<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ACE Team - Security, Performance &amp; Privacy</title><link>http://blogs.msdn.com/ace_team/default.aspx</link><description /><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Blog Series:  Get Familiar with the SDL-LOB Process, Introduction to Phase 2: Design for LOB</title><link>http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx</link><pubDate>Sat, 20 Jun 2009 01:29:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9792526</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9792526.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9792526</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold; mso-ansi-language: EN" lang=EN&gt;&lt;FONT face=verdana,geneva&gt;Hello, Anmol here.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is a continuation of my blog series on the &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;&lt;FONT face=verdana,geneva&gt;SDL-LOB process&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In my last blog entry I talked about &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;&lt;FONT face=verdana,geneva&gt;Phase 1: Requirements for LOB&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt;&lt;B&gt;.&amp;nbsp; &lt;/B&gt;Let’s discuss Phase 2:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Design for LOB.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As you read my blog series on the SDL-LOB process, I will try to share experiences and lessons learned from an &lt;/FONT&gt;&lt;A href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;&lt;FONT face=verdana,geneva&gt;Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt; group perspective.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=verdana,geneva&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;Phase 2 is all about ensuring that application follows “Secure by Default” principle. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=verdana,geneva&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;There are 2 key tasks to be executed in this phase:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;FONT face=verdana,geneva&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;FONT face=verdana,geneva&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&lt;FONT size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Threat Modeling&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;FONT face=verdana,geneva&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&lt;FONT size=2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Design Review&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=verdana,geneva&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;Both of these activities are aimed towards identifying security design flaws upfront in the lifecycle and helping in reducing the number of security bugs propagating on to the next stages. It is far more resource intensive and cumbersome to mitigate issues identified during verification phase and even costlier if identified in production time. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Let me illustrate this by an example shown below: &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;IMG style="WIDTH: 528px; HEIGHT: 369px" title="SDL-LOB: Phase 2: Design for LOB" alt="SDL-LOB: Phase 2: Design for LOB" src="http://blogs.msdn.com/photos/ace_team/images/9792522/original.aspx" width=1167 height=633 mce_src="http://blogs.msdn.com/photos/ace_team/images/9792522/original.aspx"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 8.5pt"&gt;&lt;o:p&gt;&lt;FONT size=2 face=verdana,geneva&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;Let’s assume that your design did not consider validating user controlled input and output encoding strategy. This would result in developers coding and developing the application without deviating from the final design which lacked specific security considerations in the first place. This would eventually result in 100s of “Cross Site Scripting” bugs turning up during verification stage. I am sure no application team would want that to happen. Wouldn’t it be nice if we followed few design time activities which would call out specific security considerations that need to be followed by the development team in the context of the application? &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=verdana,geneva&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;To learn more read the detailed Design phase tasks &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/dd831971.aspx" mce_href="http://msdn.microsoft.com/en-us/library/dd831971.aspx"&gt;&lt;FONT face=verdana,geneva&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;and&amp;nbsp;also watch my podcast "&lt;A title="Security Design Reviews" href="http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/" target=_blank mce_href="http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/"&gt;Security Design Reviews&lt;/A&gt;" where I&amp;nbsp;discuss&amp;nbsp;more why&amp;nbsp;security should be "baked" into the application starting with the Design phase.&amp;nbsp; &lt;/SPAN&gt;Next time, I’ll talk about Phase 3: Implementation for LOB.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=verdana,geneva&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;Here are some additional resources &lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT face=verdana,geneva&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&lt;FONT size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" mce_href="http://msdn.microsoft.com/en-us/security/aa570413.aspx"&gt;&lt;FONT color=#0000ff face=verdana,geneva&gt;Threat Analysis and Modeling&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt; &lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT face=verdana,geneva&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&lt;FONT size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/aa302421.aspx" mce_href="http://msdn.microsoft.com/en-us/library/aa302421.aspx"&gt;&lt;FONT color=#0000ff face=verdana,geneva&gt;Conducting Design Reviews&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt; &lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT face=verdana,geneva&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; mso-ansi-language: EN; mso-bidi-font-size: 10.0pt" lang=EN&gt;&lt;FONT face=verdana,geneva&gt;-Anmol Malhotra &lt;BR&gt;Senior Security Engineer &lt;BR&gt;ACE Team&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; mso-ansi-language: EN; mso-bidi-font-size: 10.0pt" lang=EN&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9792526" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/SDL-LOB/default.aspx">SDL-LOB</category></item><item><title>Blog Series:  Get Familiar with the SDL-LOB Process, Introduction to Phase 1: Requirements for LOB</title><link>http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx</link><pubDate>Tue, 16 Jun 2009 17:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9762696</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9762696.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9762696</wfw:commentRss><description>&lt;H1 style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Segoe UI','sans-serif'; FONT-SIZE: 14pt"&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/H1&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Hello, Anmol here.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For this blog series I’ll discuss the SDL-LOB process and cover all 5 phases as we go.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In my last blog entry I provided an overview of this process, &lt;A href="http://blogs.msdn.com/ace_team/archive/2009/06/02/blog-series-get-familiar-with-the-sdl-lob-security-development-lifecycle-for-line-of-business-applications-process.aspx" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/02/blog-series-get-familiar-with-the-sdl-lob-security-development-lifecycle-for-line-of-business-applications-process.aspx"&gt;Blog Series: Get Familiar with the SDL-LOB Process&lt;/A&gt;&lt;B&gt;.&amp;nbsp; &lt;/B&gt;Today I’ll discuss Phase 1: &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Requirements for LOB.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As you read my blog series on the SDL-LOB process, I will try to share experiences and lessons learned from an information security group perspective.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt; 
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt"&gt;Phase 1: It’s is all about “Risk Assessment”&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;What we learned from our experiences working for more than 6 years now in securing Microsoft’s line of business applications is that effectively assessing risk is one of the stepping stones for managing a big portfolio of applications in an enterprise.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We have an inventory of more than 3500 applications which have different security and privacy needs. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;As you can imagine, it would have been impossible to manage such a large number of applications without effective – &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold; mso-fareast-font-family: 'Segoe UI'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;a)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Application inventory &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold; mso-fareast-font-family: 'Segoe UI'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;b)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Risk Assessment&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold; mso-fareast-font-family: 'Segoe UI'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;c)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Service Levels &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt"&gt;The following diagram summarizes key tasks in this phase: &lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt"&gt;&lt;/SPAN&gt;&lt;/B&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt"&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;&lt;o:p&gt;&lt;IMG style="WIDTH: 577px; HEIGHT: 343px" title="Risk Assessment" alt="Risk Assessment" align=middle src="http://blogs.msdn.com/photos/ace_team/images/9762706/original.aspx" width=616 height=366 mce_src="http://blogs.msdn.com/photos/ace_team/images/9762706/original.aspx"&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraph&gt;&lt;B&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="PAGE-BREAK-AFTER: avoid; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; mso-no-proof: yes"&gt;&lt;?xml:namespace prefix = v ns = "urn:schemas-microsoft-com:vml" /&gt;&lt;v:shapetype id=_x0000_t75 coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt;&lt;v:formulas&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt;&lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt;&lt;/v:shapetype&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Every organization is unique in how it measures and reacts to risk. However under the hood the basic principle for assessing risk remains consistent.