<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ACE Team - Security, Performance &amp; Privacy</title><link>http://blogs.msdn.com/b/ace_team/</link><description /><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Infrastructure Security expert?  Microsoft's ACE Team is hiring!</title><link>http://blogs.msdn.com/b/ace_team/archive/2010/10/21/infrastructure-security-expert-microsoft-s-ace-team-is-hiring.aspx</link><pubDate>Thu, 21 Oct 2010 20:23:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10079117</guid><dc:creator>Ahmad - ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=10079117</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2010/10/21/infrastructure-security-expert-microsoft-s-ace-team-is-hiring.aspx#comments</comments><description>&lt;p&gt;Do you have a passion for security and excited about impacting some of the largest and most complex infrastructure security challenges Microsoft is involved with today? If the answer is yes, you may be a candidate to join the ACE Team.&lt;/p&gt;
&lt;p&gt;The ACE (Assessment, Consulting &amp;amp; Engineering) team is the assessment arm of Microsoft&amp;rsquo;s Information Security &amp;amp; Risk Mgmt. (IS&amp;amp;RM) organization. Our team is a dynamic organization chartered with providing security assessment services to both Microsoft and to Microsoft&amp;rsquo;s enterprise and public sector customers to help effectively manage security risks. As a part of our charter, we are tasked with sharing and showcasing with external customers how Microsoft manages risks as well as to learn and bring back best practices from Microsoft&amp;rsquo;s customers to benefit Microsoft&amp;rsquo;s own risk management needs. &lt;br /&gt;&lt;br /&gt;The successful candidate for the Sr. Service Engineer (Information Security Consultant) role will engage in a consulting role with both internal clients and Microsoft&amp;rsquo;s public sector and enterprise customers to asses, develop and architect Microsoft infrastructure security solutions, specifically focused on the areas of public key infrastructure, Active Directory, certificate management and enterprise network security assessments. A thorough understanding of Microsoft technologies and experience deploying complex enterprise solutions will be valuable experience for the right candidate. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Senior Service Engineer (Information Security) responsibilities:&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Develop, design, and architect technical infrastructure security solutions, including the design and architecture of enterprise &lt;/li&gt;
&lt;li&gt;Windows PKI environments, the assessment of Microsoft Active Directory environments, deliver enterprise vulnerability scanning and leverage a thorough understanding of related technologies.&lt;/li&gt;
&lt;li&gt;Perform extensive technical consulting in the areas of infrastructure security focused on Microsoft technologies such as AD, LDAP, Windows PKI, SharePoint, Forefront TMG &amp;amp; UAG&lt;/li&gt;
&lt;li&gt;Follow all Microsoft services delivery methodology for external engagements, including ACE specific requirements around utilization, quality assurance, consistent delivery and meeting a high bar for customer satisfaction&lt;/li&gt;
&lt;li&gt;Geographic scope is the Americas however may require overseas travel. Very extensive travel is a requirement with most deliveries requiring onsite presence within the continental United States &lt;/li&gt;
&lt;li&gt;Must be able to work autonomously as well as in team environments, often in stressful, high impact situations &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Requirements/Qualifications and Previous Work and Related Experience:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Advanced knowledge of TCP/IP, Kerberos, PKI, AD, Windows Networking in the enterprise environment is required&lt;/li&gt;
&lt;li&gt;Excellent written, verbal and presentation skills are required&lt;/li&gt;
&lt;li&gt;Strong analytical and organizational skills are essential and required&lt;/li&gt;
&lt;li&gt;5+ years&amp;rsquo; experience conducting enterprise infrastructure security assessments, designing, deploying infrastructure security solutions required&lt;/li&gt;
&lt;li&gt;An understanding of ISO27002 standards and related assessment methodologies is desired&lt;/li&gt;
&lt;li&gt;CISSP, SANS certifications, Microsoft technology certifications and other security certifications are desired&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To apply, &lt;a target="_self" href="https://careers.microsoft.com/JobDetails.aspx?ss=&amp;amp;pg=0&amp;amp;so=&amp;amp;rw=1&amp;amp;jid=27320&amp;amp;jlang=EN" title="Microsoft Careers"&gt;click here&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10079117" width="1" height="1"&gt;</description></item><item><title>Technical Dependency Analysis</title><link>http://blogs.msdn.com/b/ace_team/archive/2010/02/19/technical-dependency-analysis.aspx</link><pubDate>Fri, 19 Feb 2010 19:37:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9966526</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9966526</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2010/02/19/technical-dependency-analysis.aspx#comments</comments><description>&lt;p&gt;Hi, I’m Kevin Harris, Principal Program Manager with Microsoft’s Enterprise Business Continuity Management (EBCM) team. This blog entry accompanies my video on a key component of our business continuity methodology – the &lt;u&gt;&lt;a href="http://edge.technet.com/Media/Business-Continuity-Technical-Dependency-Analysis/" target="_blank"&gt;Technical Dependency Analysis&lt;/a&gt;&lt;/u&gt; or TDA.&lt;/p&gt;  &lt;p&gt;The Business Impact Analysis (covered in an earlier &lt;a href="http://blogs.msdn.com/ace_team/archive/2010/01/26/using-the-business-impact-analysis.aspx" target="_blank"&gt;blog&lt;/a&gt; and &lt;a href="http://edge.technet.com/Media/Business-Continuity-Business-Impact-Analysis/" target="_blank"&gt;video&lt;/a&gt;) is our process driven engagement point that provides both an evaluation process criticality, using a standardized list of criteria to qualify and quantity the risk of an unexpected disruption. We engage directly with each business unit to document the anticipated impacts, which then substantiate the recovery goals for that process (in terms of recovery time objectives and recovery point objectives). Our implementation at Microsoft prioritizes those business processes that meet the company’s criticality standards. These “critical” processes then undergo a dependency analysis that includes non-technical items (such as people, internal or external dependencies) as well as technical dependencies (such as Line of Business applications, middleware, infrastructure, etc.).&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/TechnicalDependencyAnalysis_A35A/image_2.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/TechnicalDependencyAnalysis_A35A/image_thumb.png" width="531" height="345" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;For each technical dependency that the business identifies as essential for recovery, we conduct a detailed technical dependency analysis (TDA). The TDA is important because each application identified by the business is really a complex web of technical dependencies, which usually have additional technical components, secondary and/or tertiary dependencies that the business is unaware of but are essential to recovery of the Line of Business application. Without this important TDA phase, some technical dependencies that are working “behind the scenes” may be missed, which could prevent recovery of that particular business process or function.&lt;/p&gt;  &lt;p&gt;The TDA is critical to the successful implementation of a business recovery strategy. Each layer of each technical component needs to have its own recovery time objective that allows the successive layers ample time to recover and still meet the overall process recovery time objective (RTO). The TDA also assists us with identifying single points of failure and tracking critical technical assets.&lt;/p&gt;  &lt;p&gt;As I mention in the video, the TDA provides an “end-to-end” mapping or a blueprint of a technical environment. This information helps business continuity or disaster recovery teams to:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Understand the current recovery capability of a technical dependency &lt;/li&gt;    &lt;li&gt;Create strategies that take all aspects of technical recovery into account &lt;/li&gt;    &lt;li&gt;Gain insight into capacity planning for shared infrastructure elements. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;In addition to BCM, the data collected during the TDA has benefits that extend well beyond a BCM program. For example, periodic review of an “end-to-end” process can result in process and quality optimization. These technical “blueprints” provide holistic views for enabling effective service management, managing a service catalog, as well as modeling opportunities for new architecture designs or system deployments. Organizations can also use this information to plan for or evaluate risks associated with a specific element of infrastructure as I mention in the video with the data center example. The information asset from the TDA also helps crisis management teams understand business impact of threats (e.g. flood impacts to a data center).&lt;/p&gt;  &lt;p&gt;Our broader vision is to build an information asset that provides value to and is maintained by a broad stakeholder community. One of the single most important best practices associated with any BCM program is keeping the data and plans current; the TDA is no exception, so it is important that refreshes of the data occur regularly. Organizational discipline with Change Management practices and BCM maintenance policies are essential to ensuring the information stays relevant and disaster recovery capabilities meet stakeholder expectations.&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;-Kevin Harris    &lt;br /&gt;Principal Program Manager, Enterprise Business Continuity     &lt;br /&gt;&lt;a href="http://www.msinfosec.com/"&gt;Microsoft Information Security&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9966526" width="1" height="1"&gt;</description></item><item><title>Using the Business Impact Analysis</title><link>http://blogs.msdn.com/b/ace_team/archive/2010/01/26/using-the-business-impact-analysis.aspx</link><pubDate>Tue, 26 Jan 2010 16:53:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9953569</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9953569</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2010/01/26/using-the-business-impact-analysis.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Hi all, I’m Tom Easthope, Sr. Program Manager on the Enterprise Business Continuity team at Microsoft.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This blog entry is a companion to the &lt;A title="Business Continuity: Business Impact Analysis" href="http://edge.technet.com/Media/Business-Continuity-Business-Impact-Analysis/" target=_blank mce_href="http://edge.technet.com/Media/Business-Continuity-Business-Impact-Analysis/"&gt;video interview&lt;/A&gt; about a key component of our business continuity methodology – the Business Impact Assessment or BIA.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The BIA is a foundation tool in BCM program as it provides both qualitative and quantitative measures of impact to a company in the event of a business process disruption.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The BIA is a key component of a BCM program as it creates a more holistic or “business driven” perspective which differentiates business continuity from the more IT centric disaster recovery processes.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The BIA also creates an enterprise wide standard or common taxonomy across business units which help to align cross organizational collaboration activities as well facilitate reporting at an enterprise level.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;At Microsoft, the BIA understandably is a key engagement point for our BCM program.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Each BIA session is facilitated by a certified professional in our enterprise program office or in one of the “embedded” teams in our business units.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Our BIA evaluates criticality along two dimensions:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Time &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Impact across six categories:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;(Revenue, Customer Partner/Experience, 3&lt;SUP&gt;rd&lt;/SUP&gt; Parties, Legal/Regulatory, Workforce and Brand/Shareholder)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The BIA and the larger BCM program are aided at Microsoft by several governance organizations that provide leadership on setting enterprise wide standards to providing feedback on the company implementation of the BIA.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These groups provide organizational credibility; reflect ongoing commitment and accountability of results – all key criteria for any successful enterprise program.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;One less obvious benefit of the BIA is that it serves as a great business justification tool.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For example, in resource constrained situations such as the current economic environment, the BIA can be a great tool to align investment priorities with those organizational functions that are most critical to the business and its stakeholders.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;For this reason it is important to keep BIA assessments current.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The pace of business is accelerating and today’s emerging products or functions can quickly become tomorrow’s category leading product or primary cost cutting strategy.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Only a current BIA can fundamentally integrate these emerging areas into the mainstream of a business continuity program and deliver on the organizational resiliency expectations of our customers and stakeholders.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNoSpacing&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In our next blog posting we’ll spend some time on the Technical Dependency Analysis function in our EBCM program that will compliment, my colleague, Kevin Harris’s video on the subject.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNoSpacing&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNoSpacing&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;-Tom Easthope&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNoSpacing&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Senior Program Manager, Enterprise Business Continuity&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNoSpacing&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;A href="http://www.msinfosec.com/"&gt;&lt;FONT color=#4c6d7e&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9953569" width="1" height="1"&gt;</description></item><item><title>Simple Rules To Stop Bad Guys</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/12/16/simple-rules-to-stop-bad-guys.aspx</link><pubDate>Wed, 16 Dec 2009 09:46:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9937538</guid><dc:creator>TheRockyH</dc:creator><slash:comments>10</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9937538</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/12/16/simple-rules-to-stop-bad-guys.aspx#comments</comments><description>&lt;P&gt;Hi, RockyH here,&lt;/P&gt;
&lt;P&gt;I was browsing for IT security news from the hotel this evening and came across this gem:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/SimpleRulesToStopBadGuys_1459/image_6.png" mce_href="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/SimpleRulesToStopBadGuys_1459/image_6.png"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/SimpleRulesToStopBadGuys_1459/image_thumb_2.png" width=244 height=110 mce_src="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/SimpleRulesToStopBadGuys_1459/image_thumb_2.png"&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That’s it. Of course there is no information about who to email, and why should their be. If they can’t figure out how to tell the difference between malicious traffic and real traffic other than by blocking entire IP ranges, there is little chance they could filter out spam should their email address be harvested off their web page. &lt;/P&gt;
&lt;P&gt;After saying that I checked again the following night and they had amended their little blocked access page:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/SimpleRulesToStopBadGuys_1459/image_3.png" mce_href="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/SimpleRulesToStopBadGuys_1459/image_3.png"&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: inline; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px" title=image border=0 alt=image src="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/SimpleRulesToStopBadGuys_1459/image_thumb.png" width=244 height=126 mce_src="http://blogs.msdn.com/blogfiles/ace_team/WindowsLiveWriter/SimpleRulesToStopBadGuys_1459/image_thumb.png"&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Besides, at best this is a triviality. It’s security theatre. When you set your machine to use a proxy through work or something like &lt;A href="http://www.torproject.org/" mce_href="http://www.torproject.org/"&gt;TOR&lt;/A&gt; you can get right past this kind of thing. &lt;/P&gt;
&lt;P&gt;Almost every modern firewall product can do packet inspection to look for genuine malicious attack patterns.&amp;nbsp; In the modern Internet there is no need to do blind IP Range blocking. This was never a good idea in the first place, after all what you have really done is create a Denial Of Service (DOS) attack on yourself. Good thinking. &lt;/P&gt;
&lt;P&gt;That reminds me of a guy who told me about the protection he built into his web site to prevent SQL injection. He said, “What I do is look for SQL injection attacks like OR 1=1 and if I find one, I kill the web application with an exception.” Right, so now all I have to do to take down your site is send you an ‘OR 1=1’ in the search page and Blamo, your site goes offline. Good thinking.&lt;/P&gt;
