXk5iCbWn4tbV4AAAD//wMAUEsD&amp;#13;&amp;#10;BBQABgAIAAAAIQB27EByXQIAAMkIAAAfAAAAY2xpcGJvYXJkL2RyYXdpbmdzL2RyYXdpbmcyLnht&amp;#13;&amp;#10;bORWy46bMBT9Fcv7Dg4MTwWkdip1U02j0pm9Y8wEFWxkOwmZr+81Jp0hqfpIFpXaDYbLfXHuuUcs&amp;#13;&amp;#10;WbbVXJUb2nONhq4VOmM53hjTZ56n2YZ3VN/Ingt4V0vVUQOP6smrFN034qlrPZ+QyGMbqgwulqxS&amp;#13;&amp;#10;meJt2Tzzt4JtpDrmrNSlWd+7SlPyWsnOlRkKcuNHfuwvPVt1cNYDWJOUkIWzHgp3voQZ+RKekCQ9&amp;#13;&amp;#10;D09DP51HH2N0jzrKlMwxRoYPpm3EV7h3CcWu7FfK3bP73Uqhpsqxj5GgHc/xF/B/Jwe0wN53HxuA&amp;#13;&amp;#10;zADmHI/28UteJ9JjSpoNteomKOkFQHa0EdAmzWRdI1ssCAC5BKMDdBgEaRzEti2aQZOIgYMfx8ki&amp;#13;&amp;#10;Jhgx8FhEIfhYB891Yj17pc0HLq/uCtlEOVacWf7QjO4+auNKHUtMM3RY2FlbyCoYLc3WcAKGjrgX&amp;#13;&amp;#10;I4N2XJlPcKlbuc8xa5seo72ifY6FFBwjZdo72eaYOJRabUpzaPm1dUfI+2uzWByAd3ABJFoqnnLM&amp;#13;&amp;#10;xZuHEiP9DMMjIYxxPRGMZqa433ZrruwszThRF/s7CdCaag6kBzpPSJgCyRqVTbdtqeEVupOCbZXi&amp;#13;&amp;#10;wqAH0BV9UoWLakUV/fzrRqG7fpr7cdrjcuijdaYybqNmpglVoMsF+zLK2U+E50xyAj+Morlo/Fhy&amp;#13;&amp;#10;SJxE4Vl4GPmT8ShYV0hOcCo5/l+THFTDKj1a7ll6TeIDdARRSW/9NA7nqnNLyMhWKzpREsbpfyc6&amp;#13;&amp;#10;VohgfekjnP+OBC3IiQSVnElRzdXhTzfee/3rUnwDAAD//wMAUEsDBBQABgAIAAAAIQDscOzoeQEA&amp;#13;&amp;#10;ABkEAAAfAAAAY2xpcGJvYXJkL2RyYXdpbmdzL2RyYXdpbmcxLnhtbKRTy07DMBC8I/EPlu80bYka&amp;#13;&amp;#10;iJr20FLEBSoBH7BynIdI7Mh2Q/r3rBNLMQUJ1F4se+2dndlZL9ddXZGWK11KkdDZZEoJF0ympcgT&amp;#13;&amp;#10;+v62u7mjRBsQKVRS8IQeuabr1fXVEuJcQVOUjCCC0DEktDCmiYNAs4LXoCey4QLvMqlqMHhUeZAq&amp;#13;&amp;#10;+ETkugrm0+kiqKEUdDVCbcEAOajyDKhKsg+ebkC0oBGyYrEfcRwrdjkyxKJ9VM1rs1eWOXtu94qU&amp;#13;&amp;#10;aUKxcwJqbBEN3IV7hsfgJCsfAbpM1fa9zDLS9ShHu/YYvDOEYTC8D2/DKKSE4d08imZRtHBVipdf&amp;#13;&amp;#10;8ljx8EcmEhoK48Yj4yzdKRRiSVmpvcl95FQxEhoUbwpQhsw94X7SqN+PWnhXztteMAHMkkDrWdzv&amp;#13;&amp;#10;nOXnOD4gOQD1n5FB80rGt5Idai7MMNyKV2DwV+mibDQlKrZDop7SmW1T3/a+HVaxf7bNuGQmvjs7&amp;#13;&amp;#10;dhxrnHwKv+oPFl8AAAD//wMAUEsDBBQABgAIAAAAIQA9pzEfGgEAAAUCAAAmAAAAY2xpcGJvYXJk&amp;#13;&amp;#10;L2NoYXJ0cy9fcmVscy9jaGFydDEueG1sLnJlbHOskT1rwzAQhvdC/4MQdKxleyglxM6SDzKEhtQZ&amp;#13;&amp;#10;Cl6u0vmjlSWhU1vn31cphDYQyNJN70n33PueprNx0OwTPfXWFDxLUs7QSKt60xZ8Xy3vHzmjAEaB&amp;#13;&amp;#10;tgYLfkDis/L2ZrpDDSE2Udc7YpFiqOBdCG4iBMkOB6DEOjTxprF+gBClb4UD+Q4tijxNH4T/y+Dl&amp;#13;&amp;#10;GZOtVcH9WuWcVQcXJ19n26bpJc6t/BjQhAsjhOzAhz2hf+7AxSSsAt9iKHiSCOXhK6am0yFPonUu&amp;#13;&amp;#10;LrvK/tOV1fj0+oYy/Pppeo1xkWI+qZcvWXqXp1tvj0+o3lS7KBfr7bFofQBdr6xWUVVIoV55cF0y&amp;#13;&amp;#10;ahpPtI1VcX2LMaA38JNInH1e+Q0AAP//AwBQSwMEFAAGAAgAAAAhAOFRNx/PBgAA5hsAABoAAABj&amp;#13;&amp;#10;bGlwYm9hcmQvdGhlbWUvdGhlbWUxLnhtbOxZzW/cRBS/I/E/jHxvs9/NRt1U2c1uA23aKNkW9Thr&amp;#13;&amp;#10;z9rTjD3WzGzSvaH2iISEKIgDlbhxQEClVuJS/ppAERSp/wJvZmyvJ+uQtI2gguaQtZ9/877fm6/L&amp;#13;&amp;#10;V+7FDB0QISlPel79Ys1DJPF5QJOw590ajy6sekgqnASY8YT0vDmR3pX199+7jNd8RtMJxyIYRyQm&amp;#13;&amp;#10;CBglcg33vEipdG1lRfpAxvIiT0kC36ZcxFjBqwhXAoEPQUDMVhq1WmclxjTx1oGj0oyGDP4lSmqC&amp;#13;&amp;#10;z8SeZkNQgmOQfnM6pT4x2GC/rhFyLgdMoAPMeh7wDPjhmNxTHmJYKvjQ82rmz1tZv7yC17JBTJ0w&amp;#13;&amp;#10;tjRuZP6ycdmAYL9hZIpwUgitj1rdS5sFfwNgahk3HA4Hw3rBzwCw74OlVpcyz9Zotd7PeZZA9nGZ&amp;#13;&amp;#10;96DWrrVcfIl/c0nnbr/fb3czXSxTA7KPrSX8aq3T2mg4eAOy+PYSvtXfGAw6Dt6ALL6zhB9d6nZa&amp;#13;&amp;#10;Lt6AIkaT/SW0DuholHEvIFPOtirhqwBfrWXwBQqyocguLWLKE3VSrsX4LhcjAGggw4omSM1TMsU+&amp;#13;&amp;#10;5OQAxxNBsRaA1wgufbEkXy6RtCwkfUFT1fM+THHilSAvn33/8tkTdHT/6dH9n44ePDi6/6Nl5Iza&amp;#13;&amp;#10;wklYHvXi28/+fPQx+uPJNy8eflGNl2X8rz988svPn1cDoXwW5j3/8vFvTx8//+rT3797WAHfEHhS&amp;#13;&amp;#10;ho9pTCS6QQ7RLo/BMOMVV3MyEa82YhxhWh6xkYQSJ1hLqeA/VJGDvjHHLIuOo0efuB68LaB9VAGv&amp;#13;&amp;#10;zu46Cu9FYqZoheRrUewAtzlnfS4qvXBNyyq5eTxLwmrhYlbG7WJ8UCV7gBMnvsNZCn0zT0vH8EFE&amp;#13;&amp;#10;HDV3GE4UDklCFNLf+D4hFdbdodTx6zb1BZd8qtAdivqYVrpkTCdONi0GbdEY4jKvshni7fhm+zbq&amp;#13;&amp;#10;c1Zl9SY5cJFQFZhVKD8mzHHjVTxTOK5iOcYxKzv8OlZRlZJ7c+GXcUOpINIhYRwNAyJl1ZibAuwt&amp;#13;&amp;#10;Bf0aho5VGfZtNo9dpFB0v4rndcx5GbnJ9wcRjtMq7B5NojL2A7kPKYrRDldV8G3uVoh+hzjg5MRw&amp;#13;&amp;#10;36bECffp3eAWDR2VFgmiv8yEjiW0aqcDxzT5u3bMKPRjmwPn146hAT7/+lFFZr2tjXgD5qSqStg6&amp;#13;&amp;#10;1n5Pwh1vugMuAvr299xNPEt2CKT58sTzruW+a7nef77lnlTPZ220i94KbVevG+yi2CyR4xNXyFPK&amp;#13;&amp;#10;2J6aM3JdmkWyhHkiGAFRjzM7QVLsmNIIHrO+7uBCgc0YJLj6iKpoL8IpLLDrnmYSyox1KFHKJWzs&amp;#13;&amp;#10;DLmSt8bDIl3ZbWFbbxhsP5BYbfPAkpuanO8LCjZmtgnN5jMX1NQMziqseSljCma/jrC6VurM0upG&amp;#13;&amp;#10;NdPqHGmFyRDDZdOAWHgTFiAIli3g5Q7sxbVo2JhgRgLtdzv35mExUTjPEMkIBySLkbZ7OUZ1E6Q8&amp;#13;&amp;#10;V8xJAORORYz0Ju8Ur5WkdTXbN5B2liCVxbVOEJdH702ilGfwIkq6bo+VI0vKxckSdNjzuu1G20M+&amp;#13;&amp;#10;TnveFPa08BinEHWp13yYhXAa5Cth0/7UYjZVvohmNzfMLYI6HFNYvy8Z7PSBVEi1iWVkU8N8ylKA&amp;#13;&amp;#10;JVqS1b/RBreelwE2019Di+YqJMO/pgX40Q0tmU6Jr8rBLlG07+xr1kr5TBGxFwWHaMJmYhdD+HWq&amp;#13;&amp;#10;gj0BlXA0YTqCfoFzNO1t88ltzlnRlU+vDM7SMUsjnLVbXaJ5JVu4qeNCB/NWUg9sq9TdGPfqppiS&amp;#13;&amp;#10;PydTymn8PzNFzydwUtAMdAR8OJQVGOl67XlcqIhDF0oj6o8ELBxM74BsgbNY+AxJBSfI5leQA/1r&amp;#13;&amp;#10;a87yMGUNGz61S0MkKMxHKhKE7EBbMtl3CrN6NndZlixjZDKqpK5MrdoTckDYWPfAjp7bPRRBqptu&amp;#13;&amp;#10;krUBgzuef+57VkGTUC9yyvXm9JBi7rU18E+vfGwxg1FuHzYLmtz/hYoVs6odb4bnc2/ZEP1hscxq&amp;#13;&amp;#10;5VUBwkpTQTcr+9dU4RWnWtuxlixutHPlIIrLFgOxWBClcN6D9D+Y/6jwmb1t0BPqmO9Cb0Vw0aCZ&amp;#13;&amp;#10;QdpAVl+wCw+kG6QlTmDhZIk2mTQr69ps6aS9lk/W57zSLeQec7bW7CzxfkVnF4szV5xTi+fp7MzD&amp;#13;&amp;#10;jq8t7URXQ2SPlyiQpvlGxgSm6tZpG6doEtZ7Htz8QKDvwRPcHXlAa2haQ9PgCS6EYLFkb3F6XvaQ&amp;#13;&amp;#10;U+C7pRSYZk5p5phWTmnllHZOgcVZdl+SUzrQqfQVB1yx6R8P5bcZsILLbj/ypupcza3/BQAA//8D&amp;#13;&amp;#10;AFBLAwQUAAYACAAAACEAbaHXWlsEAAAgDAAAGwAAAGNsaXBib2FyZC9jaGFydHMvY2hhcnQxLnht&amp;#13;&amp;#10;bJxWTW/jNhC9F+h/UIUc2sPakixLshF74WSx2wUS1IiTPfTGSGNbDUUKFB3b/77DL1n2Vltjc3Co&amp;#13;&amp;#10;meHjzJvhcG4/HirqvYNoSs5mfjgIfA9YzouSbWb+y/PnD5nvNZKwglDOYOYfofE/zn/95Taf5lsi&amp;#13;&amp;#10;5KomOXgIwpppPvO3UtbT4bDJt1CRZsBrYKhbc1ERiZ9iMywE2SN4RYdRECRDDeJbAPITABUpmdsv&amp;#13;&amp;#10;rtnP1+syh08831XApPFCACUSGWi2Zd34cwyuIBLCSRB774QiL/5QCSlhGyMA9uFlZYQ6AqWVpaSg&amp;#13;&amp;#10;Fwf1K8p8O78l01deHJcC95MpbeRKHinoj1pJ6qVQ/wpYP2mbYSvScrEUnjp05rcHkqmcL7mQhHp/&amp;#13;&amp;#10;8gpqsgFvlRNKXktayuMtIsi5+kUAhYa/zhdcSO0aJUe+k+iFkjiva8rlQgAxgSoDtaoI2xH6oDec&amp;#13;&amp;#10;NM9EbEAaKkrGQBgqDo+8AEtQsQEjPP6X8GCsgkEYplEwjrM4DSeTbBTGdlOrT5MgHadpPBlPoiTN&amp;#13;&amp;#10;IqPfO30WZ9koSJI4nIzjNJtY/dbpkyiJoiQL02wcjaIwVdsx6vOwUGAoURE2OZESxL2q7s63TpxB&amp;#13;&amp;#10;bSrO5faRiDcXeAPIdj4tCxeX8ZKLAoT1xEgM/40UT7BWO9bz1RZAhr/d3N2EyjEtRf09wSukLGp5&amp;#13;&amp;#10;z3fMcm3rsJYeHjXzA19ZvM8XeIFVHTxBU2MRg/dcVuD93kDOWdH8oXDfddi1Kg0MscU3H9oZXBrv&amp;#13;&amp;#10;iodX2ihgeTDVeX0Fe6/2rpzqGFixJIJgeV9Wclud5hx0a8v337CuT1cOfWq9OaBKecV21XfkLW6i&amp;#13;&amp;#10;6c3iJjxRiFYthab93GNtzr8AFiuhmmndlLT0O5oDk61LnsfBOZUqOyYToc1EGPSaRM6kH2VkTbAz&amp;#13;&amp;#10;9h0UO5N+lLE1GfWjJM6kHyW1JnHU60vmTPpRJtZkfOkLZvaUIvPhqtAl+viDhN+phOOV+d+EBwPt&amp;#13;&amp;#10;fqcErk121JcCl+teA5fpaKDdO129U720mR5grrt/vaBt4gfR5Owv6/PT1UF09Q5XFtEg7gN1ZREN&amp;#13;&amp;#10;kj4TVxajQdpn4soiHgRnsUwuQH9QJa46TDM+7xm2HZPD18IoxgE+H1lqH4czeRLGQWZfhcvWj41o&amp;#13;&amp;#10;oR/Msx0dJNxAcZhRbYmLEscJPUWYM6uSPZKDaSQVsQ8D3oPTWW4rOSx5Yza9Gnu8Gp8r6Z2qdubb&amp;#13;&amp;#10;zoXTGN+JHB5K9gZFO5nIMn/Dtt3iUL43SLngTbNoT5+04eL8plRgDyY7yf8GwTu77kDuAZiLprgn&amp;#13;&amp;#10;0mgr8g8XL6y0j9LYhdTS1S7OeOscfR1vmP2OYYcl2vHjiygLJBIafNh1T7kkDjvAlaQxOMjnLgMd&amp;#13;&amp;#10;3jpJ/0neMBrLC67Ohi3Y4COpvKd61SbR0t2d1oyFslUI38rmL0aPJkN6NkDodh7FaEAwQj8RSTyB&amp;#13;&amp;#10;w8nMF18LO0Ls8I6stqTG/LcqfT0cgh7s5/8CAAD//wMAUEsDBBQABgAIAAAAIQBnA+6GzgAAAKwB&amp;#13;&amp;#10;AAAqAAAAY2xpcGJvYXJkL2RyYXdpbmdzL19yZWxzL2RyYXdpbmcxLnhtbC5yZWxzrJDNasMwDIDv&amp;#13;&amp;#10;g72D0X1W0sMYo04vpdDr6B5AOMoPTWxjqWV9+5kWxgKFXnqRkIQ+fWi9+Zknc+YsYwwOaluB4eBj&amp;#13;&amp;#10;O4bewfdh9/YBRpRCS1MM7ODCApvm9WX9xRNpWZJhTGIKJYiDQTV9IoofeCaxMXEoky7mmbSUucdE&amp;#13;&amp;#10;/kg946qq3jH/Z0CzYJp96yDv2xWYwyWVy4/ZsetGz9voTzMHvXMCtXhxAVLuWR1Ye+vcYm2LK+B9&amp;#13;&amp;#10;jfqZGn6grAuNa0fwmv48cPHj5hcAAP//AwBQSwECLQAUAAYACAAAACEAg7XtPxwBAAAuAwAAEwAA&amp;#13;&amp;#10;AAAAAAAAAAAAAAAAAAAAW0NvbnRlbnRfVHlwZXNdLnhtbFBLAQItABQABgAIAAAAIQCtMD/xwQAA&amp;#13;&amp;#10;ADIBAAALAAAAAAAAAAAAAAAAAE0BAABfcmVscy8ucmVsc1BLAQItABQABgAIAAAAIQB27EByXQIA&amp;#13;&amp;#10;AMkIAAAfAAAAAAAAAAAAAAAAADcCAABjbGlwYm9hcmQvZHJhd2luZ3MvZHJhd2luZzIueG1sUEsB&amp;#13;&amp;#10;Ai0AFAAGAAgAAAAhAOxw7Oh5AQAAGQQAAB8AAAAAAAAAAAAAAAAA0QQAAGNsaXBib2FyZC9kcmF3&amp;#13;&amp;#10;aW5ncy9kcmF3aW5nMS54bWxQSwECLQAUAAYACAAAACEAPacxHxoBAAAFAgAAJgAAAAAAAAAAAAAA&amp;#13;&amp;#10;AACHBgAAY2xpcGJvYXJkL2NoYXJ0cy9fcmVscy9jaGFydDEueG1sLnJlbHNQSwECLQAUAAYACAAA&amp;#13;&amp;#10;ACEA4VE3H88GAADmGwAAGgAAAAAAAAAAAAAAAADlBwAAY2xpcGJvYXJkL3RoZW1lL3RoZW1lMS54&amp;#13;&amp;#10;bWxQSwECLQAUAAYACAAAACEAbaHXWlsEAAAgDAAAGwAAAAAAAAAAAAAAAADsDgAAY2xpcGJvYXJk&amp;#13;&amp;#10;L2NoYXJ0cy9jaGFydDEueG1sUEsBAi0AFAAGAAgAAAAhAGcD7obOAAAArAEAACoAAAAAAAAAAAAA&amp;#13;&amp;#10;AAAAgBMAAGNsaXBib2FyZC9kcmF3aW5ncy9fcmVscy9kcmF3aW5nMS54bWwucmVsc1BLBQYAAAAA&amp;#13;&amp;#10;CAAIAFECAACWFAAAAAA=&amp;#13;&amp;#10;" o:spid="_x0000_i1025"&gt;&lt;v:imagedata mce_src="file:///C:\Users\eddiel\AppData\Local\Temp\msohtmlclip1\01\clip_image001.png" o:title="" src="file:///C:\Users\eddiel\AppData\Local\Temp\msohtmlclip1\01\clip_image001.png"&gt;&lt;/v:imagedata&gt;&lt;o:lock v:ext="edit" aspectratio="f"&gt;&lt;/o:lock&gt;&lt;/v:shape&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;IMG style="WIDTH: 526px; HEIGHT: 298px" title="Response Time Graph" alt="Response Time Graph" align=middle src="http://lgn4pg.blu.livefilestore.com/y1pe-Ip7eWxbCyjusySxw2j5g7cJqcI2PJfHkrXbr8JfUk4Txg-Zp456hWPijX0v0BrUQAxngKorQEg25x0kM2ZVWSRnez5h7Xo/Response%20Time%20Graph.PNG" width=526 height=298 mce_src="http://lgn4pg.blu.livefilestore.com/y1pe-Ip7eWxbCyjusySxw2j5g7cJqcI2PJfHkrXbr8JfUk4Txg-Zp456hWPijX0v0BrUQAxngKorQEg25x0kM2ZVWSRnez5h7Xo/Response%20Time%20Graph.PNG"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;To create a meaningful Response Time Graph, it does not require the purchase of expensive tools or running a dozen application load tests.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;At a minimum you will need:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Visual Studio 2008 Team Test Edition or Team Suite (90-day trial available for download &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d95598d7-aa6e-4f24-82e3-81570c5384cb&amp;amp;DisplayLang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d95598d7-aa6e-4f24-82e3-81570c5384cb&amp;amp;DisplayLang=en"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Log Parser 2.2 (free download available &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=890cd06b-abf8-4c25-91b2-f8d975cf8c07&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=890cd06b-abf8-4c25-91b2-f8d975cf8c07&amp;amp;displaylang=en"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;IIS (Internet Information Services) Log&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Office Excel&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The step-by-step instructions provided below do not cover the basics of using Visual Studio testing features such as creating a web test.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For more information, please look at a list of comprehensive &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/edglas/pages/content-index-for-web-tests-and-load-tests.aspx" mce_href="http://blogs.msdn.com/edglas/pages/content-index-for-web-tests-and-load-tests.aspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;resources&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; on the web available off Ed Glas's &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/edglas/default.aspx" mce_href="http://blogs.msdn.com/edglas/default.aspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Also consider this 7-minute &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/jimmymay/archive/2009/02/23/vsts-web-test-step-by-step-primer-7-minute-video-by-microsoft-a-c-e-performance-engineer-chris-lundquist-with-copious-notes-screen-shots-from-your-humble-correspondent.aspx" mce_href="http://blogs.msdn.com/jimmymay/archive/2009/02/23/vsts-web-test-step-by-step-primer-7-minute-video-by-microsoft-a-c-e-performance-engineer-chris-lundquist-with-copious-notes-screen-shots-from-your-humble-correspondent.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;web test step-by-step primer&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; by A.C.E. Performance Engineer Chris Lundquist.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Enable the &lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;time-taken&lt;/I&gt;&lt;/B&gt; field in your target application’s Internet Information Services (IIS) log under IIS Manager.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Leave the default log format of &lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;W3C&lt;/I&gt;&lt;/B&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Create a new folder under the IIS Log directory (e.g., Test01) and assign it to store the log files. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Execute your load test with the &lt;U&gt;Step Load Pattern&lt;/U&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As illustrated in the table below, the test begins with 10 users, incrementing by 10 users every 20 seconds until 500 concurrent users are loaded.&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV align=center&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: auto auto auto 0.5in; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid #4F81BD 1.0pt; mso-border-themecolor: accent1; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt" class=LightGrid-Accent11 border=1 cellSpacing=0 cellPadding=0 class="LightGrid-Accent11"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: -1; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 2.25pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4f81bd 1pt solid; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-bottom-themecolor: accent1" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 5" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Load Pattern&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4f81bd 1pt solid; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1" vAlign=top width=49&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Step&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 0"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Initial User Count&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 64" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;10&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Maximum User Count&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 128" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;500&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 2"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Step Duration (seconds)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 64" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;20&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 3"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Step Ramp Time (seconds)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 128" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;0&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 4; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Step User Count&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 64" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;10&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Execute the test and record the start and end time (also available in the Load Test Summary report).