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;When looking at application we first try to gather the following information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold; mso-fareast-font-family: 'Segoe UI'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;a)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Data: Type of data being handled by the application (is it sensitive, non sensitive, public, etc.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold; mso-fareast-font-family: 'Segoe UI'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;b)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Business: Business Unit being catered by the application (such as finance, HR, payroll or cafeteria)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold; mso-fareast-font-family: 'Segoe UI'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;c)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Audience: Audience (users of the application) and hosting type&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;(internal/external) &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;From a broader level, we are also trying to get a mind map of what will be the impact on the organization if the application got compromised. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold; mso-fareast-font-family: 'Segoe UI'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;a)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Will this cause negative impact to the company’s reputation? (loss of customers, brand, etc.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo3" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold; mso-fareast-font-family: 'Segoe UI'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;b)&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; FONT-SIZE: 10pt; mso-bidi-font-weight: bold"&gt;Will this cause negative business impact? (loss of revenue, sensitive data stolen, etc.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; mso-bidi-font-weight: bold; mso-bidi-font-size: 10.0pt"&gt;As application data becomes more sensitive or the system becomes more critical to business, risk increases.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; mso-bidi-font-weight: bold; mso-bidi-font-size: 10.0pt"&gt;Whenever you’re working with risk, it’s most likely there will be a risk assessment in some form conducted.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For the SDL-LOB process&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;, a &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt;&lt;A title="Risk Assessment" href="http://msdn.microsoft.com/en-us/library/dd835478.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd835478.aspx"&gt;Risk Assessment questionnaire&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Segoe UI','sans-serif'"&gt; helps us capture general &lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Segoe UI','sans-serif'; FONT-SIZE: 11pt"&gt;security and privacy ‘‘&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Segoe UI','sans-serif'; COLOR: black; mso-bidi-font-weight: bold; mso-bidi-font-size: 10.0pt"&gt;qualities” for the application.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This allows us to determine the appropriate amount of “oversight” needed. Essentially we are trying to understand the potential risk the application poses for the enterprise. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;From a risk perspective, if an application is high risk, we’ll put forth more oversight and vice versa, if an application is low risk, it receives less oversight. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Note that definition of what is “High” is also organization specific. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;You can create your own risk categories such as “Red/Orange/Green,” “High/Medium/Low,“ “Most Risky/Risky/Minimum Risk” - it’s all up to you. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Identifying the most risky applications in an organization and spending the right resources, money and time to reduce the risk posed by them is the key here.&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-bidi-font-size: 10.0pt"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-bidi-font-size: 10.0pt"&gt;At Microsoft, risk assessment produces repeatable guidance on the type of oversight the application will receive in the SDL-LOB process. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;I encourage you to read the detailed requirements and recommendations for this Phase on Security Development Lifecycle 4.1 under &lt;A title="SDL-LOB Phase 1: Requirements for LOB" href="http://msdn.microsoft.com/en-us/library/dd861504.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd861504.aspx "&gt;SDL-LOB&lt;/A&gt; section. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-bidi-font-size: 10.0pt"&gt;Next time I'll&amp;nbsp;talk about Phase 2: Design for LOB.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-bidi-font-size: 10.0pt; mso-ansi-language: EN" lang=EN&gt;-Anmol Malhotra &lt;BR&gt;Senior Security Engineer &lt;BR&gt;ACE Team&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Segoe UI','sans-serif'; mso-bidi-font-size: 10.0pt; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9762696" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/SDL-LOB/default.aspx">SDL-LOB</category></item><item><title>Blog Series: Get Familiar with the SDL-LOB (Security Development Lifecycle for Line-Of-Business Applications) Process</title><link>http://blogs.msdn.com/ace_team/archive/2009/06/02/blog-series-get-familiar-with-the-sdl-lob-security-development-lifecycle-for-line-of-business-applications-process.aspx</link><pubDate>Tue, 02 Jun 2009 15:14:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9685661</guid><dc:creator>ACE Team</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9685661.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9685661</wfw:commentRss><description>&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Hello, Anmol Malhotra here. I’m a Senior Security Engineer with ACE Team, a part of Microsoft IT &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; group. I’d like to introduce you to the &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=2 face=verdana,geneva&gt;&lt;A title=SDL-LOB href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;Security Development Lifecycle for Line-of-Business Applications (SDL-LOB)&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; process.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;As part of our continued commitment towards sharing security processes and recommendations with our customers, we’re excited to announce the addition of detailed security requirements and recommendations for LOB (line-of-business) applications with the release of &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=2 face=verdana,geneva&gt;&lt;A title="Microsoft SDL 4.1" href="http://msdn.microsoft.com/en-us/library/84aed186-1d75-4366-8e61-8d258746bopq.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/84aed186-1d75-4366-8e61-8d258746bopq.aspx"&gt;Microsoft SDL version 4.1&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; on MSDN. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;SDL-LOB provides a mainstream approach to the SDL which focuses on development of applications that support the business such as accounting, human resources (HR), payroll, &lt;/FONT&gt;&lt;A href="http://searchcio.techtarget.com/sDefinition/0,,sid182_gci214546,00.html" mce_href="http://searchcio.techtarget.com/sDefinition/0,,sid182_gci214546,00.html"&gt;&lt;SPAN style="LINE-HEIGHT: 112%; COLOR: windowtext; TEXT-DECORATION: none; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-font-size: 11.0pt; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri; text-underline: none"&gt;&lt;FONT face=verdana,geneva&gt;supply chain management&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt; and resource planning applications, etc. The SDL-LOB guidance is positioned exclusively for LOB applications or web applications; and not for ISV/rich client and server application development. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Here’s an overview of SDL-LOB process.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;High level tasks performed in each stage are listed in the table below:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;IMG alt="Dd831970.SDL Lifecycle(en-us,MSDN.10).png" src="http://i.msdn.microsoft.com/Dd831970.SDL%20Lifecycle(en-us,MSDN.10).png" width=548 height=31&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;TABLE style="WIDTH: 544px; HEIGHT: 111px" class=class border=1 cellSpacing=0 cellPadding=2 width=544 class="class"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top width=77 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Training&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=94 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Requirements&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=129 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Design&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=104 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Implementation&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=108 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Verification&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=48 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Release&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top width=77 class="class"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold"&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;LOB-specific training &lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=94 class="class"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;Risk assessment &lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;-Application portfolio&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;-Application risk assessment&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;-Determine service level&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=129 class="class"&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;Asset-centric threat modeling &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;-Threat model&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=1 face=Verdana&gt;
&lt;P&gt;-Design review &lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;/P&gt;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=104 class="class"&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;Internal review &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;-Incorporate security checklists and standards&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=1 face=Verdana&gt;