&lt;P&gt;Ok everyone, pay attention! The best way to handle these kinds of things is a very simple tactic called Input Validation. Say it with me now, Input Validation! &lt;/P&gt;
&lt;P&gt;All your commercial firewalls can do stateful packet inspection and drop suspect packets. Things like &lt;A href="http://www.microsoft.com/forefront/threat-management-gateway/en/us/overview.aspx" mce_href="http://www.microsoft.com/forefront/threat-management-gateway/en/us/overview.aspx"&gt;Threat Management Gateway (TMG)&lt;/A&gt; can even inspect traffic at the logical level and filter out known bad attack strings such as those used to exploit known vulnerabilities. Now I don’t recommend this kind of black-list inspection as your only means of defence, but it’s good to put a rule in place to plug the whole while the developers work on the patch. &lt;/P&gt;
&lt;P&gt;With over 90% of the actual attacks happening at the application layer, this is where you should concentrate your defensive measures. It all starts with the software. If you have in-house developed applications, you can no longer afford to rely on goofy blacklisting mentioned above.&lt;/P&gt;
&lt;P&gt;Here are a few simple rules for application development that will stop a vast majority of the attacks out there. &lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Rule #1:&lt;/STRONG&gt; Implement a Secure Development Lifecycle in your organisation.&lt;/H2&gt;
&lt;P&gt;This includes the following activities:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Train your developers, and testers in secure development and secure testing respectively &lt;/LI&gt;
&lt;LI&gt;Establish a team of security experts to be the ‘go to’ group when people want advice on security &lt;/LI&gt;
&lt;LI&gt;Implement Threat Modelling in your development process. If you do nothing else, do this! &lt;/LI&gt;
&lt;LI&gt;Implement Automatic and Manual Code Reviews for your in-house written applications &lt;/LI&gt;
&lt;LI&gt;Ensure you have ‘Right to Inspect’ clauses in your contracts with vendors and third parties that are producing software for you &lt;/LI&gt;
&lt;LI&gt;Have your testers include basic security testing in their standard testing practices &lt;/LI&gt;
&lt;LI&gt;Do deployment reviews and hardening exercises for your systems &lt;/LI&gt;
&lt;LI&gt;Have an emergency response process in place and keep it updated &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;If you want some good information on doing this, email me and check out this link: &lt;BR&gt;&lt;A href="http://www.microsoft.com/security/sdl/default.aspx" mce_href="http://www.microsoft.com/security/sdl/default.aspx"&gt;http://www.microsoft.com/sdl&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Rule #2:&lt;/STRONG&gt; Implement a centralised input validation system (CIVS) in your organisation. &lt;/H2&gt;
&lt;P&gt;These CIVS systems are designed to perform common input validation on commonly accepted input values. Let’s face it, as much as we’d all like to believe that we are the only ones doing things like, registering users, or recording data from visitors it’s actually all the same thing. &lt;/P&gt;
&lt;P&gt;When you receive data it will very likely be an integer, decimal, phone number, date, URI, email address, post code, or string. The values and formats of the first 7 of those are very predictable. The string’s are a bit harder to deal with but they can all be validated against known good values. Always remember to check for the three F’s; Form, Fit and Function.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Form: Is the data the right type of data that you expect? If you are expecting a quantity, is the data an integer? Always cast data to a strong type as soon as possible to help determine this. &lt;/LI&gt;
&lt;LI&gt;Fit: Is the data the right length/size? Will the data fit in the buffer you allocated (including any trailing nulls if applicable). If you are expecting and Int32, or a Short, make sure you didn’t get an Int64 value. Did you get a positive integer for a quantity rather than a negative integer? &lt;/LI&gt;
&lt;LI&gt;Function: Can the data you received be used for the purpose it was intended? If you receive a date, is the date value in the right range? If you received an integer to be used as an index, is it in the right range? If you received an int as a value for an Enum, does it match a legitimate Enum value? &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;In a vast majority of the cases, string data being sent to an application will be 0-9, a-z, A-Z. In some cases such as names or currencies you may want to allow –, $, % and ‘. You will almost never need , &amp;lt;&amp;gt; {} or [] unless you have a special use case such as &lt;A href="http://www.regexlib.com/" mce_href="http://www.regexlib.com"&gt;http://www.regexlib.com&lt;/A&gt; in which case see Rule #3.&lt;/P&gt;
&lt;P&gt;You want to build this as a centralised library so that all of the applications in your organisation can use it. This means if you have to fix your phone number validator, everyone gets the fix. By the same token, you have to inspect and scrutinise the crap out of these CIVS to ensure that they are not prone to errors and vulnerabilities because everyone will be relying on it. But, applying heavy scrutiny to a centralised library is far better than having to apply that same scrutiny to every single input value of every single application.&amp;nbsp; You can be fairly confident that as long as they are using the CIVS, that they are doing the right thing. &lt;/P&gt;
&lt;P&gt;Fortunately implementing a CIVS is easy if you start with the &lt;A href="http://msdn.microsoft.com/en-us/library/cc309509.aspx" mce_href="http://msdn.microsoft.com/en-us/library/cc309509.aspx"&gt;Enterprise Library Validation Application Block&lt;/A&gt; which is a free download from &lt;A href="http://www.microsoft.com/" mce_href="http://www.microsoft.com"&gt;Microsoft&lt;/A&gt; that you can use in all of your applications. &lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Rule #3:&lt;/STRONG&gt; Implement input/output encoding for all externally supplied values.&lt;/H2&gt;
&lt;P&gt;Due to the prevalence of cross site scripting vulnerabilities, you need to encode any values that came from an outside source that you may display back to the browser. (even embedded browsers in thick client applications). The encoding essentially takes potentially dangerous characters like &amp;lt; or &amp;gt; and converts them into their HTML, HTTP, or URL equivalents. &lt;/P&gt;
&lt;P&gt;For example, if you were to HTTP encode &amp;lt;script&amp;gt;alert(‘XSS Bug’)&amp;lt;/script&amp;gt; it would look like: &amp;amp;lt;script&amp;amp;gt;alert('XSS Bug')&amp;amp;lt;/script&amp;amp;gt;&amp;nbsp; A lot of this functionality is build into the .NET system. For example, the code to do the above looks like:&lt;/P&gt;
&lt;P&gt;Server.HtmlEncode("&amp;lt;script&amp;gt;alert('XSS Bug')&amp;lt;/script&amp;gt;");&lt;/P&gt;
&lt;P&gt;However it is important to know that the Server.HTMLEncode only encodes about 4 of the nasty characters you might encounter. It’s better to use a more ‘industrial strength’ library like the &lt;A href="http://msdn.microsoft.com/en-us/security/aa973814.aspx" mce_href="http://msdn.microsoft.com/en-us/security/aa973814.aspx"&gt;Anti Cross Site Scripting library&lt;/A&gt;. Another free download from &lt;A href="http://www.microsoft.com/" mce_href="http://www.microsoft.com"&gt;Microsoft&lt;/A&gt;. This library does a lot more encoding and will do HTTP and URI encoding based on a whitelist. The above encoding would look like this in AntiXSS&lt;/P&gt;
&lt;P&gt;using Microsoft.Security.Application; &lt;BR&gt;AntiXss.HtmlEncode("&amp;lt;script&amp;gt;alert('XSS Bug')&amp;lt;/script&amp;gt;");&lt;/P&gt;
&lt;P&gt;You can also run a neat test system that a friend of mine developed to test your application for XSS vulnerabilities in its outputs. It is aptly named &lt;A href="http://www.acorns.com.au/blog/?p=154" mce_href="http://www.acorns.com.au/blog/?p=154"&gt;XSS Attack Tool&lt;/A&gt;. &lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Rule #4:&lt;/STRONG&gt; Abandon Dynamic SQL&lt;/H2&gt;
&lt;P&gt;There is no reason you should be using dynamic SQL in your applications anymore. If your database does not support parameterised stored procedures in one form or another, get a new database. &lt;/P&gt;
&lt;P&gt;Dynamic SQL is when developers try to build a SQL query in code then submit it to the DB to be executed as a string rather than calling a stored procedures and feeding it the values. It usually looks something like this:&lt;/P&gt;
&lt;P&gt;(for you VB fans)&lt;/P&gt;
&lt;P&gt;dim sql &lt;BR&gt;sql = "Select ArticleTitle, ArticleBody FROM Articles WHERE ArticleID = " &lt;BR&gt;sql = sql &amp;amp; request.querystring("ArticleID") &lt;BR&gt;set results = objConn.execute(sql)&lt;/P&gt;
&lt;P&gt;In fact, &lt;A href="http://www.sqlteam.com/article/introduction-to-dynamic-sql-part-1" mce_href="http://www.sqlteam.com/article/introduction-to-dynamic-sql-part-1"&gt;this article from 2001&lt;/A&gt; is chock full of what NOT to do. Including dynamic SQL in a stored procedure. &lt;/P&gt;
&lt;P&gt;Here is an example of a stored procedure that is vulnerable to SQL Injection:&lt;/P&gt;
&lt;P&gt;Create Procedure GenericTableSelect @TableName VarChar(100) &lt;BR&gt;AS &lt;BR&gt;Declare @SQL VarChar(1000) &lt;BR&gt;SELECT @SQL = 'SELECT * FROM ' &lt;BR&gt;SELECT @SQL = @SQL + @TableName &lt;BR&gt;Exec ( @SQL) GO&lt;/P&gt;
&lt;P&gt;See this article for a look at &lt;A href="http://support.microsoft.com/kb/310130" mce_href="http://support.microsoft.com/kb/310130"&gt;using Parameterized Stored Procedures&lt;/A&gt;. &lt;/P&gt;
&lt;H2&gt;Rule #5: Properly architect your applications for scalability and failover&lt;/H2&gt;
&lt;P&gt;Applications can be brought down by a simple crash. Or a not so simple one. Architecting your applications so that they can scale easily, vertically or horizontally, and so that they are fault tolerant will give you a lot of breathing room. &lt;/P&gt;
&lt;P&gt;Keep in mind that fault tolerant is not just a way to say that they restart when they crash. It means that you have a proper exception handling hierarchy built into the application.&amp;nbsp; It also means that the application needs to be able to handle situations that result in server failover. This is usually where session management comes in. &lt;/P&gt;
&lt;P&gt;The best fault tolerant session management solution is to store session state in SQL Server.&amp;nbsp; This also helps avoid the server affinity issues some applications have. &lt;/P&gt;
&lt;P&gt;You will also want a good load balancer up front. This will help distribute load evenly so that you won’t run into the failover scenario often hopefully. &lt;/P&gt;
&lt;P&gt;And by all means do NOT do what they did on the site in the beginning of this article. Set up your routers and switches to properly shunt bad traffic or DOS traffic. Then let your applications handle the input filtering. &lt;/P&gt;
&lt;H2&gt;Rule #6: Always check the configuration of your production servers&lt;/H2&gt;
&lt;P&gt;Configuration mistakes are all too popular. When you consider that proper server hardening and standard out of the box deployments are probably a good secure default, there are a lot of people out there changing stuff that shouldn’t be. You may have remembered when Bing went down for about 45 minutes. That was due to configuration issues. &lt;/P&gt;
&lt;P&gt;To help address this, we have released the Web Application Configuration Auditor (WACA). This is a free download that you can use on your servers to see if they are configured according to best practice. You can download it &lt;A href="https://connect.microsoft.com/site734/Downloads" mce_href="https://connect.microsoft.com/site734/Downloads"&gt;at this link&lt;/A&gt;. [edited to fix link]&lt;/P&gt;
&lt;P&gt;You should establish a standard SOE for your web servers that is hardened and properly configured. Any variations to that SOE should be scrutinised and go through a very thorough change control process. Test them first before turning them loose on the production environment…please. &lt;/P&gt;
&lt;P&gt;So with all that being said, you will be well on your way to stopping the majority of attacks you are likely to encounter on your web applications. Most of the attacks that occur are SQL Injection, XSS, and improper configuration issues. The above rules will knock out most of them. In fact, Input Validation is your best friend. Regardless of inspecting firewalls and things, the applications is the only link in the chain that can make an intelligent and informed decision on if the incoming data is actually legit or not. So put your effort where it will do you the most good. &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9937538" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Security/">Security</category><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/SDL_2D00_IT/">SDL-IT</category><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Anti_2D00_XSS/">Anti-XSS</category><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/rules/">rules</category><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/input+validation/">input validation</category><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/sql+injection/">sql injection</category><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/waca/">waca</category></item><item><title>InfoSec A&amp;P Suite: How to Install &amp; Configure</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/11/30/infosec-a-p-suite-how-to-install-configure-the-tools.aspx</link><pubDate>Tue, 01 Dec 2009 01:24:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9930488</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9930488</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/11/30/infosec-a-p-suite-how-to-install-configure-the-tools.aspx#comments</comments><description>&lt;P&gt;Hi everyone, Diane here.&amp;nbsp; Recently the &lt;A href="http://blogs.msdn.com/securitytools/" target=_blank mce_href="http://blogs.msdn.com/securitytools/"&gt;Information Security Tools&lt;/A&gt; (IST) Team released the &lt;A href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx" mce_href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx"&gt;Assessment &amp;amp; Protection (A&amp;amp;P) Suite&lt;/A&gt;. If you missed the overview on the A&amp;amp;P suite, check out the &lt;A href="http://blogs.msdn.com/ace_team/archive/2009/11/16/introducing-the-infosec-assessment-protection-suite.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/archive/2009/11/16/introducing-the-infosec-assessment-protection-suite.aspx"&gt;Information Security blog&lt;/A&gt;.&amp;nbsp; The Web Protection Library v1.0 (WPL) Security Runtime Engine (SRE) has been significantly updated.&amp;nbsp; Anil Revuru (RV) from the IST team discusses these updates in his recent &lt;A href="http://blogs.msdn.com/securitytools/archive/2009/11/18/how-to-configure-wpl-v1-0-sre.aspx" mce_href="http://blogs.msdn.com/securitytools/archive/2009/11/18/how-to-configure-wpl-v1-0-sre.aspx"&gt;blog&lt;/A&gt; and also provides a walkthrough on how to configure WPL SRE.&amp;nbsp; The WPL (formerly Anti-XSS Library) has also been expanded and includes new mitigation for attacks such as SQL injection, cross-site request forgery (CSRF), setting enforcement like SSL &amp;amp; HTTP_ONLY cookies and more.&amp;nbsp; RV discusses these attacks in more detail in his recent video “&lt;A href="http://channel9.msdn.com/posts/Jossie/Using-the-Web-Protection-Library-WPL-CTP-Version/" mce_href="http://channel9.msdn.com/posts/Jossie/Using-the-Web-Protection-Library-WPL-CTP-Version/"&gt;Using the Web Protection Library (WPL) - CTP Version&lt;/A&gt;.”&amp;nbsp; &lt;/P&gt;
&lt;P&gt;In addition, for the assessment tools of the A&amp;amp;P suite which includes the Code Analysis Tool for .NET (CAT.NET) and Web Application Configuration Analyzer (WACA), RV talks about how to install and configure&amp;nbsp; CAT.NET v2.0 in his blog “&lt;A href="http://blogs.msdn.com/securitytools/archive/2009/11/12/how-to-run-cat-net-2-0-ctp.aspx" mce_href="http://blogs.msdn.com/securitytools/archive/2009/11/12/how-to-run-cat-net-2-0-ctp.aspx"&gt;How to Run CAT.NET 2.0 CTP&lt;/A&gt;”.&amp;nbsp; To configure the WACA tool RV provides guidance how to setup this tool in his video “&lt;A href="http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analizer-WACA/" target=_blank mce_href="http://channel9.msdn.com/posts/Jossie/Web-Application-Configuration-Analizer-WACA/"&gt;Using Web Application Configuration Analyzer (WACA) - CTP Version&lt;/A&gt;”. &lt;/P&gt;
&lt;P&gt;The CTP (Community Technology Preview) is available in &lt;A href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" mce_href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734"&gt;Microsoft Connect – Information Security Tools&lt;/A&gt;.&amp;nbsp; Read &lt;A href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx" mce_href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx"&gt;CTP announcement&lt;/A&gt; and follow the &lt;A href="http://blogs.msdn.com/securitytools" target=_blank mce_href="http://blogs.msdn.com/securitytools"&gt;Information Security Tools&lt;/A&gt; team blog. &lt;/P&gt;
&lt;P&gt;-Diane Talvo &lt;BR&gt;Security Awareness Program Manager &lt;BR&gt;&lt;A href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;Microsoft Information Security&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9930488" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/InfoSec+Assessment+_2600_amp_3B00_+Protection+Suite/">InfoSec Assessment &amp;amp; Protection Suite</category></item><item><title>Introducing the InfoSec Assessment &amp; Protection Suite</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/11/16/introducing-the-infosec-assessment-protection-suite.aspx</link><pubDate>Mon, 16 Nov 2009 21:49:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9923183</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9923183</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/11/16/introducing-the-infosec-assessment-protection-suite.aspx#comments</comments><description>&lt;P&gt;The &lt;A href="http://blogs.msdn.com/securitytools/default.aspx" mce_href="http://blogs.msdn.com/securitytools/default.aspx"&gt;Information Security Tools (IST)&lt;/A&gt; team has released the &lt;A href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx" mce_href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx"&gt;InfoSec Assessment &amp;amp; Protection (A&amp;amp;P) Suite&lt;/A&gt;.&amp;nbsp; It’s a suite made up of protection and assessment tools which include: &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;B&gt;Web Protection Library (WPL) - &lt;/B&gt;an umbrella for several libraries and runtime modules including the Microsoft Anti-Cross Site Scripting Library v3.1 (Anti-XSS V3.1) and SRE, packaged together with Anti-XSS when downloaded. Helps prevent XSS and SQL injection attacks, but instead of having to make changes to the code (which is manual and costly), a user makes changes to the application configuration and not the code (white list/black list). Watch the podcast, “&lt;A href="http://channel9.msdn.com/posts/Jossie/Enhanced-Web-Protection-Library/" mce_href="http://channel9.msdn.com/posts/Jossie/Enhanced-Web-Protection-Library/"&gt;Enhanced Web Protection Library&lt;/A&gt;,” as Anil Revuru (RV) from the IST teams shares the details of the new expansion of this library.&lt;/LI&gt;