&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;5)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Copy the IIS logs to a client workstation with LogParser and Excel installed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;6)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Open Excel and create a new spreadsheet with 3 columns: timestamp (A), # of concurrent users (B) and response time (C).&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;7)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Populate column A and B with information you &lt;U&gt;already know&lt;/U&gt; either manually or using an Excel formula. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;For example based on the load pattern defined above I know ~100 users were simulated on the system after approximately 3 minutes into the test.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Alternatively, extract data directly from the graphs (User Load) in Visual Studio.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;8)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Calculate the average response time of your test scenario (e.g. an ASPX page or a web service call) using LogParser:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=3 face=Calibri&gt;&lt;EM&gt;logparser "SELECT TO_LOCALTIME(QUANTIZE(TO_TIMESTAMP(date, time),60)), Avg(time-taken) AS AvgTime INTO C:\MyTemp\Homepage.csv from C:\Users\eddiel\Desktop\LogIn\ex*.log where (To_Lowercase(cs-uri-stem) like '%/s/app/default.aspx%') and sc-status = 200 and cs-method like 'GET' GROUP BY TO_LOCALTIME(QUANTIZE(TO_TIMESTAMP(date, time),60))" -i:IISW3C -o:CSV&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=3 face=Calibri&gt;The sample query above is used to calculate the average response time on GET requests to “/s/app/default.aspx” resulted in HTTP status 200, based on 60 seconds increment (quantize function).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In other words, I know precisely the average execution time of the portal’s homepage by the minute as user load increases.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;9)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Populate column C (response time) in the spreadsheet created earlier by matching the timestamp.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is fine when there are more LogParser output rows than what you have defined for column A. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;10)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Create your Response Time Graph (Scatter with Smooth Line type) in Excel.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Add X and Y axis labels accordingly.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Completing step 1 to step 10 should take less than 30 minutes. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;The result is a meaningful Response Time Graph that is illustrating your application performance—a picture that’s worth a thousand words!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I invite your questions and comments.&amp;nbsp; By &lt;STRONG&gt;Eddie Lau&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9900116" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author><category term="Performance" scheme="http://blogs.msdn.com/ace_team/archive/tags/Performance/default.aspx" /><category term="Tools" scheme="http://blogs.msdn.com/ace_team/archive/tags/Tools/default.aspx" /></entry><entry><title>Anti-XSS Library v3.1 Released!</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/09/17/anti-xss-library-v3-1-released.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/09/17/anti-xss-library-v3-1-released.aspx</id><published>2009-09-17T23:53:00Z</published><updated>2009-09-17T23:53:00Z</updated><content type="html">&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;The Microsoft &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/securitytools/" mce_href="http://blogs.msdn.com/securitytools/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Information Security Tools&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; (IST) team has released the latest Microsoft &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=051EE83C-5CCF-48ED-8463-02F56A6BFC09&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?familyid=051EE83C-5CCF-48ED-8463-02F56A6BFC09&amp;amp;displaylang=en"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Anti-Cross Site Scripting (Anti-XSS) Library version 3.1&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;.&amp;nbsp; Read more about Anti-XSS v3.1 on the &lt;A title="Information Security Blog" href="http://blogs.msdn.com/infosec/archive/2009/09/17/anti-xss-3-1-released.aspx" target=_blank mce_href="http://blogs.msdn.com/infosec/archive/2009/09/17/anti-xss-3-1-released.aspx"&gt;Information Security blog&lt;/A&gt; and watch the video, “&lt;A title="Anti-XSS 3.0 Released" href="http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/" target=_blank mce_href="http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/"&gt;Anti-XSS 3.0 Released&lt;/A&gt;,” as Vineet Batta and Anil Revuru (RV), Senior Software Developers from the Microsoft &lt;A title="Information Security Tools" href="http://blogs.msdn.com/securitytools/default.aspx" target=_blank mce_href="http://blogs.msdn.com/securitytools/default.aspx"&gt;Information Security Tools&lt;/A&gt; (IST), provide an overview of the Anti-XSS Library and how it can prevent XSS attacks in your application.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Diane Talvo &lt;BR&gt;Security Awareness Program Manager &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9896502" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author><category term="Anti-XSS" scheme="http://blogs.msdn.com/ace_team/archive/tags/Anti-XSS/default.aspx" /></entry><entry><title>Introducing the Connected Information Security Framework (CISF) and Risk Tracker Version 1.0</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/09/16/introducing-the-connected-information-security-framework-cisf-and-risk-tracker-version-1-0.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/09/16/introducing-the-connected-information-security-framework-cisf-and-risk-tracker-version-1-0.aspx</id><published>2009-09-16T21:34:00Z</published><updated>2009-09-16T21:34:00Z</updated><content type="html">&lt;P align=justify&gt;&lt;FONT face=verdana,geneva&gt;The Microsoft Information Security Tools (IST) team has released the &lt;A title="CISF: Build Custom Security Solutions" href="http://edge.technet.com/Media/CISF-Connected-Information-Security-Framework/" target=_blank mce_href="http://edge.technet.com/Media/CISF-Connected-Information-Security-Framework/"&gt;Connected Information Security Framework (CISF)&lt;/A&gt;, a software development framework comprises of API’s and reusable components that is designed to ‘create bespoke or custom information security and risk management solutions.’ Additionally along with this release of CISF, the IST team is also releasing the first custom application using CISF called &lt;A title="Risk Tracker: Reducing Risks at Microsoft" href="http://edge.technet.com/Media/Risk-Tracker/" target=_blank mce_href="http://edge.technet.com/Media/Risk-Tracker/"&gt;Risk Tracker version 1.0&lt;/A&gt; that manages and tracks information security risk. Read more about CISF and the Risk Tracker application as Todd Kutzke, Senior Director from &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/security/dd547422.aspx" mce_href="http://msdn.microsoft.com/en-us/security/dd547422.aspx"&gt;&lt;FONT face=verdana,geneva&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt;, provides an overview in his recent blog, “&lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/infosec/archive/2009/09/15/announcing-the-connected-information-security-framework-cisf-and-risk-tracker.aspx" mce_href="http://blogs.msdn.com/infosec/archive/2009/09/15/announcing-the-connected-information-security-framework-cisf-and-risk-tracker.aspx"&gt;&lt;FONT face=verdana,geneva&gt;Announcing the Connected Information Security Framework (CISF) and Risk Tracker&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt;.”&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;-Diane Talvo&lt;BR&gt;Security Awareness Program Manager&lt;BR&gt;&lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;&lt;FONT color=#0065e2&gt;&lt;FONT face=verdana,geneva&gt;Microsoft Information Security&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9895985" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author><category term="CISF" scheme="http://blogs.msdn.com/ace_team/archive/tags/CISF/default.aspx" /><category term="Risk Tracker" scheme="http://blogs.msdn.com/ace_team/archive/tags/Risk+Tracker/default.aspx" /></entry><entry><title>Blog Series: Get Familiar with the SDL-LOB Process. Introduction to Phase Five: Release for LOB</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/08/10/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-five-release-for-lob.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/08/10/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-five-release-for-lob.aspx</id><published>2009-08-11T02:11:00Z</published><updated>2009-08-11T02:11:00Z</updated><content type="html">&lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;Hello, Anmol here.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;As you’ve been following along with me in my blog series on &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;a title="SDL-LOB" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;Security Development Lifecycle for Line-of-Business applications (SDL-LOB)&lt;/a&gt;&lt;/span&gt; , I’ve talked about &lt;span style="line-height: 112%; font-family: &amp;#39;ver&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;a title="SDL-LOB Phase One: Requirements for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;Phase One&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;, &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;font color="#0000ff"&gt;&lt;a title="SDL-LOB Phase Two: Design for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx"&gt;Two&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;, &lt;span style="line-height: 112%; font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;font color="#0000ff"&gt;&lt;a title="SDL-LOB Phase Three: Implementation for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx"&gt;Three&lt;/a&gt;&lt;/font&gt;&lt;/span&gt; and &lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-font-size: 11.0pt"&gt;&lt;a title="SDL-LOB Phase Four: Verification for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx"&gt;Four&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Today, I’ll discuss the last phase - &lt;b style="mso-bidi-font-weight: normal"&gt;&lt;i style="mso-bidi-font-style: normal"&gt;Phase Five: Release for LOB&lt;/i&gt;&lt;/b&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;SDL-LOB defines standards and best practices for providing security and privacy for line-of-business (LOB) applications either in development or being planned for development.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;In the Release phase, now that the application is live in production, a &lt;i style="mso-bidi-font-style: normal"&gt;post-production assessment&lt;/i&gt; takes place. It is important to note that this is a continuous process and all applications/hosts/network devices are in scope.&lt;span style="line-height: 112%; font-family: &amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 8pt"&gt; &lt;/span&gt;This type of assessment performed by an operations team and involves verification of patch management, compliance, network and host scanning as well as responding to incremental releases for hotfixes and service packs. Typically the assessment occurs on a continuous regular cycle and integrates with an existing management process already in place established by the compliance group.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;font size="2" face="ver"&gt;Highlight for this phase include:&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Host-level security              &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;      &lt;ul&gt;       &lt;li&gt;         &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Patch Management                &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: &amp;#39;Segoe UI&amp;#39;; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2" face="ver"&gt;Appropriate configuration                &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="mso-bidi-font-family: &amp;#39;Segoe UI&amp;#39;; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Antivirus                &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Compliance                &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;       &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Review access control/permissions              &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;/b&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Server auditing and logging              &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;strong&gt;Network level security&lt;/strong&gt;               &lt;br /&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Application retirement &lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;         &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;       &lt;/b&gt;&lt;/div&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="mso-bookmark: _toc26865442"&gt;&lt;span style="mso-bookmark: _toc26845431"&gt;&lt;span style="mso-bookmark: _toc29787492"&gt;&lt;span style="mso-bookmark: _toc90435890"&gt;&lt;span style="mso-bookmark: _toc94327020"&gt;&lt;span style="mso-bookmark: _toc96833554"&gt;&lt;span style="mso-bookmark: _toc96838661"&gt;&lt;span style="mso-bookmark: _toc217797264"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;Under every task given above,&lt;/span&gt; there are several &lt;i style="mso-bidi-font-style: normal"&gt;security requirements&lt;/i&gt; that the application team follows. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Here’s the complete list of security requirements &lt;font color="#0000ff"&gt;&lt;a title="Security Requirements" href="http://msdn.microsoft.com/en-us/library/dd831974.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831974.aspx"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-font-size: 11.0pt"&gt;here&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/font&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Concluding my blog series I’ve talked about all 5 phases of SDL-LOB, providing you a brief highlight of each of the phases.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Take some time and review all phases of the &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;a title="SDL-LOB" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;&lt;font color="#0000ff"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-font-size: 11.0pt"&gt;SDL-LOB&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt; in detail.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="mso-bidi-font-family: &amp;#39;Segoe UI&amp;#39;; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;To wrap up, here’s the phases again:&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;p&gt;&lt;a title="Phase One: Requirements for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;&lt;font color="#0000ff" face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 115%; font-size: 10pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;Phase One: Requirements for LOB&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a title="Phase Two: Design for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx"&gt;&lt;font color="#0000ff" size="2" face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 115%; font-size: 9pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;Phase Two: Design for LOB&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a title="Phase Three: Implementation for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx"&gt;&lt;font color="#0000ff" size="2" face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 115%; font-size: 9pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;Phase Three: Implementation for LOB&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a title="Phase Four: Verificatoin for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx"&gt;&lt;font size="2" face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 115%; font-size: 9pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;Phase Four: Verification for LOB&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;&lt;a title="Phase Five: Release for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/08/10/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-five-release-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/08/10/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-five-release-for-lob.aspx"&gt;&lt;font size="2" face="ver"&gt;Phase Five:&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Release for LOB&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt; &lt;/ul&gt; &lt;span style="mso-bookmark: _toc21158575"&gt;&lt;/span&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;-Anmol Malhotra          &lt;br /&gt;Senior Security Engineer           &lt;br /&gt;ACE Team           &lt;br /&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9863622" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author></entry><entry><title>Video Series: ACE Security Consultants from the Field</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/08/04/video-series-ace-security-consultants-from-the-field.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/08/04/video-series-ace-security-consultants-from-the-field.aspx</id><published>2009-08-04T23:45:00Z</published><updated>2009-08-04T23:45:00Z</updated><content type="html">&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Kicking off our video series, ‘&lt;I style="mso-bidi-font-style: normal"&gt;ACE Security Consultants from the Field,&lt;/I&gt;’ Talhah Mir from &lt;/FONT&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Microsoft Information Security&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;, talks to&amp;nbsp;two passionate individuals about security.&lt;I style="mso-bidi-font-style: normal"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Watch the podcast, “&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A title="ACE From the Field: Carric 'DEFCON Goon' Dooley" href="http://edge.technet.com/Media/ACE-From-the-Field-Carric-Dooley/" target=_blank mce_href="http://edge.technet.com/Media/ACE-From-the-Field-Carric-Dooley/"&gt;ACE from the Field: Carric 'DEFCON Goon' Dooley&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;,” as Carric Dooley, Senior Security Consultant from Microsoft ACE Team, talks about his broad security experience including pen testing (on non-Microsoft platforms), the completeness of security and more. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Roger Grimes, Security Architect from Microsoft ACE Team in this video, “&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A title="ACE From the Field: Roger Grimes &amp;amp; Securing the Internet" href="http://edge.technet.com/Media/ACE-From-the-Field-Roger-Grimes--Securing-the-Internet/" target=_blank mce_href="http://edge.technet.com/Media/ACE-From-the-Field-Roger-Grimes--Securing-the-Internet/"&gt;ACE from the Field: Roger Grimes &amp;amp; Securing the Internet&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;,” discusses his lifelong passion for making the internet more secure.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;He shares his thoughts on how security has evolved, where it stands, how it can be fixed including how most&amp;nbsp;hacks can actually be avoided by the user. &lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Calibri&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;More videos coming up from&amp;nbsp;ACE security consultants in the field, stay tuned...&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;-Diane Talvo&lt;BR&gt;Security Awareness Program Manager&lt;BR&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Microsoft Information Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9857433" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author><category term="Security" scheme="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx" /></entry><entry><title>Blog Series: Get Familiar with the SDL-LOB Process. Introduction to Phase Four: Verification for LOB</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx</id><published>2009-07-30T00:43:00Z</published><updated>2009-07-30T00:43:00Z</updated><content type="html">&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;Hello, Anmol here…continuing our discussion of &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="Security Development Lifecycle for Line-of-Business applications (SDL-LOB)" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;Security Development Lifecycle for Line-of-Business applications (SDL-LOB)&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt; process, let’s discuss &lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;Phase Four: Verification for LOB &lt;/I&gt;&lt;/B&gt;today.