&lt;P&gt;-Conduct “self” code review &lt;/P&gt;
&lt;P&gt;-Security code analysis &lt;/P&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=108 class="class"&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;Pre-production assessment &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;-Comprehensive security assessment &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;-Bug tracking &lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt; mso-list: l3 level1 lfo4; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=1 face=verdana,geneva&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT size=1 face=verdana,geneva&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=48 class="class"&gt;
&lt;P style="MARGIN: 2pt 0in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=1 face=verdana,geneva&gt;Post-production assessment &lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=1 face=verdana,geneva&gt;-Host level scan &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;It is important to note that organizations should adapt rather than adopt “Microsoft SDL-LOB” process.&lt;B style="mso-bidi-font-weight: normal"&gt; &lt;/B&gt;Organizations are unique – given that fact we should expect and plan for differences in resources, executive support and security expertise.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Some of the highlights of SDL-LOB are:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;To weave security in SDLC by embedding various milestones/checkpoints in each of the phases.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Identifying security vulnerabilities early in the development cycle and thereby improving the overall design.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;To enable effective application risk management from strategic, tactical, operational and legal perspective.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;At Microsoft, all line-of-business application development teams must go through the SDL-LOB process and if they fail to do so, the application cannot go live. Enforcement of the SDL-LOB process attributes to its success.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;In this blog series I’ll discuss the highlights of each of the phases in SDL-LOB.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Next time, I’ll go over &lt;B style="mso-bidi-font-weight: normal"&gt;Phase 1: Risk Assessment for LOB&lt;/B&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In the mean time get familiar with the SDL-LOB &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT size=2 face=verdana,geneva&gt;&lt;A title="Microsoft SDL-LOB" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;here&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verdana,geneva&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;-Anmol Malhotra &lt;BR&gt;Senior Security Engineer &lt;BR&gt;ACE Team&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9685661" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/SDL-LOB/default.aspx">SDL-LOB</category></item><item><title>How Do I: Set Up Fiddler’s Reverse Proxy to Create a VSTS 2008 Web Test</title><link>http://blogs.msdn.com/ace_team/archive/2009/05/29/how-do-i-set-up-fiddler-s-reverse-proxy-to-create-a-vsts-2008-web-test.aspx</link><pubDate>Fri, 29 May 2009 23:10:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9660625</guid><dc:creator>ACE Team</dc:creator><slash:comments>5</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9660625.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9660625</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;VSTS 2008 has a great recording tool that allows you to create web test simply by recording your web traffic in the browser. But what if your application doesn’t use web browser, but still communicates with servers using HTTP or HTTPS protocols (such as Smart Client application). Then, you can use Fiddler to capture web traffic on the client side and create a VSTS test from Fiddler’s capture. Unfortunately, there might be one more problem… Since Fiddler acts as a proxy, you web application’s traffic has to go through Fiddler. But it doesn’t work for some application, which might have web server name hardcoded into code or configuration file. When this happens, there is another way to record application’s web traffic and create a VSTS 2008 web test – by using Fiddler’s reverse proxy. By reverse proxy I mean capturing web traffic on the web server side, and not on the client side. Basically, your application will think that it’s hitting web server, while it will be directing its traffic to Fiddler installed on web server, and then Fiddler will forward that traffic to the actual application. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Here are the steps on how to set up and use reverse proxy:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Log in to your web server and install the latest versions of Fiddler (http://www.fiddler2.com/Fiddler2/) and neXpert (http://www.fiddler2.com/fiddler2/addons/nexpert.asp)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open IIS manager (Start&amp;gt;Administrative Tools&amp;gt;Internet Information Services (IIS) Manager)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;3.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Find your application under Web Sites, right click it and select Properties&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;4.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Change TCP port from 80 to 81, and click OK &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&lt;IMG style="WIDTH: 471px; HEIGHT: 454px" title="IIS Manager Port Edit" alt="IIS Manager Port Edit" src="http://blogs.msdn.com/photos/ace_team/images/9651364/original.aspx" width=471 height=454 mce_src="http://blogs.msdn.com/photos/ace_team/images/9651364/original.aspx"&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;5.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open Fiddler on Web server&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;6.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Select Tools &amp;gt; Fiddler Options&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;7.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Make sure “Allow remote computers to connect” check box is checked on General tab&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;8.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Click on Connections tab, and Change “Fiddler listens on port:” from 8888 to 80, and click OK&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;IMG style="WIDTH: 550px; HEIGHT: 391px" title="Fiddler Port Edit" alt="Fiddler Port Edit" src="http://blogs.msdn.com/photos/ace_team/images/9651366/original.aspx" width=550 height=391 mce_src="http://blogs.msdn.com/photos/ace_team/images/9651366/original.aspx"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;9.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Select Rules &amp;gt; Customize Rules…&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;10.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Find “static function OnBeforeRequest(oSession: Session)”&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;11.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Add the following code inside of curly brackets: if (oSession.host.toLowerCase() == "webserver") oSession.host = "webserver:81"; &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;//(where webserver is the name of your web server, make sure you spell it in lower case)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&lt;FONT size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;So, it should look like this:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static function OnBeforeRequest(oSession: Session)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;&lt;SPAN style="mso-tab-count: 2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;if (oSession.host.toLowerCase() == "WebServer") oSession.host = "WebServer:81";&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&lt;FONT size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;12.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Save it and close text editor.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;13.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Close Fiddler and open it again.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;14.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Make sure that Fiddler is capturing the traffic (Left bottom corner should say “Capturing” or if you click on File menu, “Capture traffic” will have a check mark next to it)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;15.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open the application you want to record on the client (not on web server) and perform activities you want to be recorded. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;16.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Make sure to add a step description after each step you perform by going back to Fiddler on Web server, selecting neXpert tab and clicking Add for Step Description.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;IMG style="WIDTH: 587px; HEIGHT: 361px" title=neXpert alt=neXpert src="http://blogs.msdn.com/photos/ace_team/images/9651365/original.aspx" width=587 height=361 mce_src="http://blogs.msdn.com/photos/ace_team/images/9651365/original.aspx"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;17.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;After you recorded all steps, go back to Fiddler on Web server and stop capturing.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;18.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Select all recorded sessions (Ctrl + A), right click them and select Save&amp;gt;Selected Sessions&amp;gt;as Visual Studio Web Test…&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;19.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Also, make sure to check out neXpert report, by clicking Create Report button on neXpert tab.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;20.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Change Fiddler listen port back to 8888 (Tools &amp;gt; Fiddler Options &amp;gt; Connections tab). And close fiddler&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;21.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Change application’s TCP port back to 80 in IIS manager (See step 4)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;22.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Then, copy the Web test you created with Fiddler in step 18 to your machine (Where you have VSTS 2008 installed).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;23.