&lt;LI&gt;&lt;B&gt;Code Analysis Tool for .NET (CAT.NET)&lt;/B&gt; - a managed code security source code scanning tool that has been totally rewritten. &lt;/LI&gt;
&lt;LI&gt;&lt;B&gt;Web Application Configuration Analyzer (WACA)&lt;/B&gt; designed to scan your development environment against best practices for .NET security configuration, IIS settings, SQL Server Security best practices and some Windows permission settings. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Read more about the the A&amp;amp;P suite &lt;A href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx" target=_blank mce_href="http://blogs.msdn.com/infosec/archive/2009/11/16/infosec-assessment-protection-a-p-suite-released.aspx"&gt;here&lt;/A&gt; and watch the podcast, “&lt;A href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/" mce_href="http://channel9.msdn.com/posts/Jossie/Assessment-and-Protection-Suite/"&gt;Assessment and Protection Suite&lt;/A&gt;,” as Anil Revuru (RV) and Mark Curphey from &lt;A href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Microsoft IST team&lt;/A&gt; discuss the future of this suite of tools.&lt;/P&gt;
&lt;P&gt;To download these tools for free, you will need to register on the &lt;A href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734" mce_href="https://connect.microsoft.com/site/sitehome.aspx?SiteID=734"&gt;Connect site&lt;/A&gt;. Once you’ve registered, you can download the tools below directly. Get the latest on the A&amp;amp;P Suite on the &lt;A href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx" mce_href="http://blogs.msdn.com/securitytools/archive/2009/11/11/some-new-software-security-tools-for-web-developers-ctp-releases.aspx"&gt;IST Blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;Download, A&amp;amp;P Suite will include:&lt;/B&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=734&amp;amp;DownloadID=23328" mce_href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=734&amp;amp;DownloadID=23328"&gt;CAT.NET 2.0 CTP&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=734&amp;amp;DownloadID=23329" mce_href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=734&amp;amp;DownloadID=23329"&gt;WPL 1.0 CTP&lt;/A&gt; &lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=734&amp;amp;DownloadID=23330" mce_href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=734&amp;amp;DownloadID=23330"&gt;WACA 1.0 CTP&lt;/A&gt; &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;-Diane Talvo &lt;BR&gt;&lt;A href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Microsoft Information Security&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9923183" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/InfoSec+Assessment+_2600_amp_3B00_+Protection+Suite/">InfoSec Assessment &amp;amp; Protection Suite</category></item><item><title>Dogfooding: How Microsoft IT Information Security Dogfoods: Product Influence</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/10/30/dogfooding-how-microsoft-it-information-security-dogfoods-product-influence.aspx</link><pubDate>Sat, 31 Oct 2009 00:40:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9915567</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9915567</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/10/30/dogfooding-how-microsoft-it-information-security-dogfoods-product-influence.aspx#comments</comments><description>&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hi Steven Michalove here, I’m a principal program manager on Microsoft IT’s &lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt; (InfoSec) group. For the last of couple weeks, we’ve been talking about Microsoft IT’s (MSIT) dogfooding process, known as the First &amp;amp; Best program. Concluding this dogfooding blog series, I would like to share with you how we help influence the development of products from an information security risk perspective. If you missed the prior blogs, read Mark Smith’s &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx" mce_href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx"&gt;&lt;FONT size=2 face="Segoe UI"&gt;blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; for an overview of the process, Don Nguyen’s &lt;/FONT&gt;&lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 1: Conduct a Security Design Review" href="http://blogs.msdn.com/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx"&gt;blog&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt; for &lt;I&gt;Phase 1&lt;/I&gt; and Price Oden’s recent &lt;/FONT&gt;&lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 2: Perform an Assessment of the Features Only" href="http://blogs.msdn.com/ace_team/archive/2009/10/26/dogfooding-how-microsoft-it-information-security-dogfoods-phase-2-perform-an-assessment-of-the-features-only.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/archive/2009/10/26/dogfooding-how-microsoft-it-information-security-dogfoods-phase-2-perform-an-assessment-of-the-features-only.aspx"&gt;blog&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt; for &lt;I&gt;Phase 2&lt;/I&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;A little background on me, I am a subject matter expert that works with security features in the Windows OS. Our team mission is to deploy controls that mitigate security risks for Microsoft. In the last few years I have been working in the area of Desktop Encryption and the deployment of BitLocker&lt;SUP&gt;TM&lt;/SUP&gt; internally within Microsoft. As part of the First &amp;amp; Best program, we act as early adopters and influencers of specific features like BitLocker&lt;SUP&gt;TM&lt;/SUP&gt;. Our role stretches throughout the entire lifecycle of a product release to test, pilot, and improvements to a product while at the same time making a measureable impact on reducing risk.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Additionally, I am a deployer of new security technologies where I get an early look at Microsoft technologies. Basically we get the bits earlier than our customer and we can log bugs and feature requests directly with our internal product developers. Since we deploy and also evaluate the deployment early, we get a look at the features while there’s still an opportunity to both test the technology and provide input into the features themselves. We generally give three kinds of feedback and the focus may change depending on where in the development lifecycle the product or feature may be. Those three kinds of feedback usually are 1) Technical errors that often indicate some kind of bug or programming error, 2) Manageability issues and documentation that influence enterprise scale deployments and 3) Feature feedback and requests. Along with providing feedback to the product teams, we’ll often brainstorm and discuss options with the developers. Our feedback really depends upon the product lifecycle, specifically how early in the process we are involved. Additionally, often times we will also develop shared goals and pilot programs (both mandatory and optional) with target numbers. For example, we may say we want to install 1000 systems with a pre-Beta build and turn on a specific feature. We’ll then build the measurement instrumentation to support the shared goals and recruit users to help.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;An example of MSIT’s involvement with influencing a product is the move from Vista to Windows 7 specifically around enterprise manageability and deployment ease of BitLocker&lt;SUP&gt;TM&lt;/SUP&gt;. The Vista splitloader that’s needed for BitLocker&lt;SUP&gt;TM&lt;/SUP&gt; is 1.5G. However, it can be hard to retrofit onto a system with existing drives. In Windows 7 not only did we shrink that to 100Mb (depending on certain options) but also, with MSIT’s input, improved the shrink API code base to help make the shrink operation itself more reliable. So while these improvements did not influence the BitLocker™ feature itself, it improved the deployment footprint of the feature.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;The dogfooding process is an iterative approach. We’ve been early adopters of our own technology for quite some time. Some questions we ask ourselves are, “what will our universe will look like in three to five years; will we see new technologies and threats; if we could achieve a dream state, what would that be?” If you’re thinking about implementing a dogfooding program in your own company, here are a few things to consider. Primary on the list is management support. The total cost of ownership is much higher as you test technologies in the production environment. For example, we have more versions of operating systems deployed than most companies, even more than our &lt;/FONT&gt;&lt;A title="Technical Adoption Program" href="http://msdn.microsoft.com/en-us/isv/bb190413.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/isv/bb190413.aspx"&gt;TAP customers&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt;, since we get software very early in the pre-release cycle. Most companies would not consider these early versions production ready for at scale deployments. We do it differently and deploy these early versions into our production environments at scale to aid in the product development lifecycle – we take the first and best objective into our operation and make it part of our overall footprint. That is how Microsoft does IT. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;&lt;FONT face="Segoe UI"&gt;Making the decision to use the production IT environment as an incubator for new technologies is a business decision. We have to both support and upgrade, as well as migrate and deploy, constantly. This can be expensive and that’s where having a strong business sponsorship is necessary. Seek specific measurable outcomes and boundaries. Agreeing on quantitative shared goals and resourcing them is a constant challenge but it needs to be a continuous process. Next, setup a mechanism to recycle the knowledge you gain. If early deployments teach you something, make sure you have the knowledge management in place to leverage this through to the production (finished, released product) systems deployments. &lt;INS dateTime=2009-11-02T11:03 cite="mailto:Steven%20Michalove"&gt;&lt;/INS&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Eventually a “dogfood” cycle ends and things move to a full production environment. You can gain a lot of speed with your early learnings. Set yourself up for that. Lastly, be prepared to deal with outages and bugs in early versions; software is unpredictable at scale so you need to have a plan “B” prepared so you can back out or limit unintended consequences. You can almost always be sure the thing you least expect will be discovered in pre-release versions, plan ahead and be prepared for the unexpected. The upside is because Microsoft IT uses early versions the released versions are stable and predictable.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hope you have enjoyed our dogfooding blog series. Watch my recent video, "&lt;A id=ctl00_MainPlaceHolder_Starter_TitleLink title="Dogfooding: Deplyoment &amp;amp; Product Influence" href="http://edge.technet.com/Media/Dogfooding-Deplyoments--Product-Influence/" target=_blank mce_href="http://edge.technet.com/Media/Dogfooding-Deplyoments--Product-Influence/"&gt;Dogfooding: Deplyoment &amp;amp; Product Influence&lt;/A&gt;,"&amp;nbsp;as I discuss in more detail on&amp;nbsp;our dogfooding process.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;- Steven Michalove &lt;BR&gt;Principal Program Manager&amp;nbsp; &lt;BR&gt;&lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com/"&gt;Microsoft Information Security&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9915567" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/dogfooding/">dogfooding</category></item><item><title>Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 2: Perform an Assessment of the Features Only</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/10/26/dogfooding-how-microsoft-it-information-security-dogfoods-phase-2-perform-an-assessment-of-the-features-only.aspx</link><pubDate>Mon, 26 Oct 2009 18:03:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9913062</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9913062</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/10/26/dogfooding-how-microsoft-it-information-security-dogfoods-phase-2-perform-an-assessment-of-the-features-only.aspx#comments</comments><description>&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hi Price Oden here, I’m a principal senior security architect on the Microsoft IT &lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank&gt;&lt;FONT size=2 face="Segoe UI"&gt;Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; (InfoSec) group. Dogfooding is part of Microsoft IT’s culture.&amp;nbsp; It’s where Microsoft IT (MSIT) plays an important role and service for Microsoft’s enterprise customers.&amp;nbsp; Despite the challenges of mixing testing and production on the same network and environment, MSIT trials new products at large scale in a production environment to identify and address deployment, operational and functional issues before those products reach Microsoft’s enterprise customers.&amp;nbsp; In this blog, I’ll talk about the next phase of our dogfooding process, &lt;I&gt;Phase 2: Perform an Assessment of the Features Only&lt;/I&gt;. To get an &lt;I&gt;overview&lt;/I&gt; of the dogfooding process, read Mark Smith’s &lt;/FONT&gt;&lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods" href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx" target=_blank&gt;&lt;FONT size=2 face="Segoe UI"&gt;blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; and also read about &lt;I&gt;Phase 1&lt;/I&gt; in Don Nguyen’s &lt;/FONT&gt;&lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 1: Conduct a Security Design Review" href="http://blogs.msdn.com/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx" target=_blank&gt;&lt;FONT size=2 face="Segoe UI"&gt;blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;In phase 2, after the ACE Team performs a security design review, the Security Operations Planning and Strategy Team which I’m a part of, we conduct an assessment of the features only.&amp;nbsp; For this assessment, we assess security-related features and technologies in upcoming Microsoft software products to determine how they help us in MSIT’s efforts to reduce risks in the enterprise.&amp;nbsp; Our team works with the product groups to obtain the design and functional specs and early beta builds.&amp;nbsp; If the product or feature is a good candidate, we’ll dive into technical details with the product group.&amp;nbsp; In addition, if necessary we’ll install and configure the product and tests use cases.&amp;nbsp; One example that our team was involved with was the &lt;A href="http://www.microsoft.com/windows/enterprise/products/windows-7/features.aspx#bitlocker" target=_blank&gt;Windows 7 BitLocker to Go&lt;/A&gt;&lt;SUP&gt;TM &lt;/SUP&gt;feature.&amp;nbsp; An industry trend is the explosion of removable media used in the enterprise. We prescribed &lt;A title="Windows 7 BitLocker to Go" href="http://www.microsoft.com/windows/enterprise/products/windows-7/features.aspx#bitlocker" target=_blank&gt;Windows 7 BitLocker to Go&lt;/A&gt;&lt;SUP&gt;TM &lt;/SUP&gt;as an excellent risk mitigator to protect removable media.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Many enterprises are early adopters so if you’re thinking about starting a dogfooding process in your own organization, here’s a couple of things to consider.&amp;nbsp; Rollouts to test drive new technologies can carry much of the same resource expenditure that deploying any product would have.&amp;nbsp; Therefore it may be prudent to go into all deployments with a commitment to eventual production use; you can focus on a measured rollout that occurs at a non-disruptive pace.&amp;nbsp;&amp;nbsp; Additionally, having a vision in place is extremely valuable to guide the decision process of which technologies to deploy.&amp;nbsp; Against the backdrop of a vision, each technology can be assessed to determine if it moves the organization closer to reaching its vision and if the candidate technology strategic or not.&amp;nbsp; With that assessment, the organization may decide to be conservative with regards to how much financial commitment it makes in non-strategic technologies so that it doesn’t become entrenched and prohibit replacement when a strategic technology becomes available.&amp;nbsp; Regardless, once a decision is made to deploy, the deployment itself needs to be &lt;I&gt;well planned&lt;/I&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;To hear more details about this phase of our dogfooding process, watch our recent video, “&lt;/FONT&gt;&lt;A title="Dogfooding Security-Related Features" href="http://edge.technet.com/Media/Dogfooding-Security-Related-Features/" target=_blank&gt;&lt;FONT size=2 face="Segoe UI"&gt;Dogfooding Security-Related Features&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;” where Yale Li, senior security architect, and I share some of our experiences.&amp;nbsp; Next time Steven Michalove will discuss how we influence products in the next phase of the dogfooding process...stay tuned.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.msinfosec.com/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Price Oden &lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt;Principal Senior Security Architect &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9913062" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/dogfooding/">dogfooding</category></item><item><title>Dogfooding: How Microsoft IT Information Security Dogfoods, Phase 1: Conduct a Security Design Review</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx</link><pubDate>Mon, 19 Oct 2009 20:31:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9909406</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9909406</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/10/19/dogfooding-how-microsoft-it-information-security-dogfoods-phase-1-conduct-a-security-design-review.aspx#comments</comments><description>&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hi Don Nguyen here, I’m a senior security engineer with the Microsoft &lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security's&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; (InfoSec), &lt;/FONT&gt;ACE&lt;FONT size=2 face="Segoe UI"&gt; Team.