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The SDL-LOB defines the standards and best practices for providing security and privacy for new and existing line-of-business (LOB) applications currently under development or being planned for development.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If you missed prior phases, read them here: &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 1" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target=_blank&gt;Phase One&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;, &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 2" href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx" target=_blank&gt;Phase Two&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt; and &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 3" href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target=_blank&gt;Phase Three&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;. 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/FONT&gt;&lt;/SPAN&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;Phase 4 is all about verifying different security claims made in earlier phases and identifying gaps in implementation. For example, during design review phase, let’s assume an application team identifies that the design is vulnerable to cross site scripting attacks and therefore adds security requirements such as &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-font-size: 11.0pt; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;FONT face=verdana,geneva&gt;&lt;A title="AntiXSS Library 3.0" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=051ee83c-5ccf-48ed-8463-02f56a6bfc09&amp;amp;displaylang=en" target=_blank&gt;AntiXSS library&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; to be incorporated during coding. During the verification phase, a security SME &lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt;(subject matter experts) &lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;will verify that all user controlled data which needed to be validated and encoded is actually *done*. If there are any gaps identified, they will be triggered as security bugs for the application teams to fix. 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;Here are a few key tasks to be executed in this phase:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;Conduct pre-production assessment (white box/black box reviews, deployment reviews of servers &amp;amp; privacy reviews) &lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;Identify security issues and applying a severity rating. &lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;FONT face=verdana,geneva&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;Compliance: Tracking all risks identified. 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Before a line-of-business (LOB) application is deployed in production, the application must adhere to internal security policies, guidance and follow industry best practice. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;As mentioned above, in this phase expert application security SMEs are engaged.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;One way a SME verifies an application is by performing a &lt;I style="mso-bidi-font-style: normal"&gt;pre-production assessment&lt;/I&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What’s a pre-production assessment?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It’s an assessment performed based on the service level assigned depending on the application’s risk rating.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Back in “&lt;/FONT&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 1" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;Phase 1: Requirements for LOB&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT face=verdana,geneva&gt;&lt;I style="mso-bidi-font-style: normal"&gt;” &lt;/I&gt;a Risk Assessment was conducted which determines an application’s risk level.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Based on the risk level, a service level is then assigned.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Generally white box code review is conducted on applications that are medium or high risk rating.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;An ideal comprehensive assessment will be a combination of white and black box testing.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Having said this, performing the assessment with a mix of manual process automated tools can help save some time.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For code reviews (white box) testing, a SME will identify &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="Categories of Vulnerabilities" href="http://msdn.microsoft.com/en-us/library/ms998364.aspx#paght000027_step3" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/ms998364.aspx#paght000027_step3"&gt;categories of vulnerabilities&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; in the code.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Here are some vulnerabilities that are identified:&lt;SPAN class=BodyText2Char&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-SIZE: 10pt; mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;&lt;SPAN class=BodyText2Char&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-SIZE: 10pt; mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=verdana,geneva&gt;SQL injection. Ensure that the SQL queries are parameterized (preferably within a stored procedure) and that any input used in a SQL query is validated.&amp;nbsp; &lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Cross-site scripting. Ensure that user controlled data is encoded properly before rendering to the browser.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;.NET applications can leverage Anti-XSS library for encoding data that is more rigorous than the native .NET encoding. &lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Cross-site request forgery. Ensure that the Page.ViewStateUserKey property is set to a unique value that prevents one-click attacks on your application from malicious users. &lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Data access. Look for improper storage of database connection strings and proper use of authentication to the database. &lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Input/data validation. Look for client-side validation that is not backed by server-side validation, poor validation techniques, and reliance on file names or other insecure mechanisms to make security decisions.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;See the complete list of vulnerabilities and learn more about &lt;A title="SDL-LOB Process: Phase 4 - Verification for LOB" href="http://msdn.microsoft.com/en-us/library/dd831973.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831973.aspx"&gt;verification &lt;/A&gt;&lt;/FONT&gt;&lt;FONT face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 4 - Verification for LOB" href="http://msdn.microsoft.com/en-us/library/dd831973.