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open or Create a VSTS 2008 test project. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;24.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Right click Project name in Solution Explorer and select Add &amp;gt; Existing Item. Browse to your recorded web test and click OK.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;25.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open web test from Solution Explorer and remove “:81” from all requests (by pressing CTRL + H, and replacing all “webserver:81” with “webserver”, where webserver is the name of your Web server)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;26.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Then, save the Web test and run it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Notice that web test has transactions already for each step that you recorded, if you added step description using neXpert tab.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Also, this method works the best for http traffic. If your application uses https, you can disable it while recording the test, by:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpFirst&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;opening IIS manager on the web server&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;right clicking your web site and selecting Properties&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;selecting Directory Security tab&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;clicking Edit on Secure Communications session&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpLast&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;and unchecking “Require secure channel (SSL)”&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Make sure to switch it back on when you done recording the test and replacing all HTTP requests in your Web test with HTTPS (the same method we used in step 25).&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;I also created a video on how to set up a Reverse proxy. You can view it here: &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://msdn.microsoft.com/en-us/teamsystem/dd876614.aspx"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;http://msdn.microsoft.com/en-us/teamsystem/dd876614.aspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;---------------------------------------- &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Vitaliy Konev&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Performance Engineer&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Microsoft – ACE Team&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9660625" width="1" height="1"&gt;</description></item><item><title>TechNet Webcast: Configuring with Least Privilege in SQL Server 2008 (Level 300)</title><link>http://blogs.msdn.com/ace_team/archive/2009/05/29/technet-webcast-configuring-with-least-privilege-in-sql-server-2008-level-300.aspx</link><pubDate>Fri, 29 May 2009 21:46:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9658944</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9658944.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9658944</wfw:commentRss><description>&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3 face=Calibri&gt;TechNet Webcast&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Configuring with Least Privilege in SQL Server 2008 (Level 300)&lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Tuesday, June 02, 2009 8:00 AM Pacific Time (US &amp;amp; Canada)&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Presenter:&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt; &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Varun Sharma, Security Engineer, Microsoft Corporation&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Overview&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;With SQL injection attacks on the rise, it is imperative to configure Microsoft SQL Server with least privilege. In this webcast, we provide an overview on how to configure a SQL Server installation with least privilege for a typical line-of-business application. We cover configuring least-privileged service accounts for SQL Server services, best practices for configuring least-privileged principals used by the front-end or middle tiers to connect to the SQL Server back end, and the details of configuring SQL Server job steps with least privilege.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A title="Configuring with Least Privilege in SQL Server 2008 (Level 300)" href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032415806&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US" target=_blank mce_href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032415806&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;Register Here&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9658944" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category></item><item><title>TechNet Webcast:  Fundamentals of Third-Party Security Management (Level 300)</title><link>http://blogs.msdn.com/ace_team/archive/2009/05/29/technet-webcast-fundamentals-of-third-party-security-management-level-300.aspx</link><pubDate>Fri, 29 May 2009 21:32:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9658653</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9658653.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9658653</wfw:commentRss><description>&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt; mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;TechNet Webcast&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;: &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Fundamentals of Third-Party Security Management (Level 300)&lt;/SPAN&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=Calibri&gt;Monday, June 01, 2009 10:00 AM Pacific Time (US &amp;amp; Canada)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 6pt 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Presenter&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;:&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt; &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Gerard Morisseau, Senior Program Manager, Microsoft Corporation&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;B&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;BR&gt;&lt;FONT size=3 face=Calibri&gt;Overview: &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In this webcast, learn the fundamentals for building a vendor security management program that provides reasonable assurance that third parties who are hosting and managing your data, applications, or business processes have appropriate levels of security controls in place to protect your information assets.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;&lt;A title="TechNet Webcast:   Fundamentals of Third-Party Security Management (Level 300)" href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032416151&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US" target=_blank mce_href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032416151&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;&lt;STRONG&gt;Register Here&lt;/STRONG&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9658653" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category></item><item><title>Infrastructure Security Design Review</title><link>http://blogs.msdn.com/ace_team/archive/2009/05/19/infrastructure-security-design-review.aspx</link><pubDate>Tue, 19 May 2009 18:19:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9628985</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9628985.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9628985</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Hello Everyone!&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;My name is Shawn Rabourn and I am a Senior Security Consultant with ACE (Assessment, Consulting and Engineering) Services, a part Microsoft IT's &lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; (InfoSec) group.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Sounds like a mouthful, I know.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Really, that is just my title.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I have a unique position within Microsoft where I can offer Security Guidance to internal Microsoft employees who are planning to make infrastructure changes.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I also have two customers external to Microsoft that I offer consulting services to.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A title="ACE Services" href="http://msdn.microsoft.com/en-us/security/aa570410.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/security/aa570410.aspx"&gt;ACE Services&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;’ offers consulting services,&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;leveraging Microsoft IT (MSIT) internal processes and best practices to deliver a specialized product to our customers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;My responsibility to InfoSec is to perform Security Design Reviews (SDR) and Security Design Consulting (SDC).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If there is a change to the core infrastructure of Microsoft, in most cases it is subject to the SDR process.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We receive the details of the change and we assess the change against our published security policies, Microsoft internal policies and the industry best practices.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Once we diagnose the proposed change in the SDR, the person submitting the proposed change is strictly held to the recommendations set forth in the SDR.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The SDC process differs from the SDR process in that the submitting employee is unsure of what kind of infrastructure change they may need to accomplish their end goal.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We can give them the baseline security guidelines to comply with policy or we can even go deeper to recommend specific configuration of servers, applications and/or hardware.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If the person submitting an SDC decides to follow through to achieve their end goal, they are still subject to an SDR.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Through SDRs and SDCs I’ve been able to work with a wide range of internal customers in many different organizations and business groups.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In every SDR or SDC, I have a responsibility to protect Microsoft assets, intellectual property, employees and customers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Each request, however different, lends itself to similar lines of questioning.