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Continuing with our blog series on dogfooding, today I will be talking about &lt;I&gt;phase 1: conduct a security design review&lt;/I&gt;, of our formal dogfooding process called, the First &amp;amp; Best program. In case you missed it, read Mark Smith’s recent blog &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx" mce_href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx"&gt;&lt;FONT size=2 face="Segoe UI"&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; where he provides an overview of our dogfooding process.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;In phase 1 of our dogfooding process, a security design review is conducted and it’s performed by our own assessment team, the &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/ace_team/" target=_blank mce_href="http://blogs.msdn.com/ace_team/"&gt;ACE team&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;FONT size=2 face="Segoe UI"&gt;. In a security design review we’re looking at additional features that might affect our policies. So basically a new feature can change our policy and if needed, we may need to modify the policy. From our review, any finding that may affect policy is communicated to our policy group. This helps ensure our internal policies are evolving along with our new technologies. For example, SQL 2005 provided a transparent data encryption to meet our internal security standard for sensitive data encryption. We assessed the encryption method and updated our policies to accept this method. The same can also be true the other way around, where we have a security policy and the product/feature may be suited at a consumer-level, but can’t be deployed in our enterprise environment per our security policies.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Also in this phase a risk assessment is performed. Anytime you add or change feature sets, the relative risk associated with the change needs to be reviewed and also existing risks will need to be assessed. Additionally with new products, new network risks can be introduced and we want to ensure these risks are identified and addressed. When we perform a risk assessment which enables the new features, this can increase risks to the network, however, this helps us determine security controls needed to mitigate a risk. Mitigation is provided to the product teams. After the assessment is completed, we provide feedback to the product teams from the context of an enterprise environment and how Microsoft IT will deploy a product, usually the enterprise features specifically.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;In the&amp;nbsp;end, success in the dogfooding program is really, seeing the overall successes over time, seeing products evolve and become more secure. Getting the opportunity to make a product more secure, working with the product teams and making a product more “enterprise-ready” is really &lt;I&gt;key&lt;/I&gt;. If you’re interested in starting a dogfooding program in your own organization, here are some things you can consider: &lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT size=2 face="Segoe UI"&gt;Determine if your organization wants to run beta software in a production environment. Make sure the beta software has feature/updates that your organization can utilize. Don’t try to beta test everything, only things that you actually expect to use as an enterprise. We test everything, but that’s our core business.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size=2 face="Segoe UI"&gt;Identify what you want to dogfood and create a dogfood plan with a start and end date per beta product/project.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size=2 face="Segoe UI"&gt;Establish a deliverable, basically a migration roadmap from when a product is beta to RTM (release to market).&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Check out my recent &lt;A title="Dogfooding: Evaluating Risk" href="http://edge.technet.com/Media/Dogfooding-Evaluating-Risk/" target=_blank mce_href="http://edge.technet.com/Media/Dogfooding-Evaluating-Risk/ "&gt;video&lt;/A&gt; where I talk more about this phase. Next time we will discuss the next phase of our dogfooding process, stay tuned…&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Don Nguyen&lt;BR&gt;Senior Security Engineer&lt;BR&gt;Microsoft &lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com/"&gt;Information Security&lt;/A&gt;, ACE Team&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9909406" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/dogfooding/">dogfooding</category></item><item><title>Risk Management in Risk Tracker</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/10/15/risk-management-in-risk-tracker.aspx</link><pubDate>Thu, 15 Oct 2009 21:19:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9907853</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9907853</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/10/15/risk-management-in-risk-tracker.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Hey there, my name is Sarah Pickard and I am a Senior Program Manager on the Microsoft Information Security Risk Management team.&amp;nbsp; You have seen some &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/securitytools/archive/2009/09/29/risk-tracker-v1-0-release.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;blogs by Vineet Batta&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; on the external release of Risk Tracker which is an application Information Security uses to - - well, track risk.&amp;nbsp;&amp;nbsp; To find out more information about Risk Tracker and how my teams uses it, please see the posted &lt;/FONT&gt;&lt;A href="http://edge.technet.com/Media/How-Microsoft-Uses-Risk-Tracker-to-Reduce-Risk/"&gt;&lt;FONT size=3 face=Calibri&gt;videos&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;In upcoming blogs I will give more information about how we have entered and structured risk data in Risk Tracker, how we have started tracking risk mitigating projects in Risk Tracker, and how ultimately we expect that Risk Tracker will help Information Security address the most risk with the least amount of resources.&amp;nbsp; As we all know, more with less is the name of the game. Feel free to contact me (&lt;/FONT&gt;&lt;A href="mailto:spickard@microsoft.com"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;spickard@microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;) with questions.&amp;nbsp; I look forward to chatting with you all.&amp;nbsp; Sarah&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9907853" width="1" height="1"&gt;</description></item><item><title>Dogfooding: How Microsoft IT's Information Security Dogfoods</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/10/08/dogfooding.aspx</link><pubDate>Fri, 09 Oct 2009 02:51:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9905201</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9905201</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/10/08/dogfooding.aspx#comments</comments><description>&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Hello Diane here.&amp;nbsp; Do you ever wonder how Microsoft’s IT &lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security&lt;/A&gt; (InfoSec) is involved in the dogfooding process?&amp;nbsp; This week we’re kicking off our blog series on dogfooding.&amp;nbsp; It's a formal program&amp;nbsp;in Microsoft IT known as the&amp;nbsp;First &amp;amp; Best prgram.&amp;nbsp; Recently Mark Smith, senior program manager on Microsoft’s InfoSec group, in his &lt;A title="Dogfooding: How Microsoft IT Information Security Dogfoods" href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx" target=_blank mce_href="http://blogs.msdn.com/infosec/archive/2009/10/08/dogfooding-how-microsoft-information-security-dogfoods.aspx"&gt;blog&lt;/A&gt; provides an overview of the First &amp;amp; Best program, along with his &lt;A title="Microsoft Information Security &amp;amp; Dogfooding" href="http://edge.technet.com/Media/Microsoft-Information-Security--Dogfooding/" target=_blank mce_href="http://edge.technet.com/Media/Microsoft-Information-Security--Dogfooding/"&gt;video&lt;/A&gt;.&amp;nbsp; In the next coming weeks, you’ll get a glimpse into our process&amp;nbsp; as we walk through the phases.&amp;nbsp;&amp;nbsp; Stay tuned.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Diane Talvo &lt;BR&gt;Security Awareness Program Manager &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9905201" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/dogfooding/">dogfooding</category></item><item><title>How to Integrate Risk Tracker with Internal HR Feeds</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/09/30/how-to-integrate-risk-tracker-with-internal-hr-feeds.aspx</link><pubDate>Thu, 01 Oct 2009 01:36:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9901557</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9901557</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/09/30/how-to-integrate-risk-tracker-with-internal-hr-feeds.aspx#comments</comments><description>&lt;p&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt;Organizations who would like to deploy the &lt;/span&gt;&lt;a href="http://edge.technet.com/Media/Risk-Tracker/"&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt;Risk Tracker v1.0&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt; application in their own environment, Vineet Batta, senior software developer on Microsoft&amp;rsquo;s IST team, shares how in his blog, &amp;ldquo;&lt;/span&gt;&lt;a target="_blank" href="http://blogs.msdn.com/securitytools/archive/2009/09/30/how-to-integrate-risk-tracker-with-internal-hr-feeds.aspx" title="How to Integrate Risk Tracker with Internal HR Feeds"&gt;How to Integrate Risk Tracker with Internal HR Feeds&lt;/a&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt;&lt;/span&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt;.&amp;rdquo;&amp;nbsp; Additionally, to get an an overview of this application and&amp;nbsp;the key features, also read Vineet&amp;rsquo;s blog, &amp;ldquo;&lt;/span&gt;&lt;a target="_blank" href="http://blogs.msdn.com/securitytools/archive/2009/09/29/risk-tracker-v1-0-release.aspx" title="Risk Tracker v1.0 Release"&gt;Risk Tracker v1.0 Release&lt;/a&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt;&lt;/span&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt;.&amp;rdquo;&amp;nbsp; Visit the &lt;/span&gt;&lt;a target="_blank" href="http://blogs.msdn.com/securitytools/default.aspx" title="Information Security Tools Blog"&gt;Information Security Tools Blog&lt;/a&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt;&lt;/span&gt; for more information on security tools.&lt;/p&gt;
&lt;p&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt;-Diane Talvo &lt;br /&gt;Security Awareness Program Manager &lt;br /&gt;&lt;/span&gt;&lt;a target="_blank" href="http://www.msinfosec.com/" title="Microsoft Information Security"&gt;Microsoft Information Security&lt;/a&gt;&lt;span style="font-family: Segoe UI; font-size: x-small;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9901557" width="1" height="1"&gt;</description></item><item><title>Risk Tracker v1.0 Release</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/09/29/risk-tracker-v1-0-release.aspx</link><pubDate>Tue, 29 Sep 2009 23:46:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9900988</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9900988</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/09/29/risk-tracker-v1-0-release.aspx#comments</comments><description>&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;The Microsoft &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/securitytools/default.aspx" mce_href="http://blogs.msdn.com/securitytools/default.aspx"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Information Security Tools (IST) team&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; releases Risk Tracker version 1.0 application.&amp;nbsp; Risk Tracker built on CISF (&lt;A title="Announcing the Connected Information Security Framework (CISF) and Risk Tracker" href="http://blogs.msdn.com/infosec/archive/2009/09/15/announcing-the-connected-information-security-framework-cisf-and-risk-tracker.aspx" target=_blank mce_href="http://blogs.msdn.com/infosec/archive/2009/09/15/announcing-the-connected-information-security-framework-cisf-and-risk-tracker.aspx"&gt;Connected Information Security Framework&lt;/A&gt;)&amp;nbsp;framework will help organizations manage, track and report on risks.&amp;nbsp; Vineet Batta, Senior Software Developer from Microsoft’s IST team, in his recent blog, “&lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=11945&amp;amp;postid=9900897" mce_href="http://blogs.msdn.com/controlpanel/blogs/posteditor.aspx?SelectedNavItem=Posts&amp;amp;sectionid=11945&amp;amp;postid=9900897"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Risk Tracker v1.0 Release&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;” provides an overview of the features supported by this release (CTP).&amp;nbsp; If you haven’t seen it, watch the video “&lt;/FONT&gt;&lt;A href="http://edge.technet.com/Media/Risk-Tracker/" mce_href="http://edge.technet.com/Media/Risk-Tracker/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Risk Tracker: Reducing Risks at Microsoft&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;,” as Sarah Pickard, Senior Security Program Manager from Microsoft Information Security team and Mark Curphey, Product Unit Manager from Microsoft Information Security Tools (IST) team discuss how the business will use Risk Tracker and how it will help manage risk.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;Read more about this application and other security tools on the &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/securitytools/default.aspx" mce_href="http://blogs.msdn.com/securitytools/default.aspx"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Information Security Tools Blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Diane Talvo &lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=2&gt;&lt;FONT face="Segoe UI"&gt;Security Awareness Program Manager &lt;BR&gt;&lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com/"&gt;&lt;FONT face="Segoe UI"&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9900988" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Risk+Tracker/">Risk Tracker</category></item><item><title>Create a Response Time Graph</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/09/27/create-a-response-time-graph.aspx</link><pubDate>Mon, 28 Sep 2009 06:30:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9900116</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9900116</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/09/27/create-a-response-time-graph.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Spending my last 4 years helping Microsoft’s enterprise customers improve their line of business application performance, I have interacted with many project managers, business analysts as well as executive officers.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Given the non-technical nature of their roles, the first thing that comes into their mind on the subject of application performance is, “How does my application perform under a certain workload?”&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The old saying “A Picture Is Worth A Thousand Words” can certainly be seen on a Response Time Graph. Below you will find a real-world sample I recently put together for a customer while working on their company portal. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;There are 2 things that are worthwhile to highlight here:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Somewhere between 420 to 450 concurrent users, the average homepage response time exceeded 3 seconds which is the company’s defined performance SLA upper limit.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Using data available from the graph, the homepage response times between 50 to 500 concurrent users are predictable.