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831973.aspx"&gt;in this Phase 4&lt;/A&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Watch the podcast called “&lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-font-size: 11.0pt; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;FONT face=verdana,geneva&gt;&lt;A title="SDL-LOB Phase 3: Implementation" href="http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/" target=_blank&gt;SDL-LOB Phase Three: Implementation&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt;” where Eugene Siu, Senior Security Engineer of Microsoft &lt;A title="Microsoft ACE Team" href="http://blogs.msdn.com/ace_team/default.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/default.aspx"&gt;ACE Team&lt;/A&gt;&lt;/FONT&gt;&lt;FONT face=verdana,geneva&gt;, provides an overview of code reviews and more.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;Next time I’ll discuss Phase 5: Release for LOB. Till then happy &amp;amp; secure coding. 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/FONT&gt;&lt;/SPAN&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="LINE-HEIGHT: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;FONT face=verdana,geneva&gt;-Anmol Malhotra &lt;BR&gt;Senior Security Engineer &lt;BR&gt;ACE Team&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt; 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9852580" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author></entry><entry><title>Blog Series: Get Familiar with the SDL-LOB Process. Introduction to Phase Three: Implementation for LOB.</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx</id><published>2009-07-13T19:49:00Z</published><updated>2009-07-13T19:49:00Z</updated><content type="html">&lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;Hello, Anmol here.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;For this blog series I’ll discuss the &lt;span style="font-family: &amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 10pt; mso-ansi-language: en-us; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-us; mso-bidi-language: ar-sa"&gt;the &lt;span style="mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-theme-font: minor-bidi; mso-ansi-font-size: 10.0pt; mso-ascii-font-family: verdana; mso-hansi-font-family: verdana"&gt;&lt;a title="Security Development Lifecycle for Line-of-Business applications (SDL-LOB)" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;Security Development Lifecycle for Line-of-Business applications (SDL-LOB)&lt;/a&gt;&lt;/span&gt; &lt;/span&gt;process and covering all 5 phases.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Today I’ll discuss &lt;b style="mso-bidi-font-weight: normal"&gt;&lt;i style="mso-bidi-font-style: normal"&gt;Phase Three: Implementation for LOB&lt;/i&gt;&lt;/b&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;The SDL-LOB defines the standards and best practices for providing security and privacy for new and existing line-of-business (LOB) applications currently under development or being planned for development&lt;span style="mso-bidi-font-family: arial"&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;If you missed prior phases, here’s &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-size: 11.0pt"&gt;&lt;a title="Phase 1 - SDL-LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;&lt;font size="2"&gt;Phase 1&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: arial"&gt; and &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-size: 11.0pt"&gt;&lt;a title="SDL-LOB Phase 2" href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx"&gt;&lt;font size="2"&gt;Phase 2&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: arial"&gt;.       &lt;p&gt;&lt;/p&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;Highlight for phase three are: &lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto 0in auto 0.75in; mso-list: l0 level1 lfo1" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;Incorporate Security Checklist and Review Policies       &lt;p&gt;&lt;/p&gt;     &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto 0in auto 0.75in; mso-list: l0 level1 lfo1" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;Conduct ‘Self’ Code Review       &lt;p&gt;&lt;/p&gt;     &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto 0in auto 0.75in; mso-list: l0 level1 lfo1" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;Run Code Analysis Tools and Incorporate Security Libraries       &lt;p&gt;&lt;/p&gt;     &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;You may be wondering, what is a ‘self’ review?&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;A ‘self’ review involves assessing your application to ensure it complies with security checklists and standards; and conducting a self-directed code review and code analysis of the application.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;An internal review is performed by the application development team.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;It’s important for development teams to adopt coding techniques and methodologies.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;More importantly, the next step is to incorporate documented coding practices and forming a security checklist.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;A checklist creates a threshold for you to measure against, i.e., at minimum these items must be met.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Using a security checklist is not a new concept; however ensuring items not met on the checklist are sufficiently documented and accounted for is the &lt;i style="mso-bidi-font-style: normal"&gt;key&lt;/i&gt; to its effectiveness. See checklist items from the &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;a title="Security Checklist Index" href="http://msdn.microsoft.com/en-us/library/ms998392.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/ms998392.aspx"&gt;&lt;font size="2"&gt;Security Checklist Index&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt; from Microsoft Patterns and Practices.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;In this phase, development teams also conduct an independent “self” code review.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;To perform this task, there are several available security tools Microsoft offers including static analysis, runtime security tools and libraries.&lt;span style="mso-spacerun: yes"&gt;&amp;#160;&amp;#160; &lt;/span&gt;The &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font color="#0000ff" size="2"&gt;&lt;a title="Microsoft Information Security" href="http://www.msinfosec.com/" target="_blank" mce_href="http://www.msinfosec.com"&gt;Anti-XSS library&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt; can protect ASP.NET Web-based applications from XSS (cross-site scripting) attacks. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;It offers a more rigorous “white-list” approach than the native encoding methods found in .NET. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;Run &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font color="#0000ff" size="2"&gt;&lt;a title="Microsoft Information Security" href="http://www.msinfosec.com/" target="_blank" mce_href="http://www.msinfosec.com"&gt;CAT.NET&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt; on managed code (C#, Visual Basic .NET, J#) applications. CAT.NET is a snap-in to the Visual Studio IDE that helps you identify exploitable code paths for security vulnerabilities, such as XSS, SQL Injection, Process Command Injection and more. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;Get familiar with the &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;a title="SDL-LOB" href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831972.aspx"&gt;&lt;font size="2"&gt;SDL-LOB document&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt; and learn more about available tools and additional details on how to perform internal reviews for your application.       &lt;p&gt;&lt;/p&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font face="verdana,geneva"&gt;Next time I’ll discuss Phase Four: Verification for LOB. Till then happy &amp;amp; secure coding.        &lt;p&gt;&lt;/p&gt;     &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font face="verdana,geneva"&gt;-Anmol Malhotra        &lt;br /&gt;Senior Security Engineer         &lt;br /&gt;ACE Team&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="3" face="Calibri"&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9831951" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author></entry><entry><title>Blog Series: Get Familiar with the SDL-LOB Process, Introduction to Phase Two: Design for LOB</title><link rel="alternate" type="text/html" href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx" /><id>http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx</id><published>2009-06-20T04:29:00Z</published><updated>2009-06-20T04:29:00Z</updated><content type="html">&lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-ansi-language: en; mso-bidi-font-weight: bold" lang="EN"&gt;&lt;font face="verdana,geneva"&gt;Hello, Anmol here.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;This is a continuation of my blog series on the &lt;/font&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;&lt;font face="verdana,geneva"&gt;SDL-LOB process&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;In my last blog entry I talked about &lt;/font&gt;&lt;a href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;&lt;font face="verdana,geneva"&gt;Phase 1: Requirements for LOB&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt;&lt;b&gt;.&amp;#160; &lt;/b&gt;Let’s discuss Phase Two:&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Design for LOB.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;As you read my blog series on the SDL-LOB process, I will try to share experiences and lessons learned from an &lt;/font&gt;&lt;a href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;&lt;font face="verdana,geneva"&gt;Information Security&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt; group perspective.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;Phase Two is all about ensuring that application follows “Secure by Default” principle. &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;There are 2 key tasks to be executed in this phase:&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="mso-spacerun: yes"&gt;&lt;font face="verdana,geneva"&gt;&lt;/font&gt;&lt;/span&gt;&amp;#160;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class="MsoListParagraphCxSpFirst"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Threat Modeling&lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class="MsoListParagraphCxSpLast"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Design Review&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;Both of these activities are aimed towards identifying security design flaws upfront in the lifecycle and helping in reducing the number of security bugs propagating on to the next stages. It is far more resource intensive and cumbersome to mitigate issues identified during verification phase and even costlier if identified in production time. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;Let me illustrate this by an example shown below: &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="Verdana"&gt;&lt;/font&gt;&amp;#160;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;img style="width: 528px; height: 369px" title="SDL-LOB: Phase 2: Design for LOB" alt="SDL-LOB: Phase 2: Design for LOB" src="http://blogs.msdn.com/photos/ace_team/images/9792522/original.aspx" width="1167" height="633" mce_src="http://blogs.msdn.com/photos/ace_team/images/9792522/original.aspx" /&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;&lt;/font&gt;&amp;#160;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 8.5pt"&gt;     &lt;p&gt;&lt;font size="2" face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;Let’s assume that your design did not consider validating user controlled input and output encoding strategy. This would result in developers coding and developing the application without deviating from the final design which lacked specific security considerations in the first place. This would eventually result in 100s of “Cross Site Scripting” bugs turning up during verification stage. I am sure no application team would want that to happen. Wouldn’t it be nice if we followed few design time activities which would call out specific security considerations that need to be followed by the development team in the context of the application? &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;To learn more read the detailed Design phase tasks &lt;/font&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831971.aspx" mce_href="http://msdn.microsoft.com/en-us/library/dd831971.aspx"&gt;&lt;font face="verdana,geneva"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="mso-spacerun: yes"&gt; and also watch my podcast &amp;quot;&lt;a title="Security Design Reviews" href="http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/" target="_blank" mce_href="http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/"&gt;Security Design Reviews&lt;/a&gt;&amp;quot; where I discuss more why security should be &amp;quot;baked&amp;quot; into the application starting with the Design phase.&amp;#160; &lt;/span&gt;Next time, I’ll talk about Phase Three: Implementation for LOB.&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;Here are some additional resources &lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;div style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" mce_href="http://msdn.microsoft.com/en-us/security/aa570413.aspx"&gt;&lt;font color="#0000ff" face="verdana,geneva"&gt;Threat Analysis and Modeling&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt; &lt;/font&gt;&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/aa302421.aspx" mce_href="http://msdn.microsoft.com/en-us/library/aa302421.aspx"&gt;&lt;font color="#0000ff" face="verdana,geneva"&gt;Conducting Design Reviews&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt; &lt;/font&gt;&lt;/div&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-ansi-language: en; mso-bidi-font-size: 10.0pt" lang="EN"&gt;&lt;font face="verdana,geneva"&gt;-Anmol Malhotra        &lt;br /&gt;Senior Security Engineer         &lt;br /&gt;ACE Team&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-ansi-language: en; mso-bidi-font-size: 10.0pt" lang="EN"&gt;&lt;font face="Verdana"&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9792526" width="1" height="1"&gt;</content><author><name>ACE Team</name><uri>http://blogs.msdn.com/members/ACE+Team.aspx</uri></author></entry></feed>