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Are we moving or storing Personally Identifiable Information (PII)?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Are we moving or storing customer data?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Are we making something externally accessible?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What are the perceived risks?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What is being done beforehand to mitigate these risks?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In some cases, the design submitted is mostly compliant with policy and poses little risk to our infrastructure.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In others, our guidelines may be nearly impossible to follow and the design need be reconsidered.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;As SDRs typically do not discriminate between technologies, in the field my work is highly specialized and product-centric.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;I’ve spent nearly 8 years at Microsoft working with customers in different capacities from Product Support Services to Premier Field Engineering and now ACE Services Consulting and what I have found is that the higher up the technology stack you go, the attention to other details has a tendency to go down.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I have been guilty of this as well.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The simple fact that you can’t write a line of code, schedule a task, set a registry value or check a checkbox to address all problems is a hard barrier to climb over.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What becomes lost in technical detail usually becomes the infamous “gotcha” that delays a project schedule.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;A company’s IT security policies may not be taken into consideration in an engineering design and often it is too late in the project before the important questions are asked.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;One of my specialties is Forefront Identity Manager (FIM) and its predecessors Identity Lifecycle Manager (ILM), Identity Integration Server (MIIS).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;One of the functions of FIM is to take unique, unrelated data sources with identity data, often authenticating data and initiate and maintain synchronization between these sources.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This ensures identity data consistency.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The engineering logistics behind connecting unique sources of data typically involve network connectivity and attribute formatting.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Beyond that, we may also incorporate timing to ensure we access and change data at appropriate intervals.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;My experience in the SDR process leads me to think about some of the other logistics as well.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;How sensitive is the PII we are synchronizing?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;What is the company policy regarding storage or encryption of PII?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Is there anything defined in policy with regard to encryption strength or algorithms used?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What logic do we need to incorporate to ensure that employee data is handled appropriately per policy in the case of a termination?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Is the data source externally accessible and if so, what are the policies around data that can be viewed externally?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Is there a firewall between the datacenter housing the FIM server and the connected sources?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What are the guidelines for creating and maintaining an account that has permission to read and write identity data?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These questions, left unanswered can (and have been known to) cause delay in an overall project.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;As you can see, the SDR process is a very important step in protecting Microsoft’s overall infrastructure and as you can imagine, those who incorporate the SDR process in their project planning find more success in meeting their milestones.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I encourage any consultant or project manager to investigate their company’s equivalent to our SDR process early in a project and if there is not a process in place, take steps to review your project against your company’s IT security policies and industry security best practices.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Allocate a small amount of time early in the project or risk spending a large amount of time late in the project.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; Feel free to &lt;A title="Contact ACE Team" href="http://blogs.msdn.com/ace_team/contact.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/contact.aspx"&gt;contact us&lt;/A&gt; and provide comments, feedback.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Good Luck!&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;-Shawn W. Rabourn&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Senior Security Consultant&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A title="ACE Services" href="http://msdn.microsoft.com/en-us/security/aa570410.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/security/aa570410.aspx"&gt;ACE Services&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9628985" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/Infrastructure/default.aspx">Infrastructure</category></item><item><title>ACE Infrastructure Security Services: An Overview</title><link>http://blogs.msdn.com/ace_team/archive/2009/05/11/ace-infrastructure-security-services-an-overview.aspx</link><pubDate>Mon, 11 May 2009 20:20:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9604428</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9604428.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9604428</wfw:commentRss><description>&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;This is Rob Cooper, Senior Engineer for ACE Infrastructure (also known internally as ICE for you William Gibson fans). Thanks to &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'"&gt;Irfan Chaudhry, Director of the ACE Team, &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;for giving us a good &lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;A href="http://blogs.msdn.com/ace_team/archive/2008/12/15/new-versions-of-anti-xss-cat-net-available-today-and-some-background-and-history-about-the-ace-team.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/archive/2008/12/15/new-versions-of-anti-xss-cat-net-available-today-and-some-background-and-history-about-the-ace-team.aspx"&gt;overview and history of ACE&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt; and how ACE’s role has expanded over the years. I’m with ACE Infrastructure (also known as ICE). Our role is to focus on the &lt;I style="mso-bidi-font-style: normal"&gt;implementation&lt;/I&gt; of technology. It may be an internal LOB (line of business) application, a third-party product or new hardware or network appliances. Mergers and Acquisitions are one of our responsibilities. Although our role is diverse, most functions can be described by a small number of services. On our team, reviews are divided into Security Consultation Reviews, Security Design Reviews and Security Compliance Reviews. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Security Consultation Reviews are when a project team asks us for advice on how to proceed, while they’re still in the design and development stages. Consultation Reviews are optional, but extremely helpful. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Security Design Reviews are for a project that has a complete (or nearly complete) design and is ready to release. Obviously, Security Design Reviews are simplified if a project has completed a Security Consultation Review. Mitigation steps and design changes are likewise much easier while the project is still in the design phase. Can a design change between the Consultation Review and a Design Review? Certainly, but the Consultation Review helps guide the project, and helps the infrastructure team get early visibility into the project and creates an early relationship with the project team, both of which help considerably. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Security Compliance Reviews are scheduled for a reasonable timeframe after project implementation. This varies, but most projects can be reviewed within 60 days of deployment. Larger projects may require more time, or have multiple reviews for individual subcomponents. Security Compliance Reviews verify that identified risks and proposed mitigation steps from the Design Review have been implemented. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;ACE Infrastructure then has a very practical role tied to &lt;I style="mso-bidi-font-style: normal"&gt;which &lt;/I&gt;decisions are made about how a deployment is configured and &lt;I style="mso-bidi-font-style: normal"&gt;when &lt;/I&gt;a deployment occurs. This is different than an application review, which analyzes all possible configurations. Let’s take IIS as an example. An application review focused on authentication may look at all authentication methods, from certificate authentication all the way down to clear-text credentials. The application review is to ensure the highest level of encryption is &lt;I style="mso-bidi-font-style: normal"&gt;available&lt;/I&gt; to IT professionals and other IIS customers. An infrastructure review is focused on a particular deployment, so reviewing authentication might determine which methods of authentication may be used and which must not be used. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Over the next several months (and hopefully beyond), I will be providing a particular view into some of the tools we use, many of which are developer-focused tools (including the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;A title="Microsoft Threat Analysis &amp;amp; Modeling " href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=59888078-9daf-4e96-b7d1-944703479451" target=_blank mce_href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=59888078-9daf-4e96-b7d1-944703479451"&gt;Microsoft Threat Analysis &amp;amp; Modeling Tool&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;). Other approaches come from years of experience of infrastructure deployments. It is our intention to share how we use existing tools, how we leverage previous work and experience and the most effective way to increase security during implementation. Please look for the following: &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; TEXT-INDENT: -0.25in; MARGIN: 12pt 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Examples of known change types, including how to leverage these for an expedited workflow. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; TEXT-INDENT: -0.25in; MARGIN: 12pt 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Explanations and descriptions of well-settled policies that can help you understand why these policies are in place, and well-known alternatives that can be both effective and secure.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; TEXT-INDENT: -0.25in; MARGIN: 12pt 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;How to leverage development tools (primarily the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;A title="Microsoft Threat Analysis &amp;amp; Modeling " href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=59888078-9daf-4e96-b7d1-944703479451" target=_blank mce_href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=59888078-9daf-4e96-b7d1-944703479451"&gt;Microsoft Threat Analysis &amp;amp; Modeling Tool&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;), including templates, examples and flowcharts that help us to help you. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt; tab-stops: 53.2pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Security infrastructure services at Microsoft are both exciting and challenging. We typically work with pre-released products and we can assist in making these products more secure. In future posts I hope to share how early engagement of our services can help your product in the long run. As a paranoid security engineer I might not provide specific implementation details, but I do hope to tell you some stories from the trenches that show how we can help. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt; tab-stops: 53.2pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Watch my podcast “&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;A title="Infrastructure Security Engineering" href="http://edge.technet.com/Media/Infrastructure-Security-Engineering/" target=_blank mce_href="http://edge.technet.com/Media/Infrastructure-Security-Engineering/"&gt;Infrastructure Security Engineering&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;” as I discuss how we try to balance security between the application and infrastructure side.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt; tab-stops: 53.2pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Thank you and I look forward to sharing these with you in the future and in hearing your &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://blogs.msdn.com/ace_team/contact.aspx" mce_href="http://blogs.msdn.com/ace_team/contact.aspx"&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;feedback&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 12pt; MARGIN: 12pt 0in 0pt; tab-stops: 53.2pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt; tab-stops: 53.2pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;-Rob Cooper&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt; tab-stops: 53.2pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;Senior Engineer&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt; tab-stops: 53.2pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;ACE Team – Infrastructure Security&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9604428" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/Infrastructure/default.aspx">Infrastructure</category></item><item><title>Security as a Service:  A Balancing Act</title><link>http://blogs.msdn.com/ace_team/archive/2009/05/04/security-as-a-service-a-balancing-act.aspx</link><pubDate>Mon, 04 May 2009 19:28:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9586317</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9586317.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9586317</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;When I first joined Microsoft IT, I was intrigued by the concept of offering security assessment as an optional service to the business.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I was even more surprised to see how enthusiastically the business had embraced the concept. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;You see, like many security professionals, I came from an organization where information security was widely perceived as obstructionists and a tax to the business.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;I would later discover that offering IT security assessment services to internal business is a constant balancing act, whose success hinges on the ability of IT to demonstrate and deliver real value to the business, while helping the enterprise reduce risks and improve its overall posture. Today, I will explore some of the issues you can expect to face when offering security assessment services to internal customers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Striking the right balance between securing information assets and business objectives should be at the core of the service and drive the engagement and delivery model.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;This balance is all the more important here at Microsoft, where a culture of innovation and entrepreneurship often creates healthy frictions between the development community and information security.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The former driven by customer demands for more features and deployment flexibility, the latter bent on enforcing security policies and closing holes.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These frictions often lead to creative solutions and expose new case scenarios.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;A clear benefit, only if the interaction between the business and IT is orchestrated properly through a set of services that recognize the needs of both parties and can provide meaningful feedback.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;The key in addressing this problem is to provide services that capture, address and drive the focus on security throughout the System Development Life Cycle. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;These services should include design consultation, pre and post deployment reviews, and operational assessment and compliance.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Other offerings should be aligned with key business processes such as procurement, fulfillment, supply chain management, etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Security service should also be able to strike a balance between servicing the specific security needs of individual business unit versus those of the larger&lt;B style="mso-bidi-font-weight: normal"&gt; &lt;/B&gt;enterprise.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For example, a client might want to remove antivirus software from its servers to improve application performance or refuse to migrate from a legacy and unsupported application. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;While these requests might have legitimate business justifications, they run counter to what it takes to secure the enterprise. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Another manifestation of this problem can be during the process of prioritizing risks and allocating remediation resources.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Essential to the ability to deliver security as a service is to ensure that the organization has established security policies and a risk framework that provides a&amp;nbsp;consistent way to manage risks (i.e. identify, assess, measure, prioritize) across the enterprise.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;-Gerard Morisseau&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;ACE Team – Infrastructure Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-bidi-font-family: Tahoma; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9586317" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/Infrastructure/default.aspx">Infrastructure</category></item><item><title>About ACE’s Information Security Assessment Service - Your Friendly Neighborhood Security Auditor</title><link>http://blogs.msdn.com/ace_team/archive/2009/04/28/about-ace-s-information-security-assessment-service-your-friendly-neighborhood-security-auditor.aspx</link><pubDate>Tue, 28 Apr 2009 17:53:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9573924</guid><dc:creator>ACE Team</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9573924.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9573924</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;This is Gerard Morisseau, Senior Program Manager for ACE’s Information Security Assessment Services (ISAS).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;ISAS offers several security assessment services aimed at helping Microsoft IT and the business assess their information security risks, improve controls environment, and strengthen their information security management systems. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Our most popular services include &lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;&lt;FONT color=#0000ff&gt;&lt;A title="Information Security Risk Assessment" href="http://download.microsoft.com/download/5/3/D/53D7863C-0709-4606-A4A4-E0023C3B1F1D/ACE_Services_Information_Security_Risk_Assessment.pdf" target=_blank mce_href="http://download.microsoft.com/download/5/3/D/53D7863C-0709-4606-A4A4-E0023C3B1F1D/ACE_Services_Information_Security_Risk_Assessment.pdf"&gt;Information Security Risk Assessment&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;, Controls Assessment Training and &lt;A title="Vendor Security Maturity Assessment" href="http://download.microsoft.com/download/9/D/7/9D7E894D-AA6C-4567-9009-2C3CB1A99622/ACE_Services_Vendor_Security_Maturity_Assessment.pdf" target=_blank mce_href="http://download.microsoft.com/download/9/D/7/9D7E894D-AA6C-4567-9009-2C3CB1A99622/ACE_Services_Vendor_Security_Maturity_Assessment.pdf"&gt;Vendor Security Maturity Assessment&lt;/A&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These services are based on the ISO/IEC 27002:2005&lt;I&gt; &lt;/I&gt;standard, an internationally recognized framework for managing information security management programs.