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This answered the project manager’s inquiry on “how does my application perform under X users”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;&lt;?xml:namespace prefix = v ns = "urn:schemas-microsoft-com:vml" /&gt;&lt;v:shapetype id=_x0000_t75 coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt;&lt;v:formulas&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt;&lt;/v:shapetype&gt;&lt;v:shape style="WIDTH: 390.75pt; HEIGHT: 219pt; VISIBILITY: visible" id=Chart_x0020_2 type="#_x0000_t75" o:gfxdata="UEsDBBQABgAIAAAAIQCDte0/HAEAAC4DAAATAAAAW0NvbnRlbnRfVHlwZXNdLnhtbKxSy07DMBC8&amp;#13;&amp;#10;I/EPlq8ocdoDQqhJDzyOwKF8wGJvEquObdluaf+ezevCIQjoxU/tzOzsbLanzrAjhqidLfkqLzhD&amp;#13;&amp;#10;K53Stin5++45u+MsJrAKjLNY8jNGvq2urza7s8fIqNrGkrcp+Xshomyxg5g7j5Z+ahc6SHQNjfAg&amp;#13;&amp;#10;99CgWBfFrZDOJrQpSz0GrzavJCBohewNQnqBjniENNp/OAhKyJZe47itcsLl7GEE6DWUHLw3WkKi&amp;#13;&amp;#10;DsTRqm/smatrLVE5eeiIM1cBPqm5zuQD7k2PJ36SMBVFMR3Wl5YRWyArZjGPWMPBJPZ0IpvGyQQ0&amp;#13;&amp;#10;8Xd9T47nVDl4E1vtlxiWjf2TTReb1mzMclASpQ/FsP6feYCZecWQ9uoLAAD//wMAUEsDBBQABgAI&amp;#13;&amp;#10;AAAAIQCtMD/xwQAAADIBAAALAAAAX3JlbHMvLnJlbHOEj80KwjAQhO+C7xD2btN6EJGmvYjgVfQB&amp;#13;&amp;#10;1mTbBtskZOPf25uLoCB4m2XYb2bq9jGN4kaRrXcKqqIEQU57Y12v4HTcLdYgOKEzOHpHCp7E0Dbz&amp;#13;&amp;#10;WX2gEVN+4sEGFpniWMGQUthIyXqgCbnwgVx2Oh8nTPmMvQyoL9iTXJblSsZPBjRfTLE3CuLeVCCO&amp;#13;&amp;#10;z5CT/7N911lNW6+vE7n0I0KaiPe8LCMx9pQU6NGGs8do3ha/RVXk5iCbWn4tbV4AAAD//wMAUEsD&amp;#13;&amp;#10;BBQABgAIAAAAIQB27EByXQIAAMkIAAAfAAAAY2xpcGJvYXJkL2RyYXdpbmdzL2RyYXdpbmcyLnht&amp;#13;&amp;#10;bORWy46bMBT9Fcv7Dg4MTwWkdip1U02j0pm9Y8wEFWxkOwmZr+81Jp0hqfpIFpXaDYbLfXHuuUcs&amp;#13;&amp;#10;WbbVXJUb2nONhq4VOmM53hjTZ56n2YZ3VN/Ingt4V0vVUQOP6smrFN034qlrPZ+QyGMbqgwulqxS&amp;#13;&amp;#10;meJt2Tzzt4JtpDrmrNSlWd+7SlPyWsnOlRkKcuNHfuwvPVt1cNYDWJOUkIWzHgp3voQZ+RKekCQ9&amp;#13;&amp;#10;D09DP51HH2N0jzrKlMwxRoYPpm3EV7h3CcWu7FfK3bP73Uqhpsqxj5GgHc/xF/B/Jwe0wN53HxuA&amp;#13;&amp;#10;zADmHI/28UteJ9JjSpoNteomKOkFQHa0EdAmzWRdI1ssCAC5BKMDdBgEaRzEti2aQZOIgYMfx8ki&amp;#13;&amp;#10;Jhgx8FhEIfhYB891Yj17pc0HLq/uCtlEOVacWf7QjO4+auNKHUtMM3RY2FlbyCoYLc3WcAKGjrgX&amp;#13;&amp;#10;I4N2XJlPcKlbuc8xa5seo72ifY6FFBwjZdo72eaYOJRabUpzaPm1dUfI+2uzWByAd3ABJFoqnnLM&amp;#13;&amp;#10;xZuHEiP9DMMjIYxxPRGMZqa433ZrruwszThRF/s7CdCaag6kBzpPSJgCyRqVTbdtqeEVupOCbZXi&amp;#13;&amp;#10;wqAH0BV9UoWLakUV/fzrRqG7fpr7cdrjcuijdaYybqNmpglVoMsF+zLK2U+E50xyAj+Morlo/Fhy&amp;#13;&amp;#10;SJxE4Vl4GPmT8ShYV0hOcCo5/l+THFTDKj1a7ll6TeIDdARRSW/9NA7nqnNLyMhWKzpREsbpfyc6&amp;#13;&amp;#10;VohgfekjnP+OBC3IiQSVnElRzdXhTzfee/3rUnwDAAD//wMAUEsDBBQABgAIAAAAIQDscOzoeQEA&amp;#13;&amp;#10;ABkEAAAfAAAAY2xpcGJvYXJkL2RyYXdpbmdzL2RyYXdpbmcxLnhtbKRTy07DMBC8I/EPlu80bYka&amp;#13;&amp;#10;iJr20FLEBSoBH7BynIdI7Mh2Q/r3rBNLMQUJ1F4se+2dndlZL9ddXZGWK11KkdDZZEoJF0ympcgT&amp;#13;&amp;#10;+v62u7mjRBsQKVRS8IQeuabr1fXVEuJcQVOUjCCC0DEktDCmiYNAs4LXoCey4QLvMqlqMHhUeZAq&amp;#13;&amp;#10;+ETkugrm0+kiqKEUdDVCbcEAOajyDKhKsg+ebkC0oBGyYrEfcRwrdjkyxKJ9VM1rs1eWOXtu94qU&amp;#13;&amp;#10;aUKxcwJqbBEN3IV7hsfgJCsfAbpM1fa9zDLS9ShHu/YYvDOEYTC8D2/DKKSE4d08imZRtHBVipdf&amp;#13;&amp;#10;8ljx8EcmEhoK48Yj4yzdKRRiSVmpvcl95FQxEhoUbwpQhsw94X7SqN+PWnhXztteMAHMkkDrWdzv&amp;#13;&amp;#10;nOXnOD4gOQD1n5FB80rGt5Idai7MMNyKV2DwV+mibDQlKrZDop7SmW1T3/a+HVaxf7bNuGQmvjs7&amp;#13;&amp;#10;dhxrnHwKv+oPFl8AAAD//wMAUEsDBBQABgAIAAAAIQA9pzEfGgEAAAUCAAAmAAAAY2xpcGJvYXJk&amp;#13;&amp;#10;L2NoYXJ0cy9fcmVscy9jaGFydDEueG1sLnJlbHOskT1rwzAQhvdC/4MQdKxleyglxM6SDzKEhtQZ&amp;#13;&amp;#10;Cl6u0vmjlSWhU1vn31cphDYQyNJN70n33PueprNx0OwTPfXWFDxLUs7QSKt60xZ8Xy3vHzmjAEaB&amp;#13;&amp;#10;tgYLfkDis/L2ZrpDDSE2Udc7YpFiqOBdCG4iBMkOB6DEOjTxprF+gBClb4UD+Q4tijxNH4T/y+Dl&amp;#13;&amp;#10;GZOtVcH9WuWcVQcXJ19n26bpJc6t/BjQhAsjhOzAhz2hf+7AxSSsAt9iKHiSCOXhK6am0yFPonUu&amp;#13;&amp;#10;LrvK/tOV1fj0+oYy/Pppeo1xkWI+qZcvWXqXp1tvj0+o3lS7KBfr7bFofQBdr6xWUVVIoV55cF0y&amp;#13;&amp;#10;ahpPtI1VcX2LMaA38JNInH1e+Q0AAP//AwBQSwMEFAAGAAgAAAAhAOFRNx/PBgAA5hsAABoAAABj&amp;#13;&amp;#10;bGlwYm9hcmQvdGhlbWUvdGhlbWUxLnhtbOxZzW/cRBS/I/E/jHxvs9/NRt1U2c1uA23aKNkW9Thr&amp;#13;&amp;#10;z9rTjD3WzGzSvaH2iISEKIgDlbhxQEClVuJS/ppAERSp/wJvZmyvJ+uQtI2gguaQtZ9/877fm6/L&amp;#13;&amp;#10;V+7FDB0QISlPel79Ys1DJPF5QJOw590ajy6sekgqnASY8YT0vDmR3pX199+7jNd8RtMJxyIYRyQm&amp;#13;&amp;#10;CBglcg33vEipdG1lRfpAxvIiT0kC36ZcxFjBqwhXAoEPQUDMVhq1WmclxjTx1oGj0oyGDP4lSmqC&amp;#13;&amp;#10;z8SeZkNQgmOQfnM6pT4x2GC/rhFyLgdMoAPMeh7wDPjhmNxTHmJYKvjQ82rmz1tZv7yC17JBTJ0w&amp;#13;&amp;#10;tjRuZP6ycdmAYL9hZIpwUgitj1rdS5sFfwNgahk3HA4Hw3rBzwCw74OlVpcyz9Zotd7PeZZA9nGZ&amp;#13;&amp;#10;96DWrrVcfIl/c0nnbr/fb3czXSxTA7KPrSX8aq3T2mg4eAOy+PYSvtXfGAw6Dt6ALL6zhB9d6nZa&amp;#13;&amp;#10;Lt6AIkaT/SW0DuholHEvIFPOtirhqwBfrWXwBQqyocguLWLKE3VSrsX4LhcjAGggw4omSM1TMsU+&amp;#13;&amp;#10;5OQAxxNBsRaA1wgufbEkXy6RtCwkfUFT1fM+THHilSAvn33/8tkTdHT/6dH9n44ePDi6/6Nl5Iza&amp;#13;&amp;#10;wklYHvXi28/+fPQx+uPJNy8eflGNl2X8rz988svPn1cDoXwW5j3/8vFvTx8//+rT3797WAHfEHhS&amp;#13;&amp;#10;ho9pTCS6QQ7RLo/BMOMVV3MyEa82YhxhWh6xkYQSJ1hLqeA/VJGDvjHHLIuOo0efuB68LaB9VAGv&amp;#13;&amp;#10;zu46Cu9FYqZoheRrUewAtzlnfS4qvXBNyyq5eTxLwmrhYlbG7WJ8UCV7gBMnvsNZCn0zT0vH8EFE&amp;#13;&amp;#10;HDV3GE4UDklCFNLf+D4hFdbdodTx6zb1BZd8qtAdivqYVrpkTCdONi0GbdEY4jKvshni7fhm+zbq&amp;#13;&amp;#10;c1Zl9SY5cJFQFZhVKD8mzHHjVTxTOK5iOcYxKzv8OlZRlZJ7c+GXcUOpINIhYRwNAyJl1ZibAuwt&amp;#13;&amp;#10;Bf0aho5VGfZtNo9dpFB0v4rndcx5GbnJ9wcRjtMq7B5NojL2A7kPKYrRDldV8G3uVoh+hzjg5MRw&amp;#13;&amp;#10;36bECffp3eAWDR2VFgmiv8yEjiW0aqcDxzT5u3bMKPRjmwPn146hAT7/+lFFZr2tjXgD5qSqStg6&amp;#13;&amp;#10;1n5Pwh1vugMuAvr299xNPEt2CKT58sTzruW+a7nef77lnlTPZ220i94KbVevG+yi2CyR4xNXyFPK&amp;#13;&amp;#10;2J6aM3JdmkWyhHkiGAFRjzM7QVLsmNIIHrO+7uBCgc0YJLj6iKpoL8IpLLDrnmYSyox1KFHKJWzs&amp;#13;&amp;#10;DLmSt8bDIl3ZbWFbbxhsP5BYbfPAkpuanO8LCjZmtgnN5jMX1NQMziqseSljCma/jrC6VurM0upG&amp;#13;&amp;#10;NdPqHGmFyRDDZdOAWHgTFiAIli3g5Q7sxbVo2JhgRgLtdzv35mExUTjPEMkIBySLkbZ7OUZ1E6Q8&amp;#13;&amp;#10;V8xJAORORYz0Ju8Ur5WkdTXbN5B2liCVxbVOEJdH702ilGfwIkq6bo+VI0vKxckSdNjzuu1G20M+&amp;#13;&amp;#10;TnveFPa08BinEHWp13yYhXAa5Cth0/7UYjZVvohmNzfMLYI6HFNYvy8Z7PSBVEi1iWVkU8N8ylKA&amp;#13;&amp;#10;JVqS1b/RBreelwE2019Di+YqJMO/pgX40Q0tmU6Jr8rBLlG07+xr1kr5TBGxFwWHaMJmYhdD+HWq&amp;#13;&amp;#10;gj0BlXA0YTqCfoFzNO1t88ltzlnRlU+vDM7SMUsjnLVbXaJ5JVu4qeNCB/NWUg9sq9TdGPfqppiS&amp;#13;&amp;#10;PydTymn8PzNFzydwUtAMdAR8OJQVGOl67XlcqIhDF0oj6o8ELBxM74BsgbNY+AxJBSfI5leQA/1r&amp;#13;&amp;#10;a87yMGUNGz61S0MkKMxHKhKE7EBbMtl3CrN6NndZlixjZDKqpK5MrdoTckDYWPfAjp7bPRRBqptu&amp;#13;&amp;#10;krUBgzuef+57VkGTUC9yyvXm9JBi7rU18E+vfGwxg1FuHzYLmtz/hYoVs6odb4bnc2/ZEP1hscxq&amp;#13;&amp;#10;5VUBwkpTQTcr+9dU4RWnWtuxlixutHPlIIrLFgOxWBClcN6D9D+Y/6jwmb1t0BPqmO9Cb0Vw0aCZ&amp;#13;&amp;#10;QdpAVl+wCw+kG6QlTmDhZIk2mTQr69ps6aS9lk/W57zSLeQec7bW7CzxfkVnF4szV5xTi+fp7MzD&amp;#13;&amp;#10;jq8t7URXQ2SPlyiQpvlGxgSm6tZpG6doEtZ7Htz8QKDvwRPcHXlAa2haQ9PgCS6EYLFkb3F6XvaQ&amp;#13;&amp;#10;U+C7pRSYZk5p5phWTmnllHZOgcVZdl+SUzrQqfQVB1yx6R8P5bcZsILLbj/ypupcza3/BQAA//8D&amp;#13;&amp;#10;AFBLAwQUAAYACAAAACEAbaHXWlsEAAAgDAAAGwAAAGNsaXBib2FyZC9jaGFydHMvY2hhcnQxLnht&amp;#13;&amp;#10;bJxWTW/jNhC9F+h/UIUc2sPakixLshF74WSx2wUS1IiTPfTGSGNbDUUKFB3b/77DL1n2Vltjc3Co&amp;#13;&amp;#10;meHjzJvhcG4/HirqvYNoSs5mfjgIfA9YzouSbWb+y/PnD5nvNZKwglDOYOYfofE/zn/95Taf5lsi&amp;#13;&amp;#10;5KomOXgIwpppPvO3UtbT4bDJt1CRZsBrYKhbc1ERiZ9iMywE2SN4RYdRECRDDeJbAPITABUpmdsv&amp;#13;&amp;#10;rtnP1+syh08831XApPFCACUSGWi2Zd34cwyuIBLCSRB774QiL/5QCSlhGyMA9uFlZYQ6AqWVpaSg&amp;#13;&amp;#10;Fwf1K8p8O78l01deHJcC95MpbeRKHinoj1pJ6qVQ/wpYP2mbYSvScrEUnjp05rcHkqmcL7mQhHp/&amp;#13;&amp;#10;8gpqsgFvlRNKXktayuMtIsi5+kUAhYa/zhdcSO0aJUe+k+iFkjiva8rlQgAxgSoDtaoI2xH6oDec&amp;#13;&amp;#10;NM9EbEAaKkrGQBgqDo+8AEtQsQEjPP6X8GCsgkEYplEwjrM4DSeTbBTGdlOrT5MgHadpPBlPoiTN&amp;#13;&amp;#10;IqPfO30WZ9koSJI4nIzjNJtY/dbpkyiJoiQL02wcjaIwVdsx6vOwUGAoURE2OZESxL2q7s63TpxB&amp;#13;&amp;#10;bSrO5faRiDcXeAPIdj4tCxeX8ZKLAoT1xEgM/40UT7BWO9bz1RZAhr/d3N2EyjEtRf09wSukLGp5&amp;#13;&amp;#10;z3fMcm3rsJYeHjXzA19ZvM8XeIFVHTxBU2MRg/dcVuD93kDOWdH8oXDfddi1Kg0MscU3H9oZXBrv&amp;#13;&amp;#10;iodX2ihgeTDVeX0Fe6/2rpzqGFixJIJgeV9Wclud5hx0a8v337CuT1cOfWq9OaBKecV21XfkLW6i&amp;#13;&amp;#10;6c3iJjxRiFYthab93GNtzr8AFiuhmmndlLT0O5oDk61LnsfBOZUqOyYToc1EGPSaRM6kH2VkTbAz&amp;#13;&amp;#10;9h0UO5N+lLE1GfWjJM6kHyW1JnHU60vmTPpRJtZkfOkLZvaUIvPhqtAl+viDhN+phOOV+d+EBwPt&amp;#13;&amp;#10;fqcErk121JcCl+teA5fpaKDdO129U720mR5grrt/vaBt4gfR5Owv6/PT1UF09Q5XFtEg7gN1ZREN&amp;#13;&amp;#10;kj4TVxajQdpn4soiHgRnsUwuQH9QJa46TDM+7xm2HZPD18IoxgE+H1lqH4czeRLGQWZfhcvWj41o&amp;#13;&amp;#10;oR/Msx0dJNxAcZhRbYmLEscJPUWYM6uSPZKDaSQVsQ8D3oPTWW4rOSx5Yza9Gnu8Gp8r6Z2qdubb&amp;#13;&amp;#10;zoXTGN+JHB5K9gZFO5nIMn/Dtt3iUL43SLngTbNoT5+04eL8plRgDyY7yf8GwTu77kDuAZiLprgn&amp;#13;&amp;#10;0mgr8g8XL6y0j9LYhdTS1S7OeOscfR1vmP2OYYcl2vHjiygLJBIafNh1T7kkDjvAlaQxOMjnLgMd&amp;#13;&amp;#10;3jpJ/0neMBrLC67Ohi3Y4COpvKd61SbR0t2d1oyFslUI38rmL0aPJkN6NkDodh7FaEAwQj8RSTyB&amp;#13;&amp;#10;w8nMF18LO0Ls8I6stqTG/LcqfT0cgh7s5/8CAAD//wMAUEsDBBQABgAIAAAAIQBnA+6GzgAAAKwB&amp;#13;&amp;#10;AAAqAAAAY2xpcGJvYXJkL2RyYXdpbmdzL19yZWxzL2RyYXdpbmcxLnhtbC5yZWxzrJDNasMwDIDv&amp;#13;&amp;#10;g72D0X1W0sMYo04vpdDr6B5AOMoPTWxjqWV9+5kWxgKFXnqRkIQ+fWi9+Zknc+YsYwwOaluB4eBj&amp;#13;&amp;#10;O4bewfdh9/YBRpRCS1MM7ODCApvm9WX9xRNpWZJhTGIKJYiDQTV9IoofeCaxMXEoky7mmbSUucdE&amp;#13;&amp;#10;/kg946qq3jH/Z0CzYJp96yDv2xWYwyWVy4/ZsetGz9voTzMHvXMCtXhxAVLuWR1Ye+vcYm2LK+B9&amp;#13;&amp;#10;jfqZGn6grAuNa0fwmv48cPHj5hcAAP//AwBQSwECLQAUAAYACAAAACEAg7XtPxwBAAAuAwAAEwAA&amp;#13;&amp;#10;AAAAAAAAAAAAAAAAAAAAW0NvbnRlbnRfVHlwZXNdLnhtbFBLAQItABQABgAIAAAAIQCtMD/xwQAA&amp;#13;&amp;#10;ADIBAAALAAAAAAAAAAAAAAAAAE0BAABfcmVscy8ucmVsc1BLAQItABQABgAIAAAAIQB27EByXQIA&amp;#13;&amp;#10;AMkIAAAfAAAAAAAAAAAAAAAAADcCAABjbGlwYm9hcmQvZHJhd2luZ3MvZHJhd2luZzIueG1sUEsB&amp;#13;&amp;#10;Ai0AFAAGAAgAAAAhAOxw7Oh5AQAAGQQAAB8AAAAAAAAAAAAAAAAA0QQAAGNsaXBib2FyZC9kcmF3&amp;#13;&amp;#10;aW5ncy9kcmF3aW5nMS54bWxQSwECLQAUAAYACAAAACEAPacxHxoBAAAFAgAAJgAAAAAAAAAAAAAA&amp;#13;&amp;#10;AACHBgAAY2xpcGJvYXJkL2NoYXJ0cy9fcmVscy9jaGFydDEueG1sLnJlbHNQSwECLQAUAAYACAAA&amp;#13;&amp;#10;ACEA4VE3H88GAADmGwAAGgAAAAAAAAAAAAAAAADlBwAAY2xpcGJvYXJkL3RoZW1lL3RoZW1lMS54&amp;#13;&amp;#10;bWxQSwECLQAUAAYACAAAACEAbaHXWlsEAAAgDAAAGwAAAAAAAAAAAAAAAADsDgAAY2xpcGJvYXJk&amp;#13;&amp;#10;L2NoYXJ0cy9jaGFydDEueG1sUEsBAi0AFAAGAAgAAAAhAGcD7obOAAAArAEAACoAAAAAAAAAAAAA&amp;#13;&amp;#10;AAAAgBMAAGNsaXBib2FyZC9kcmF3aW5ncy9fcmVscy9kcmF3aW5nMS54bWwucmVsc1BLBQYAAAAA&amp;#13;&amp;#10;CAAIAFECAACWFAAAAAA=&amp;#13;&amp;#10;" o:spid="_x0000_i1025"&gt;&lt;v:imagedata mce_src="file:///C:\Users\eddiel\AppData\Local\Temp\msohtmlclip1\01\clip_image001.png" o:title="" src="file:///C:\Users\eddiel\AppData\Local\Temp\msohtmlclip1\01\clip_image001.png"&gt;&lt;/v:imagedata&gt;&lt;o:lock v:ext="edit" aspectratio="f"&gt;&lt;/o:lock&gt;&lt;/v:shape&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;IMG style="WIDTH: 526px; HEIGHT: 298px" title="Response Time Graph" alt="Response Time Graph" align=middle src="http://lgn4pg.blu.livefilestore.com/y1pe-Ip7eWxbCyjusySxw2j5g7cJqcI2PJfHkrXbr8JfUk4Txg-Zp456hWPijX0v0BrUQAxngKorQEg25x0kM2ZVWSRnez5h7Xo/Response%20Time%20Graph.PNG" width=526 height=298 mce_src="http://lgn4pg.blu.livefilestore.com/y1pe-Ip7eWxbCyjusySxw2j5g7cJqcI2PJfHkrXbr8JfUk4Txg-Zp456hWPijX0v0BrUQAxngKorQEg25x0kM2ZVWSRnez5h7Xo/Response%20Time%20Graph.PNG"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;To create a meaningful Response Time Graph, it does not require the purchase of expensive tools or running a dozen application load tests.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;At a minimum you will need:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Visual Studio 2008 Team Test Edition or Team Suite (90-day trial available for download &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d95598d7-aa6e-4f24-82e3-81570c5384cb&amp;amp;DisplayLang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d95598d7-aa6e-4f24-82e3-81570c5384cb&amp;amp;DisplayLang=en"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Log Parser 2.2 (free download available &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=890cd06b-abf8-4c25-91b2-f8d975cf8c07&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?FamilyID=890cd06b-abf8-4c25-91b2-f8d975cf8c07&amp;amp;displaylang=en"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;)&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;IIS (Internet Information Services) Log&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Office Excel&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The step-by-step instructions provided below do not cover the basics of using Visual Studio testing features such as creating a web test.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For more information, please look at a list of comprehensive &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/edglas/pages/content-index-for-web-tests-and-load-tests.aspx" mce_href="http://blogs.msdn.com/edglas/pages/content-index-for-web-tests-and-load-tests.aspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;resources&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; on the web available off Ed Glas's &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/edglas/default.aspx" mce_href="http://blogs.msdn.com/edglas/default.aspx"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;blog&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Also consider this 7-minute &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/jimmymay/archive/2009/02/23/vsts-web-test-step-by-step-primer-7-minute-video-by-microsoft-a-c-e-performance-engineer-chris-lundquist-with-copious-notes-screen-shots-from-your-humble-correspondent.aspx" mce_href="http://blogs.msdn.com/jimmymay/archive/2009/02/23/vsts-web-test-step-by-step-primer-7-minute-video-by-microsoft-a-c-e-performance-engineer-chris-lundquist-with-copious-notes-screen-shots-from-your-humble-correspondent.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;web test step-by-step primer&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; by A.C.E. Performance Engineer Chris Lundquist.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Enable the &lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;time-taken&lt;/I&gt;&lt;/B&gt; field in your target application’s Internet Information Services (IIS) log under IIS Manager.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Leave the default log format of &lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;W3C&lt;/I&gt;&lt;/B&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Create a new folder under the IIS Log directory (e.g., Test01) and assign it to store the log files. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Execute your load test with the &lt;U&gt;Step Load Pattern&lt;/U&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As illustrated in the table below, the test begins with 10 users, incrementing by 10 users every 20 seconds until 500 concurrent users are loaded.&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV align=center&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: auto auto auto 0.5in; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none; mso-border-alt: solid #4F81BD 1.0pt; mso-border-themecolor: accent1; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 5.4pt 0in 5.4pt" class=LightGrid-Accent11 border=1 cellSpacing=0 cellPadding=0 class="LightGrid-Accent11"&gt;
&lt;TBODY&gt;
&lt;TR style="mso-yfti-irow: -1; mso-yfti-firstrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 2.25pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4f81bd 1pt solid; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-bottom-themecolor: accent1" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 5" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Load Pattern&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 2.25pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #4f81bd 1pt solid; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1" vAlign=top width=49&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 1" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Step&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 0"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Initial User Count&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 64" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;10&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 1"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Maximum User Count&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 128" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;500&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 2"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Step Duration (seconds)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 64" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;20&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 3"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 132" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Step Ramp Time (seconds)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 128" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;0&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR style="mso-yfti-irow: 4; mso-yfti-lastrow: yes"&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #4f81bd 1pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 185.4pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=247&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 68" class=MsoNormal&gt;&lt;B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: 新細明體; mso-fareast-theme-font: major-fareast; mso-fareast-language: EN-US"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Step User Count&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: #4f81bd 1pt solid; BORDER-LEFT: #f0f0f0; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 36.75pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d3dfee; BORDER-TOP: #f0f0f0; BORDER-RIGHT: #4f81bd 1pt solid; PADDING-TOP: 0in; mso-border-bottom-themecolor: accent1; mso-border-top-themecolor: accent1; mso-border-right-themecolor: accent1; mso-border-left-alt: solid #4F81BD 1.0pt; mso-border-left-themecolor: accent1; mso-border-top-alt: solid #4F81BD 1.0pt; mso-background-themecolor: accent1; mso-background-themetint: 63" vAlign=top width=49&gt;
&lt;P style="TEXT-ALIGN: right; LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-yfti-cnfc: 64" class=MsoNormal align=right&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-fareast-language: EN-US"&gt;10&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Execute the test and record the start and end time (also available in the Load Test Summary report).&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;5)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Copy the IIS logs to a client workstation with LogParser and Excel installed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;6)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Open Excel and create a new spreadsheet with 3 columns: timestamp (A), # of concurrent users (B) and response time (C).&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;7)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Populate column A and B with information you &lt;U&gt;already know&lt;/U&gt; either manually or using an Excel formula. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;For example based on the load pattern defined above I know ~100 users were simulated on the system after approximately 3 minutes into the test.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Alternatively, extract data directly from the graphs (User Load) in Visual Studio.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;8)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Calculate the average response time of your test scenario (e.g. an ASPX page or a web service call) using LogParser:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=3 face=Calibri&gt;&lt;EM&gt;logparser "SELECT TO_LOCALTIME(QUANTIZE(TO_TIMESTAMP(date, time),60)), Avg(time-taken) AS AvgTime INTO C:\MyTemp\Homepage.csv from C:\Users\eddiel\Desktop\LogIn\ex*.log where (To_Lowercase(cs-uri-stem) like '%/s/app/default.aspx%') and sc-status = 200 and cs-method like 'GET' GROUP BY TO_LOCALTIME(QUANTIZE(TO_TIMESTAMP(date, time),60))" -i:IISW3C -o:CSV&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=3 face=Calibri&gt;The sample query above is used to calculate the average response time on GET requests to “/s/app/default.aspx” resulted in HTTP status 200, based on 60 seconds increment (quantize function).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In other words, I know precisely the average execution time of the portal’s homepage by the minute as user load increases.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;9)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Populate column C (response time) in the spreadsheet created earlier by matching the timestamp.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is fine when there are more LogParser output rows than what you have defined for column A. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;10)&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Create your Response Time Graph (Scatter with Smooth Line type) in Excel.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Add X and Y axis labels accordingly.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Completing step 1 to step 10 should take less than 30 minutes. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;The result is a meaningful Response Time Graph that is illustrating your application performance—a picture that’s worth a thousand words!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I invite your questions and comments.&amp;nbsp; By &lt;STRONG&gt;Eddie Lau&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9900116" width="1" height="1"&gt;</description><enclosure url="http://blogs.msdn.com/cfs-file.ashx/__key/communityserver-components-postattachments/00-09-90-01-16/Capture.PNG" length="14344" type="image/x-png" /><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Performance/">Performance</category><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Tools/">Tools</category></item><item><title>Anti-XSS Library v3.1 Released!</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/09/17/anti-xss-library-v3-1-released.aspx</link><pubDate>Thu, 17 Sep 2009 23:53:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9896502</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9896502</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/09/17/anti-xss-library-v3-1-released.aspx#comments</comments><description>&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;The Microsoft &lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/securitytools/" mce_href="http://blogs.msdn.com/securitytools/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Information Security Tools&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt; (IST) team has released the latest Microsoft &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?familyid=051EE83C-5CCF-48ED-8463-02F56A6BFC09&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?familyid=051EE83C-5CCF-48ED-8463-02F56A6BFC09&amp;amp;displaylang=en"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Anti-Cross Site Scripting (Anti-XSS) Library version 3.1&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=2 face="Segoe UI"&gt;.&amp;nbsp; Read more about Anti-XSS v3.1 on the &lt;A title="Information Security Blog" href="http://blogs.msdn.com/infosec/archive/2009/09/17/anti-xss-3-1-released.aspx" target=_blank mce_href="http://blogs.msdn.com/infosec/archive/2009/09/17/anti-xss-3-1-released.aspx"&gt;Information Security blog&lt;/A&gt; and watch the video, “&lt;A title="Anti-XSS 3.0 Released" href="http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/" target=_blank mce_href="http://channel9.msdn.com/posts/Jossie/Anti-XSS-30-Released/"&gt;Anti-XSS 3.0 Released&lt;/A&gt;,” as Vineet Batta and Anil Revuru (RV), Senior Software Developers from the Microsoft &lt;A title="Information Security Tools" href="http://blogs.msdn.com/securitytools/default.aspx" target=_blank mce_href="http://blogs.msdn.com/securitytools/default.aspx"&gt;Information Security Tools&lt;/A&gt; (IST), provide an overview of the Anti-XSS Library and how it can prevent XSS attacks in your application.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2 face="Segoe UI"&gt;-Diane Talvo &lt;BR&gt;Security Awareness Program Manager &lt;BR&gt;&lt;/FONT&gt;&lt;A href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;&lt;FONT size=2 face="Segoe UI"&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9896502" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Anti_2D00_XSS/">Anti-XSS</category></item><item><title>Introducing the Connected Information Security Framework (CISF) and Risk Tracker Version 1.0</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/09/16/introducing-the-connected-information-security-framework-cisf-and-risk-tracker-version-1-0.aspx</link><pubDate>Wed, 16 Sep 2009 21:34:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9895985</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9895985</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/09/16/introducing-the-connected-information-security-framework-cisf-and-risk-tracker-version-1-0.aspx#comments</comments><description>&lt;P align=justify&gt;&lt;FONT face=verdana,geneva&gt;The Microsoft Information Security Tools (IST) team has released the &lt;A title="CISF: Build Custom Security Solutions" href="http://edge.technet.com/Media/CISF-Connected-Information-Security-Framework/" target=_blank mce_href="http://edge.technet.com/Media/CISF-Connected-Information-Security-Framework/"&gt;Connected Information Security Framework (CISF)&lt;/A&gt;, a software development framework comprises of API’s and reusable components that is designed to ‘create bespoke or custom information security and risk management solutions.’ Additionally along with this release of CISF, the IST team is also releasing the first custom application using CISF called &lt;A title="Risk Tracker: Reducing Risks at Microsoft" href="http://edge.technet.com/Media/Risk-Tracker/" target=_blank mce_href="http://edge.technet.com/Media/Risk-Tracker/"&gt;Risk Tracker version 1.0&lt;/A&gt; that manages and tracks information security risk. Read more about CISF and the Risk Tracker application as Todd Kutzke, Senior Director from &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/security/dd547422.aspx" mce_href="http://msdn.microsoft.com/en-us/security/dd547422.aspx"&gt;&lt;FONT face=verdana,geneva&gt;Microsoft Information Security&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt;, provides an overview in his recent blog, “&lt;/FONT&gt;&lt;A href="http://blogs.msdn.com/infosec/archive/2009/09/15/announcing-the-connected-information-security-framework-cisf-and-risk-tracker.aspx" mce_href="http://blogs.msdn.com/infosec/archive/2009/09/15/announcing-the-connected-information-security-framework-cisf-and-risk-tracker.aspx"&gt;&lt;FONT face=verdana,geneva&gt;Announcing the Connected Information Security Framework (CISF) and Risk Tracker&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt;.”&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;-Diane Talvo&lt;BR&gt;Security Awareness Program Manager&lt;BR&gt;&lt;/FONT&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;&lt;FONT color=#0065e2&gt;&lt;FONT face=verdana,geneva&gt;Microsoft Information Security&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9895985" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/CISF/">CISF</category><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Risk+Tracker/">Risk Tracker</category></item><item><title>Blog Series: Get Familiar with the SDL-LOB Process. Introduction to Phase Five: Release for LOB</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/08/10/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-five-release-for-lob.aspx</link><pubDate>Tue, 11 Aug 2009 02:11:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9863622</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9863622</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/08/10/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-five-release-for-lob.aspx#comments</comments><description>&lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;Hello, Anmol here.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;As you’ve been following along with me in my blog series on &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;a title="SDL-LOB" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;Security Development Lifecycle for Line-of-Business applications (SDL-LOB)&lt;/a&gt;&lt;/span&gt; , I’ve talked about &lt;span style="line-height: 112%; font-family: &amp;#39;ver&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;a title="SDL-LOB Phase One: Requirements for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;Phase One&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;, &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;font color="#0000ff"&gt;&lt;a title="SDL-LOB Phase Two: Design for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx"&gt;Two&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;, &lt;span style="line-height: 112%; font-family: &amp;#39;Calibri&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 11pt; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin"&gt;&lt;font color="#0000ff"&gt;&lt;a title="SDL-LOB Phase Three: Implementation for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx"&gt;Three&lt;/a&gt;&lt;/font&gt;&lt;/span&gt; and &lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-font-size: 11.0pt"&gt;&lt;a title="SDL-LOB Phase Four: Verification for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx"&gt;Four&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Today, I’ll discuss the last phase - &lt;b style="mso-bidi-font-weight: normal"&gt;&lt;i style="mso-bidi-font-style: normal"&gt;Phase Five: Release for LOB&lt;/i&gt;&lt;/b&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;SDL-LOB defines standards and best practices for providing security and privacy for line-of-business (LOB) applications either in development or being planned for development.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;In the Release phase, now that the application is live in production, a &lt;i style="mso-bidi-font-style: normal"&gt;post-production assessment&lt;/i&gt; takes place. It is important to note that this is a continuous process and all applications/hosts/network devices are in scope.&lt;span style="line-height: 112%; font-family: &amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 8pt"&gt; &lt;/span&gt;This type of assessment performed by an operations team and involves verification of patch management, compliance, network and host scanning as well as responding to incremental releases for hotfixes and service packs. Typically the assessment occurs on a continuous regular cycle and integrates with an existing management process already in place established by the compliance group.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;font size="2" face="ver"&gt;Highlight for this phase include:&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Host-level security              &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;      &lt;ul&gt;       &lt;li&gt;         &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Patch Management                &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: &amp;#39;Segoe UI&amp;#39;; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2" face="ver"&gt;Appropriate configuration                &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="mso-bidi-font-family: &amp;#39;Segoe UI&amp;#39;; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Antivirus                &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Compliance                &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;       &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Review access control/permissions              &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;/b&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Server auditing and logging              &lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;strong&gt;Network level security&lt;/strong&gt;               &lt;br /&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="2" face="ver"&gt;Application retirement &lt;/font&gt;&lt;/span&gt;&lt;/b&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;         &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;       &lt;/b&gt;&lt;/div&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="mso-bookmark: _toc26865442"&gt;&lt;span style="mso-bookmark: _toc26845431"&gt;&lt;span style="mso-bookmark: _toc29787492"&gt;&lt;span style="mso-bookmark: _toc90435890"&gt;&lt;span style="mso-bookmark: _toc94327020"&gt;&lt;span style="mso-bookmark: _toc96833554"&gt;&lt;span style="mso-bookmark: _toc96838661"&gt;&lt;span style="mso-bookmark: _toc217797264"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;Under every task given above,&lt;/span&gt; there are several &lt;i style="mso-bidi-font-style: normal"&gt;security requirements&lt;/i&gt; that the application team follows. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Here’s the complete list of security requirements &lt;font color="#0000ff"&gt;&lt;a title="Security Requirements" href="http://msdn.microsoft.com/en-us/library/dd831974.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831974.aspx"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-font-size: 11.0pt"&gt;here&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/font&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Concluding my blog series I’ve talked about all 5 phases of SDL-LOB, providing you a brief highlight of each of the phases.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Take some time and review all phases of the &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;a title="SDL-LOB" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;&lt;font color="#0000ff"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-font-size: 11.0pt"&gt;SDL-LOB&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt; in detail.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="mso-bidi-font-family: &amp;#39;Segoe UI&amp;#39;; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;To wrap up, here’s the phases again:&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;p&gt;&lt;a title="Phase One: Requirements for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;&lt;font color="#0000ff" face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 115%; font-size: 10pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;Phase One: Requirements for LOB&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a title="Phase Two: Design for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx"&gt;&lt;font color="#0000ff" size="2" face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 115%; font-size: 9pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;Phase Two: Design for LOB&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a title="Phase Three: Implementation for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx"&gt;&lt;font color="#0000ff" size="2" face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 115%; font-size: 9pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;Phase Three: Implementation for LOB&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;a title="Phase Four: Verificatoin for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx"&gt;&lt;font size="2" face="ver"&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="line-height: 115%; font-size: 9pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;Phase Four: Verification for LOB&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;p&gt;&lt;span style="mso-bookmark: _toc21158575"&gt;&lt;span style="mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;"&gt;&lt;a title="Phase Five: Release for LOB" href="http://blogs.msdn.com/ace_team/archive/2009/08/10/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-five-release-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/08/10/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-five-release-for-lob.aspx"&gt;&lt;font size="2" face="ver"&gt;Phase Five:&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Release for LOB&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/li&gt; &lt;/ul&gt; &lt;span style="mso-bookmark: _toc21158575"&gt;&lt;/span&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font size="2"&gt;&lt;font face="ver"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;-Anmol Malhotra          &lt;br /&gt;Senior Security Engineer           &lt;br /&gt;ACE Team           &lt;br /&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size="2" face="ver"&gt;&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9863622" width="1" height="1"&gt;</description></item><item><title>Video Series: ACE Security Consultants from the Field</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/08/04/video-series-ace-security-consultants-from-the-field.aspx</link><pubDate>Tue, 04 Aug 2009 23:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9857433</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9857433</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/08/04/video-series-ace-security-consultants-from-the-field.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Kicking off our video series, ‘&lt;I style="mso-bidi-font-style: normal"&gt;ACE Security Consultants from the Field,&lt;/I&gt;’ Talhah Mir from &lt;/FONT&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Microsoft Information Security&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;, talks to&amp;nbsp;two passionate individuals about security.&lt;I style="mso-bidi-font-style: normal"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Watch the podcast, “&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A title="ACE From the Field: Carric 'DEFCON Goon' Dooley" href="http://edge.technet.com/Media/ACE-From-the-Field-Carric-Dooley/" target=_blank mce_href="http://edge.technet.com/Media/ACE-From-the-Field-Carric-Dooley/"&gt;ACE from the Field: Carric 'DEFCON Goon' Dooley&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;,” as Carric Dooley, Senior Security Consultant from Microsoft ACE Team, talks about his broad security experience including pen testing (on non-Microsoft platforms), the completeness of security and more. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Roger Grimes, Security Architect from Microsoft ACE Team in this video, “&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A title="ACE From the Field: Roger Grimes &amp;amp; Securing the Internet" href="http://edge.technet.com/Media/ACE-From-the-Field-Roger-Grimes--Securing-the-Internet/" target=_blank mce_href="http://edge.technet.com/Media/ACE-From-the-Field-Roger-Grimes--Securing-the-Internet/"&gt;ACE from the Field: Roger Grimes &amp;amp; Securing the Internet&lt;/A&gt;&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;,” discusses his lifelong passion for making the internet more secure.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;He shares his thoughts on how security has evolved, where it stands, how it can be fixed including how most&amp;nbsp;hacks can actually be avoided by the user. &lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Calibri&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;More videos coming up from&amp;nbsp;ACE security consultants in the field, stay tuned...