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 1.45pt 6pt 0in" class=BodyCopyMain&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;The&lt;A title="Information Security Risk Assessment" href="http://download.microsoft.com/download/5/3/D/53D7863C-0709-4606-A4A4-E0023C3B1F1D/ACE_Services_Information_Security_Risk_Assessment.pdf" target=_blank mce_href="http://download.microsoft.com/download/5/3/D/53D7863C-0709-4606-A4A4-E0023C3B1F1D/ACE_Services_Information_Security_Risk_Assessment.pdf"&gt; &lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;&lt;FONT color=#0000ff&gt;&lt;A title="Information Security Risk Assessment" href="http://download.microsoft.com/download/5/3/D/53D7863C-0709-4606-A4A4-E0023C3B1F1D/ACE_Services_Information_Security_Risk_Assessment.pdf" target=_blank mce_href="http://download.microsoft.com/download/5/3/D/53D7863C-0709-4606-A4A4-E0023C3B1F1D/ACE_Services_Information_Security_Risk_Assessment.pdf"&gt;Information Security Risk Assessment&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt; service is designed to help organizations identify, evaluate and prioritize risks to their critical information assets.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;The service also helps organizations develop remediation plan based on risk prioritization model.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;The goal of this service is to ensure that clients are managing their information assets in a manner not only consistent with Microsoft security policies and standards, but also with industry best practices. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 1.45pt 12pt 0in" class=BodyCopyMain&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;The &lt;A title="Vendor Security Maturity Assessment" href="http://download.microsoft.com/download/9/D/7/9D7E894D-AA6C-4567-9009-2C3CB1A99622/ACE_Services_Vendor_Security_Maturity_Assessment.pdf" target=_blank mce_href="http://download.microsoft.com/download/9/D/7/9D7E894D-AA6C-4567-9009-2C3CB1A99622/ACE_Services_Vendor_Security_Maturity_Assessment.pdf"&gt;Vendor Security Maturity Assessment&lt;/A&gt; provides managers with great insights into third parties’ ability to secure and maintain the confidentiality, integrity and availability of hosted information assets.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;This service also helps ensure that third parties are managing information assets in a manner not only consistent with established security policies and standards, but also with industry best practices. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;These services are now available to Microsoft customers and partners interested in assessing information security risks in their environment or at third parties hosting their information assets.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;ISAS also include services to help prepare organizations interesting in obtaining their ISO 27001 Certification.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;Watch my podcast “&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;&lt;A title="Infrastructure Security Assessments" href="http://edge.technet.com/Media/Infrastructure-Security-Assessments/" target=_blank mce_href="http://edge.technet.com/Media/Infrastructure-Security-Assessments/"&gt;Infrastructure Security Assessments&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;” where I describe our risk models and I also talk about how we how identify security maturity levels in different environments inside and outside of Microsoft.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Feel free to &lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;&lt;A title="Contact ACE Team" href="http://blogs.msdn.com/ace_team/contact.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/contact.aspx"&gt;contact us&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt; if you have any questions or comments.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;-Gerard Morisseau&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;Senior Program Manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt"&gt;ACE&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Team - Infrastructure Security&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: Tahoma"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9573924" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/Infrastructure/default.aspx">Infrastructure</category></item><item><title>VSTS Web Test Step-by-Step Primer: 7-Minute Video by Microsoft A.C.E. Performance Engineer Chris Lundquist (with Copious Notes and Screen Shots from Your Humble Correspondent)</title><link>http://blogs.msdn.com/ace_team/archive/2009/04/27/vsts-web-test-step-by-step-primer-7-minute-video-by-microsoft-a-c-e-performance-engineer-chris-lundquist-with-copious-notes-and-screen-shots-from-your-humble-correspondent.aspx</link><pubDate>Mon, 27 Apr 2009 19:04:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9571725</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9571725.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9571725</wfw:commentRss><description>&lt;P&gt;My colleague &amp;amp; &lt;A href="http://blogs.msdn.com/ace_team/" target=_blank mce_href="http://blogs.msdn.com/ace_team/"&gt;&lt;FONT color=#176db5&gt;A.C.E.&lt;/FONT&gt;&lt;/A&gt; performance engineer Chris Lundquist has compiled a 6:58 wmv featuring his unscripted yet eloquent dialog walking us step-by-step through a VSTS web test:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;OL&gt;
&lt;LI&gt;Starting VSTS 
&lt;LI&gt;Adding a new C#/Web Test project 
&lt;LI&gt;Adding comments 
&lt;LI&gt;Running the test, exploring the Web Browser, Request, Response, Context, &amp;amp; Details tabs 
&lt;LI&gt;Modifying test parameters &amp;amp; re-running&lt;/LI&gt;&lt;/OL&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This is the best introduction to this technology you may ever see.&amp;nbsp; It's certainly the best I've seen.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/jimmymay/archive/2009/02/23/vsts-web-test-step-by-step-primer-7-minute-video-by-microsoft-a-c-e-performance-engineer-chris-lundquist-with-copious-notes-screen-shots-from-your-humble-correspondent.aspx" target=_blank mce_href="http://blogs.msdn.com/jimmymay/archive/2009/02/23/vsts-web-test-step-by-step-primer-7-minute-video-by-microsoft-a-c-e-performance-engineer-chris-lundquist-with-copious-notes-screen-shots-from-your-humble-correspondent.aspx"&gt;Read more...&lt;/A&gt;&lt;EM&gt;&lt;FONT size=1&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/user/Profile.aspx?UserID=28693" target=_blank mce_href="http://blogs.msdn.com/user/Profile.aspx?UserID=28693"&gt;&lt;FONT color=#176db5 size=1&gt;Jimmy May&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=1&gt;&lt;B&gt;, &lt;/B&gt;MCDBA, MCSE, MCITP: DBA + DB Dev&lt;BR&gt;Senior Performance Consultant: SQL Server&lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/ace_team" target=_blank mce_href="http://blogs.msdn.com/ace_team"&gt;&lt;FONT color=#555555 size=1&gt;A.C.E.&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=1&gt;: Assessment, Consulting, &amp;amp; Engineering Services&lt;BR&gt;&lt;U&gt;&lt;A href="http://blogs.msdn.com/jimmymay" mce_href="http://blogs.msdn.com/jimmymay"&gt;&lt;FONT color=#555555&gt;http://blogs.msdn.com/jimmymay&lt;/FONT&gt;&lt;/A&gt;&lt;/U&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1&gt;&lt;FONT size=1&gt;"If it is fast and ugly, they will use it and curse you; if it is slow, they will not use it." &lt;BR&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; —Computer science professor, billionaire, &amp;amp; entrepreneur David Cheriton&lt;/FONT&gt; &lt;/P&gt;&lt;/FONT&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9571725" width="1" height="1"&gt;</description></item><item><title>Shrinking Budgets: Application Security Tools vs Process Tradeoff</title><link>http://blogs.msdn.com/ace_team/archive/2009/04/21/shrinking-budgets-application-security-tools-vs-process-tradeoff.aspx</link><pubDate>Tue, 21 Apr 2009 17:47:34 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9559861</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9559861.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9559861</wfw:commentRss><description>&lt;p&gt;An all too familiar scene repeated itself two weeks ago. My good friend &amp;amp; CISO of a mid-sized technology company, lets call him Alok, went into a budget planning meeting and came out as a shadow of his former self. To be more precise a 85% version of the Alok that I know. He had just been handed a 15% reduction in budget.&lt;/p&gt;  &lt;p&gt;Like most managers, Alok, started taking stock of his mini-empire and prioritizing things that he could do without. Luckily he had already expected a cut and so had planned ahead. Unluckily, he had planned for a 6% reduction not a 15% reduction. After some brainstorming and taking some tough decisions he had cut costs by 10%. Now began his quest for the elusive final 5%. His organization had started the transition from being a network security centric organization to a more application security centric organization around 15 months ago. So, a solution posed by one of his managers was to drop the security engineering process integration program and replace it with a set of static analysis tools they had just evaluated. This strategy had paid of handsomely for them in the network security field. Ron, one of the leading application architects in the organization was opposed to the idea. Thus started a turf war, which left some angry, most frustrated and everyone confused.&lt;/p&gt;  &lt;p&gt;Unlike most managers, Alok reached out for advice. &lt;a href="http://nofud.org/2009/04/10/shrinking-budgets-application-security-tools-vs-process-tradeoff/"&gt;Read more…&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Akshay Aggarwal &lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9559861" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/Consulting/default.aspx">Consulting</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/Information+Technology/default.aspx">Information Technology</category></item><item><title>About ACE’s Infrastructure Security Team</title><link>http://blogs.msdn.com/ace_team/archive/2009/04/17/about-ace-s-infrastructure-security-team.aspx</link><pubDate>Fri, 17 Apr 2009 23:47:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9554744</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9554744.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9554744</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;Hi, my name is Brad Gobble and I manage &lt;/FONT&gt;&lt;FONT face=Calibri&gt;ACE&lt;/FONT&gt;&lt;FONT face=Calibri&gt;’s Infrastructure Security Team, a part Microsoft IT’s &lt;/FONT&gt;&lt;FONT face=Calibri&gt;&lt;A title="Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security&lt;/A&gt;&lt;/FONT&gt;&lt;FONT face=Calibri&gt; group. Over the next few weeks you’ll hear a lot about our services: what we do, how we do it, how we prepare our team to execute and where we’re going in the future. But before we dive too deeply in to the details I’d like to share what we mean by “Infrastructure Security” and&amp;nbsp;what our guiding principles are.