&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;-Diane Talvo&lt;BR&gt;Security Awareness Program Manager&lt;BR&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Microsoft Information Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9857433" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Security/">Security</category></item><item><title>Blog Series: Get Familiar with the SDL-LOB Process. Introduction to Phase Four: Verification for LOB</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx</link><pubDate>Thu, 30 Jul 2009 00:43:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9852580</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9852580</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/07/29/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-4-verification-for-lob.aspx#comments</comments><description>&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;Hello, Anmol here…continuing our discussion of &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="Security Development Lifecycle for Line-of-Business applications (SDL-LOB)" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;Security Development Lifecycle for Line-of-Business applications (SDL-LOB)&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt; process, let’s discuss &lt;B style="mso-bidi-font-weight: normal"&gt;&lt;I style="mso-bidi-font-style: normal"&gt;Phase Four: Verification for LOB &lt;/I&gt;&lt;/B&gt;today.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The SDL-LOB defines the standards and best practices for providing security and privacy for new and existing line-of-business (LOB) applications currently under development or being planned for development.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If you missed prior phases, read them here: &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 1" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target=_blank&gt;Phase One&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;, &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 2" href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx" target=_blank&gt;Phase Two&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt; and &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 3" href="http://blogs.msdn.com/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx" target=_blank&gt;Phase Three&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;. 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/FONT&gt;&lt;/SPAN&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;Phase 4 is all about verifying different security claims made in earlier phases and identifying gaps in implementation. For example, during design review phase, let’s assume an application team identifies that the design is vulnerable to cross site scripting attacks and therefore adds security requirements such as &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-font-size: 11.0pt; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;FONT face=verdana,geneva&gt;&lt;A title="AntiXSS Library 3.0" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=051ee83c-5ccf-48ed-8463-02f56a6bfc09&amp;amp;displaylang=en" target=_blank&gt;AntiXSS library&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; to be incorporated during coding. During the verification phase, a security SME &lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt;(subject matter experts) &lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;will verify that all user controlled data which needed to be validated and encoded is actually *done*. If there are any gaps identified, they will be triggered as security bugs for the application teams to fix. 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;&lt;/FONT&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;Here are a few key tasks to be executed in this phase:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;Conduct pre-production assessment (white box/black box reviews, deployment reviews of servers &amp;amp; privacy reviews) &lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;Identify security issues and applying a severity rating. &lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;FONT face=verdana,geneva&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;Compliance: Tracking all risks identified. 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Before a line-of-business (LOB) application is deployed in production, the application must adhere to internal security policies, guidance and follow industry best practice. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;As mentioned above, in this phase expert application security SMEs are engaged.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;One way a SME verifies an application is by performing a &lt;I style="mso-bidi-font-style: normal"&gt;pre-production assessment&lt;/I&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;What’s a pre-production assessment?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It’s an assessment performed based on the service level assigned depending on the application’s risk rating.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Back in “&lt;/FONT&gt;&lt;I style="mso-bidi-font-style: normal"&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 1" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;Phase 1: Requirements for LOB&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT face=verdana,geneva&gt;&lt;I style="mso-bidi-font-style: normal"&gt;” &lt;/I&gt;a Risk Assessment was conducted which determines an application’s risk level.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Based on the risk level, a service level is then assigned.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Generally white box code review is conducted on applications that are medium or high risk rating.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;An ideal comprehensive assessment will be a combination of white and black box testing.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Having said this, performing the assessment with a mix of manual process automated tools can help save some time.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For code reviews (white box) testing, a SME will identify &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="Categories of Vulnerabilities" href="http://msdn.microsoft.com/en-us/library/ms998364.aspx#paght000027_step3" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/ms998364.aspx#paght000027_step3"&gt;categories of vulnerabilities&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; in the code.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Here are some vulnerabilities that are identified:&lt;SPAN class=BodyText2Char&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-SIZE: 10pt; mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;&lt;SPAN class=BodyText2Char&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-SIZE: 10pt; mso-fareast-font-family: calibri; mso-fareast-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT face=verdana,geneva&gt;SQL injection. Ensure that the SQL queries are parameterized (preferably within a stored procedure) and that any input used in a SQL query is validated.&amp;nbsp; &lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Cross-site scripting. Ensure that user controlled data is encoded properly before rendering to the browser.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;.NET applications can leverage Anti-XSS library for encoding data that is more rigorous than the native .NET encoding. &lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Cross-site request forgery. Ensure that the Page.ViewStateUserKey property is set to a unique value that prevents one-click attacks on your application from malicious users. &lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Data access. Look for improper storage of database connection strings and proper use of authentication to the database. &lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Input/data validation. Look for client-side validation that is not backed by server-side validation, poor validation techniques, and reliance on file names or other insecure mechanisms to make security decisions.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;See the complete list of vulnerabilities and learn more about &lt;A title="SDL-LOB Process: Phase 4 - Verification for LOB" href="http://msdn.microsoft.com/en-us/library/dd831973.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831973.aspx"&gt;verification &lt;/A&gt;&lt;/FONT&gt;&lt;FONT face=verdana,geneva&gt;&lt;A title="SDL-LOB Process: Phase 4 - Verification for LOB" href="http://msdn.microsoft.com/en-us/library/dd831973.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831973.aspx"&gt;in this Phase 4&lt;/A&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Watch the podcast called “&lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-font-size: 11.0pt; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri"&gt;&lt;FONT face=verdana,geneva&gt;&lt;A title="SDL-LOB Phase 3: Implementation" href="http://channel9.msdn.com/posts/Jossie/SDL-LOB-Phase-3-Implementation/" target=_blank&gt;SDL-LOB Phase Three: Implementation&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt;” where Eugene Siu, Senior Security Engineer of Microsoft &lt;A title="Microsoft ACE Team" href="http://blogs.msdn.com/ace_team/default.aspx" target=_blank mce_href="http://blogs.msdn.com/ace_team/default.aspx"&gt;ACE Team&lt;/A&gt;&lt;/FONT&gt;&lt;FONT face=verdana,geneva&gt;, provides an overview of code reviews and more.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT face=verdana,geneva&gt;Next time I’ll discuss Phase 5: Release for LOB. Till then happy &amp;amp; secure coding. 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/FONT&gt;&lt;/SPAN&gt;
&lt;P style="MARGIN: auto 0in" class=MsoBodyText&gt;&lt;SPAN style="LINE-HEIGHT: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;FONT face=verdana,geneva&gt;-Anmol Malhotra &lt;BR&gt;Senior Security Engineer &lt;BR&gt;ACE Team&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt; 
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/SPAN&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9852580" width="1" height="1"&gt;</description></item><item><title>Blog Series: Get Familiar with the SDL-LOB Process. Introduction to Phase Three: Implementation for LOB.</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx</link><pubDate>Mon, 13 Jul 2009 19:49:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9831951</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9831951</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/07/13/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-3-implementation-for-lob.aspx#comments</comments><description>&lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;Hello, Anmol here.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;For this blog series I’ll discuss the &lt;span style="font-family: &amp;#39;Verdana&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 10pt; mso-ansi-language: en-us; mso-fareast-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-fareast-language: en-us; mso-bidi-language: ar-sa"&gt;the &lt;span style="mso-bidi-font-family: &amp;#39;Times New Roman&amp;#39;; mso-bidi-theme-font: minor-bidi; mso-ansi-font-size: 10.0pt; mso-ascii-font-family: verdana; mso-hansi-font-family: verdana"&gt;&lt;a title="Security Development Lifecycle for Line-of-Business applications (SDL-LOB)" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;Security Development Lifecycle for Line-of-Business applications (SDL-LOB)&lt;/a&gt;&lt;/span&gt; &lt;/span&gt;process and covering all 5 phases.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Today I’ll discuss &lt;b style="mso-bidi-font-weight: normal"&gt;&lt;i style="mso-bidi-font-style: normal"&gt;Phase Three: Implementation for LOB&lt;/i&gt;&lt;/b&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;The SDL-LOB defines the standards and best practices for providing security and privacy for new and existing line-of-business (LOB) applications currently under development or being planned for development&lt;span style="mso-bidi-font-family: arial"&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;If you missed prior phases, here’s &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-size: 11.0pt"&gt;&lt;a title="Phase 1 - SDL-LOB" href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;&lt;font size="2"&gt;Phase 1&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: arial"&gt; and &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-size: 11.0pt"&gt;&lt;a title="SDL-LOB Phase 2" href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx" target="_blank" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx"&gt;&lt;font size="2"&gt;Phase 2&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: arial"&gt;.       &lt;p&gt;&lt;/p&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;Highlight for phase three are: &lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto 0in auto 0.75in; mso-list: l0 level1 lfo1" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;Incorporate Security Checklist and Review Policies       &lt;p&gt;&lt;/p&gt;     &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto 0in auto 0.75in; mso-list: l0 level1 lfo1" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;Conduct ‘Self’ Code Review       &lt;p&gt;&lt;/p&gt;     &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: auto 0in auto 0.75in; mso-list: l0 level1 lfo1" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;Run Code Analysis Tools and Incorporate Security Libraries       &lt;p&gt;&lt;/p&gt;     &lt;/b&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;You may be wondering, what is a ‘self’ review?&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;A ‘self’ review involves assessing your application to ensure it complies with security checklists and standards; and conducting a self-directed code review and code analysis of the application.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;An internal review is performed by the application development team.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;It’s important for development teams to adopt coding techniques and methodologies.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;More importantly, the next step is to incorporate documented coding practices and forming a security checklist.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;A checklist creates a threshold for you to measure against, i.e., at minimum these items must be met.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Using a security checklist is not a new concept; however ensuring items not met on the checklist are sufficiently documented and accounted for is the &lt;i style="mso-bidi-font-style: normal"&gt;key&lt;/i&gt; to its effectiveness. See checklist items from the &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;a title="Security Checklist Index" href="http://msdn.microsoft.com/en-us/library/ms998392.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/ms998392.aspx"&gt;&lt;font size="2"&gt;Security Checklist Index&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt; from Microsoft Patterns and Practices.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;In this phase, development teams also conduct an independent “self” code review.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;To perform this task, there are several available security tools Microsoft offers including static analysis, runtime security tools and libraries.&lt;span style="mso-spacerun: yes"&gt;&amp;#160;&amp;#160; &lt;/span&gt;The &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font color="#0000ff" size="2"&gt;&lt;a title="Microsoft Information Security" href="http://www.msinfosec.com/" target="_blank" mce_href="http://www.msinfosec.com"&gt;Anti-XSS library&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt; can protect ASP.NET Web-based applications from XSS (cross-site scripting) attacks. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;It offers a more rigorous “white-list” approach than the native encoding methods found in .NET. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;Run &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font color="#0000ff" size="2"&gt;&lt;a title="Microsoft Information Security" href="http://www.msinfosec.com/" target="_blank" mce_href="http://www.msinfosec.com"&gt;CAT.NET&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt; on managed code (C#, Visual Basic .NET, J#) applications. CAT.NET is a snap-in to the Visual Studio IDE that helps you identify exploitable code paths for security vulnerabilities, such as XSS, SQL Injection, Process Command Injection and more. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;Get familiar with the &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 9pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;a title="SDL-LOB" href="http://msdn.microsoft.com/en-us/library/dd831972.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd831972.aspx"&gt;&lt;font size="2"&gt;SDL-LOB document&lt;/font&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt; and learn more about available tools and additional details on how to perform internal reviews for your application.       &lt;p&gt;&lt;/p&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font face="verdana,geneva"&gt;Next time I’ll discuss Phase Four: Verification for LOB. Till then happy &amp;amp; secure coding.        &lt;p&gt;&lt;/p&gt;     &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font face="verdana,geneva"&gt;-Anmol Malhotra        &lt;br /&gt;Senior Security Engineer         &lt;br /&gt;ACE Team&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin; mso-bidi-font-size: 10.0pt"&gt;&lt;font size="3" face="Calibri"&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin"&gt;     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9831951" width="1" height="1"&gt;</description></item><item><title>Blog Series: Get Familiar with the SDL-LOB Process, Introduction to Phase Two: Design for LOB</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx</link><pubDate>Sat, 20 Jun 2009 04:29:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9792526</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9792526</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/06/19/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-2-design-for-lob.aspx#comments</comments><description>&lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-ansi-language: en; mso-bidi-font-weight: bold" lang="EN"&gt;&lt;font face="verdana,geneva"&gt;Hello, Anmol here.