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;Infrastructure security can be described as "the discipline dedicated to securing the platform on which applications reside." &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;While there may be a gray line,&amp;nbsp;we try to differentiate by team capability rather than by explicit technical demarcations. Yes, there is some overlap between application and infrastructure security (most notably in host configuration and hardening). However we believe that by encouraging our engineers to look beyond baseline requirements almost always yields better results and as a manager I am willing to invest in the extra cycles of my team.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;&lt;A title="ACE Services" href="http://msdn.microsoft.com/en-us/security/aa570410.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/security/aa570410.aspx"&gt;ACE Services&lt;/A&gt;&lt;/FONT&gt;&lt;FONT face=Calibri&gt; is a consulting team created to help clients ensure that they're doing what they should to keep&amp;nbsp;Microsoft as reasonably secure as possible while still doing business&amp;nbsp;successfully (think technical lawyers). However, it is important to point out that we do not operate as a system of jurisprudence (read: we're not traffic cops). We have embraced the fundamental notion that, as a service organization, we are here to facilitate and advise in the most efficient mode possible while enabling the business to keep moving forward.&amp;nbsp; I am often confronted with the question: "If you are a Service, then aren't you optional?" Where the pairing of "Service=Optional" came from is a mystery to me, as we are all reminded of this on April 15. Security is not an option, but the ultimate responsibility lies on the asset owner to behave in a secure manner and on asset custodians to maintain a secure environment. &amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;Ultimately, the security of information assets is a shared responsibility.&amp;nbsp; While the breadth and impact of the Infrastructure security team is wide we can't be everywhere, all of the time. We rely on the individual business owners, engineers, and administrators to do the right thing. We provide guidance when they need help. This respectful collaboration works well, so much so that we have been taking our work outside the walls of Microsoft and have been delivering them to Microsoft Consulting Services' customers as well. &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;In the weeks and blogs to follow you will hear about the tactical reviews, strategic assessments and holistic programs the ACE Infrastructure team delivers. We invite you to watch our new podcast -&amp;nbsp;"&lt;A title="About Infrastructure Security" href="http://edge.technet.com/Media/About-Infrastructure-Security/" target=_blank mce_href="http://edge.technet.com/Media/About-Infrastructure-Security/ "&gt;About Infrastructure Security&lt;/A&gt;"&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;where I talk about our role and how our team works inside and outside of Microsoft.&amp;nbsp;&lt;/SPAN&gt;There will be more upcoming podcasts as well as promotional literature posted soon.&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi"&gt;For over a decade Microsoft has b&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 12pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;een focusing on securing Microsoft’s internal infrastructure;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; FONT-SIZE: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi"&gt; however this is the first year we've taken our proven process, knowledge and insight to our customers. The success has been exhilarating and we look eagerly to the years to come with anticipation. This is what we love to do—and we're good at it.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;After experiencing what we've put together don't hesitate to &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;&lt;A title="Contact ACE Team" href="http://blogs.msdn.com/ace_team/contact.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/contact.aspx"&gt;contact us&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt; with questions, comments, rants or raves. We look forward to hearing from you.&amp;nbsp;&lt;/SPAN&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;-Brad Gobble&lt;BR&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;ACE &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Team - Infrastructure Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9554744" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/Infrastructure/default.aspx">Infrastructure</category></item><item><title>ACE Team's Performance Development Lifecycle (PDL-IT )</title><link>http://blogs.msdn.com/ace_team/archive/2009/04/03/ace-team-s-performance-development-lifecycle-pdl-it.aspx</link><pubDate>Fri, 03 Apr 2009 16:52:44 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9530784</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9530784.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9530784</wfw:commentRss><description>&lt;p align="justify"&gt;Hi &amp;#8211; This is Irfan, Director of the ACE Team. Some of you may have come across &lt;a href="http://blogs.msdn.com/ace_team/archive/2009/03/04/performance-development-life-cycle-for-it-part-1.aspx"&gt;Abu&amp;#8217;s recent blogs&lt;/a&gt; on Performance Development Lifecycle for IT (PDL-IT), I thought it would be useful to shed some light on the history of the performance side of the ACE Team as well as discuss what led to the creation of PDL-IT. As mentioned in &lt;a href="http://blogs.msdn.com/ace_team/archive/2008/12/15/new-versions-of-anti-xss-cat-net-available-today-and-some-background-and-history-about-the-ace-team.aspx"&gt;my earlier blog&lt;/a&gt;, the ACE Team was originally formed as a dedicated performance team back in 1999 and we&amp;#8217;ve been going strong in the area of performance for 10 years. Prior to ACE&amp;#8217;s existence, centralized performance testing in Microsoft IT was conducted by the SAT (Software Acceptance Team). SAT was formed in 1996 and it&amp;#8217;s primary goal was to review operational specifications of LOBs and test those applications against those specifications to ensure they were &amp;#8216;ready&amp;#8217; and &amp;#8216;able&amp;#8217; to be released into production. Part of the testing conducted by SAT was load testing. Testers would review the operations specs where the business would have articulated the anticipated user load and from there tools/scripts would be put to use to simulate that load. SAT remained in existence until 1999 at which time the testing they were conducting was rolled back into the development teams, however the benefits of a dedicated performance team stood out and those individuals who were driving load testing were spun off to create ACE. So that was the Cliff Notes version of ACE&amp;#8217;s history with performance testing, now moving onto PDL-IT&amp;#8230;.. &lt;/p&gt;  &lt;p align="justify"&gt;PDL-IT is a direct result of best practices and standards that we&amp;#8217;ve compiled over the past 10 years. Through PDL-IT we&amp;#8217;re able to build into the Software Development Lifecycle the necessary performance testing milestones needed to reduce the risk resulting from costly &lt;b&gt;IN PRODUCTION&lt;/b&gt; performance issues. As is the case with security issues, if you are able to uncover problems early in the development lifecycle the cost&amp;#160; (in terms of man hours and budget) to fix issues is dramatically reduced. That&amp;#8217;s why you&amp;#8217;ll find that through PDL-IT it calls for the engagement with application teams as earlier as the envisioning stage. That&amp;#8217;s when the business owners are sitting across the technologists describing the business objectives they&amp;#8217;re trying to hit. Part of that discussion &lt;b&gt;MUST&lt;/b&gt; be about expected user loads thus providing context around desired performance goals. The other reason behind PDL-IT was a more simplistic one, that was to put a &amp;#8216;name&amp;#8217; to our methodology. Its much easier when talking to application teams to say &amp;#8220;refer to PDL-IT&amp;#8221; Vs &amp;#8220;our team&amp;#8217;s methodology&amp;#8221;. I just finished recording a video that delves a bit deeper into PDL-IT, if you&amp;#8217;re interested in learning more about the methodology you can view the video &lt;a href="http://channel9.msdn.com/posts/Jossie/ACEs-Performance-Development-Lifecycle-for-IT-PDL-IT/"&gt;here&lt;/a&gt;. Hopefully between Abu&amp;#8217;s blog and my video you have a better idea of PDL-IT, we do plan on publishing more information on the methodology but meanwhile we look forward to your comments and questions.&amp;#160; &lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9530784" width="1" height="1"&gt;</description></item><item><title>Akshay’s Uncertainty Principle: Observing Some Metrics Changes Them</title><link>http://blogs.msdn.com/ace_team/archive/2009/03/31/akshay-s-uncertainty-principle-observing-some-metrics-changes-them.aspx</link><pubDate>Tue, 31 Mar 2009 16:04:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9512916</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/ace_team/comments/9512916.aspx</comments><wfw:commentRss>http://blogs.msdn.com/ace_team/commentrss.aspx?PostID=9512916</wfw:commentRss><description>&lt;p&gt;You’ve probably heard of the famous&amp;#160; Heisenberg Uncertainty Principle&amp;#160; in Quantum physics. It states &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“The more precisely the position is determined, the less precisely the momentum is known in this instant, and vice versa.”      &lt;br /&gt;--Heisenberg, uncertainty paper, 1927&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;This principle is related to the observer effect. In physics, the term &lt;b&gt;&lt;a href="http://en.wikipedia.org/wiki/Observer_effect_(physics)" target="_blank"&gt;observer effect&lt;/a&gt;&lt;/b&gt; refers to changes that the act of observation will make on the phenomenon being observed.&lt;/p&gt;  &lt;p&gt;Ok, now to get to the point. &lt;a href="http://nofud.org/2009/03/24/akshays-uncertainty-principle-observing-some-metrics-changes-them/"&gt;Read more…&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;- Akshay Aggarwal&lt;/p&gt;  &lt;p&gt;&lt;font size="1"&gt;If you like this post, &lt;/font&gt;&lt;a title="Sbscribe to my feed" href="http://feeds2.feedburner.com/noFUD"&gt;&lt;font size="1"&gt;subscribe to the RSS feed&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9512916" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/ace_team/archive/tags/management/default.aspx">management</category><category domain="http://blogs.msdn.com/ace_team/archive/tags/Information+Technology/default.aspx">Information Technology</category></item></channel></rss>