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;This is a continuation of my blog series on the &lt;/font&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;&lt;font face="verdana,geneva"&gt;SDL-LOB process&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt;.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;In my last blog entry I talked about &lt;/font&gt;&lt;a href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx"&gt;&lt;font face="verdana,geneva"&gt;Phase 1: Requirements for LOB&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt;&lt;b&gt;.&amp;#160; &lt;/b&gt;Let’s discuss Phase Two:&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;Design for LOB.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;As you read my blog series on the SDL-LOB process, I will try to share experiences and lessons learned from an &lt;/font&gt;&lt;a href="http://www.msinfosec.com/" mce_href="http://www.msinfosec.com/"&gt;&lt;font face="verdana,geneva"&gt;Information Security&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt; group perspective.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;Phase Two is all about ensuring that application follows “Secure by Default” principle. &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;There are 2 key tasks to be executed in this phase:&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="mso-spacerun: yes"&gt;&lt;font face="verdana,geneva"&gt;&lt;/font&gt;&lt;/span&gt;&amp;#160;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class="MsoListParagraphCxSpFirst"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Threat Modeling&lt;/font&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class="MsoListParagraphCxSpLast"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;·&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Design Review&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;Both of these activities are aimed towards identifying security design flaws upfront in the lifecycle and helping in reducing the number of security bugs propagating on to the next stages. It is far more resource intensive and cumbersome to mitigate issues identified during verification phase and even costlier if identified in production time. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;Let me illustrate this by an example shown below: &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="Verdana"&gt;&lt;/font&gt;&amp;#160;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;img style="width: 528px; height: 369px" title="SDL-LOB: Phase 2: Design for LOB" alt="SDL-LOB: Phase 2: Design for LOB" src="http://blogs.msdn.com/photos/ace_team/images/9792522/original.aspx" width="1167" height="633" mce_src="http://blogs.msdn.com/photos/ace_team/images/9792522/original.aspx" /&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;&lt;/font&gt;&amp;#160;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 8.5pt"&gt;     &lt;p&gt;&lt;font size="2" face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;Let’s assume that your design did not consider validating user controlled input and output encoding strategy. This would result in developers coding and developing the application without deviating from the final design which lacked specific security considerations in the first place. This would eventually result in 100s of “Cross Site Scripting” bugs turning up during verification stage. I am sure no application team would want that to happen. Wouldn’t it be nice if we followed few design time activities which would call out specific security considerations that need to be followed by the development team in the context of the application? &lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;To learn more read the detailed Design phase tasks &lt;/font&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd831971.aspx" mce_href="http://msdn.microsoft.com/en-us/library/dd831971.aspx"&gt;&lt;font face="verdana,geneva"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="mso-spacerun: yes"&gt; and also watch my podcast &amp;quot;&lt;a title="Security Design Reviews" href="http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/" target="_blank" mce_href="http://channel9.msdn.com/posts/Jossie/Security-Design-Reviews/"&gt;Security Design Reviews&lt;/a&gt;&amp;quot; where I discuss more why security should be &amp;quot;baked&amp;quot; into the application starting with the Design phase.&amp;#160; &lt;/span&gt;Next time, I’ll talk about Phase Three: Implementation for LOB.&lt;/font&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;font face="verdana,geneva"&gt;Here are some additional resources &lt;/font&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;     &lt;div style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx" mce_href="http://msdn.microsoft.com/en-us/security/aa570413.aspx"&gt;&lt;font color="#0000ff" face="verdana,geneva"&gt;Threat Analysis and Modeling&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt; &lt;/font&gt;&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: symbol; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol"&gt;&lt;span style="mso-list: ignore"&gt;&lt;font face="verdana,geneva"&gt;&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&lt;font size="2"&gt;&amp;#160;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/aa302421.aspx" mce_href="http://msdn.microsoft.com/en-us/library/aa302421.aspx"&gt;&lt;font color="#0000ff" face="verdana,geneva"&gt;Conducting Design Reviews&lt;/font&gt;&lt;/a&gt;&lt;font face="verdana,geneva"&gt; &lt;/font&gt;&lt;/div&gt;   &lt;/li&gt; &lt;/ul&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;   &lt;p&gt;&lt;font face="verdana,geneva"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-ansi-language: en; mso-bidi-font-size: 10.0pt" lang="EN"&gt;&lt;font face="verdana,geneva"&gt;-Anmol Malhotra        &lt;br /&gt;Senior Security Engineer         &lt;br /&gt;ACE Team&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-ansi-language: en; mso-bidi-font-size: 10.0pt" lang="EN"&gt;&lt;font face="Verdana"&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9792526" width="1" height="1"&gt;</description></item><item><title>Blog Series: Get Familiar with the SDL-LOB Process, Introduction to Phase One: Requirements for LOB</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx</link><pubDate>Tue, 16 Jun 2009 20:00:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9762696</guid><dc:creator>ACE Team</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9762696</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/06/16/blog-series-get-familiar-with-the-sdl-lob-process-introduction-to-phase-1-requirements-for-lob.aspx#comments</comments><description>&lt;h1 style="margin: 0in 0in 10pt"&gt;&lt;span style="line-height: 115%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 14pt"&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/h1&gt; &lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Hello, Anmol here.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;For this blog series I’ll discuss the SDL-LOB process and cover all 5 phases as we go.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;In my last blog entry I provided an overview of this process, &lt;a href="http://blogs.msdn.com/ace_team/archive/2009/06/02/blog-series-get-familiar-with-the-sdl-lob-security-development-lifecycle-for-line-of-business-applications-process.aspx" mce_href="http://blogs.msdn.com/ace_team/archive/2009/06/02/blog-series-get-familiar-with-the-sdl-lob-security-development-lifecycle-for-line-of-business-applications-process.aspx"&gt;Blog Series: Get Familiar with the SDL-LOB Process&lt;/a&gt;&lt;b&gt;.&amp;#160; &lt;/b&gt;Today I’ll discuss Phase One: &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;Requirements for LOB.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;As you read my blog series on the SDL-LOB process, I will try to share experiences and lessons learned from an information security group perspective.    &lt;p&gt;&lt;/p&gt; &lt;/span&gt;   &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt"&gt;       &lt;p&gt;&amp;#160;&lt;/p&gt;     &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt"&gt;Phase One: It’s is all about “Risk Assessment”       &lt;p&gt;&lt;/p&gt;     &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt"&gt;       &lt;p&gt;&amp;#160;&lt;/p&gt;     &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;What we learned from our experiences working for more than 6 years now in securing Microsoft’s line of business applications is that effectively assessing risk is one of the stepping stones for managing a big portfolio of applications in an enterprise.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;We have an inventory of more than 3500 applications which have different security and privacy needs. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;As you can imagine, it would have been impossible to manage such a large number of applications without effective –       &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class="MsoListParagraph"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-fareast-font-family: &amp;#39;Segoe UI&amp;#39;; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: ignore"&gt;a)&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Application inventory      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class="MsoListParagraph"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-fareast-font-family: &amp;#39;Segoe UI&amp;#39;; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: ignore"&gt;b)&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Risk Assessment     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo2" class="MsoListParagraph"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-fareast-font-family: &amp;#39;Segoe UI&amp;#39;; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: ignore"&gt;c)&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Service Levels      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt"&gt;       &lt;p&gt;&amp;#160;&lt;/p&gt;     &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt"&gt;The following diagram summarizes key tasks in this phase: &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt"&gt;&lt;/span&gt;&lt;/b&gt;&amp;#160;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;     &lt;p&gt;&lt;img style="width: 577px; height: 343px" title="Risk Assessment" alt="Risk Assessment" align="middle" src="http://blogs.msdn.com/photos/ace_team/images/9762706/original.aspx" width="616" height="366" mce_src="http://blogs.msdn.com/photos/ace_team/images/9762706/original.aspx" /&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt 0.5in" class="MsoListParagraph"&gt;&lt;b&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt"&gt;       &lt;p&gt;&amp;#160;&lt;/p&gt;     &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="page-break-after: avoid; margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-no-proof: yes"&gt;&lt;shapetype id="_x0000_t75" stroked="f" filled="f" path="m@4@5l@4@11@9@11@9@5xe" o:preferrelative="t" o:spt="75" coordsize="21600,21600"&gt;&lt;stroke joinstyle="miter"&gt;&lt;/stroke&gt;&lt;formulas&gt;&lt;f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/f&gt;&lt;f eqn="sum @0 1 0"&gt;&lt;/f&gt;&lt;f eqn="sum 0 0 @1"&gt;&lt;/f&gt;&lt;f eqn="prod @2 1 2"&gt;&lt;/f&gt;&lt;f eqn="prod @3 21600 pixelWidth"&gt;&lt;/f&gt;&lt;f eqn="prod @3 21600 pixelHeight"&gt;&lt;/f&gt;&lt;f eqn="sum @0 0 1"&gt;&lt;/f&gt;&lt;f eqn="prod @6 1 2"&gt;&lt;/f&gt;&lt;f eqn="prod @7 21600 pixelWidth"&gt;&lt;/f&gt;&lt;f eqn="sum @8 21600 0"&gt;&lt;/f&gt;&lt;f eqn="prod @7 21600 pixelHeight"&gt;&lt;/f&gt;&lt;f eqn="sum @10 21600 0"&gt;&lt;/f&gt;&lt;/formulas&gt;&lt;path o:connecttype="rect" gradientshapeok="t" o:extrusionok="f"&gt;&lt;/path&gt;&lt;lock aspectratio="t" v:ext="edit"&gt;&lt;/lock&gt;&lt;/shapetype&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;     &lt;p&gt;&lt;font size="3"&gt;&amp;#160;&lt;/font&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Every organization is unique in how it measures and reacts to risk. However under the hood the basic principle for assessing risk remains consistent.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;When looking at application we first try to gather the following information.      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class="MsoListParagraph"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-fareast-font-family: &amp;#39;Segoe UI&amp;#39;; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: ignore"&gt;a)&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Data: Type of data being handled by the application (is it sensitive, non sensitive, public, etc.)     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class="MsoListParagraph"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-fareast-font-family: &amp;#39;Segoe UI&amp;#39;; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: ignore"&gt;b)&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Business: Business Unit being catered by the application (such as finance, HR, payroll or cafeteria)     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class="MsoListParagraph"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-fareast-font-family: &amp;#39;Segoe UI&amp;#39;; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: ignore"&gt;c)&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Audience: Audience (users of the application) and hosting type&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;(internal/external)       &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;     &lt;p&gt;&amp;#160;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: 0in 0in 0pt" class="MsoNormal"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;From a broader level, we are also trying to get a mind map of what will be the impact on the organization if the application got compromised.      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo3" class="MsoListParagraph"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-fareast-font-family: &amp;#39;Segoe UI&amp;#39;; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: ignore"&gt;a)&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Will this cause negative impact to the company’s reputation? (loss of customers, brand, etc.)     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l2 level1 lfo3" class="MsoListParagraph"&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-fareast-font-family: &amp;#39;Segoe UI&amp;#39;; mso-bidi-font-weight: bold"&gt;&lt;span style="mso-list: ignore"&gt;b)&lt;span style="font: 7pt &amp;#39;Times New Roman&amp;#39;"&gt;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; font-size: 10pt; mso-bidi-font-weight: bold"&gt;Will this cause negative business impact? (loss of revenue, sensitive data stolen, etc.)     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; mso-bidi-font-weight: bold; mso-bidi-font-size: 10.0pt"&gt;As application data becomes more sensitive or the system becomes more critical to business, risk increases.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; mso-bidi-font-weight: bold; mso-bidi-font-size: 10.0pt"&gt;Whenever you’re working with risk, it’s most likely there will be a risk assessment in some form conducted.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;For the SDL-LOB process&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;, a &lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt;&lt;a title="Risk Assessment" href="http://msdn.microsoft.com/en-us/library/dd835478.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd835478.aspx"&gt;Risk Assessment questionnaire&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;"&gt; helps us capture general &lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; font-size: 11pt"&gt;security and privacy ‘‘&lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; color: black; mso-bidi-font-weight: bold; mso-bidi-font-size: 10.0pt"&gt;qualities” for the application.&lt;span style="mso-spacerun: yes"&gt;&amp;#160; &lt;/span&gt;This allows us to determine the appropriate amount of “oversight” needed. Essentially we are trying to understand the potential risk the application poses for the enterprise. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;From a risk perspective, if an application is high risk, we’ll put forth more oversight and vice versa, if an application is low risk, it receives less oversight. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;Note that definition of what is “High” is also organization specific. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;You can create your own risk categories such as “Red/Orange/Green,” “High/Medium/Low,“ “Most Risky/Risky/Minimum Risk” - it’s all up to you. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;Identifying the most risky applications in an organization and spending the right resources, money and time to reduce the risk posed by them is the key here.&lt;/span&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-bidi-font-size: 10.0pt"&gt;      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-bidi-font-size: 10.0pt"&gt;At Microsoft, risk assessment produces repeatable guidance on the type of oversight the application will receive in the SDL-LOB process. &lt;span style="mso-spacerun: yes"&gt;&amp;#160;&lt;/span&gt;I encourage you to read the detailed requirements and recommendations for this Phase on Security Development Lifecycle 4.1 under &lt;a title="SDL-LOB Phase 1: Requirements for LOB" href="http://msdn.microsoft.com/en-us/library/dd861504.aspx" target="_blank" mce_href="http://msdn.microsoft.com/en-us/library/dd861504.aspx "&gt;SDL-LOB&lt;/a&gt; section.       &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-bidi-font-size: 10.0pt"&gt;Next time I'll talk about Phase Two: Design for LOB.     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-ansi-language: en; mso-bidi-font-size: 10.0pt" lang="EN"&gt;-Anmol Malhotra      &lt;br /&gt;Senior Security Engineer       &lt;br /&gt;ACE Team&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin: auto 0in" class="MsoBodyText"&gt;&lt;span style="line-height: 112%; font-family: &amp;#39;Segoe UI&amp;#39;,&amp;#39;sans-serif&amp;#39;; mso-ansi-language: en; mso-bidi-font-size: 10.0pt" lang="EN"&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9762696" width="1" height="1"&gt;</description></item><item><title>Blog Series: Get Familiar with the SDL-LOB (Security Development Lifecycle for Line-Of-Business Applications) Process</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/06/02/blog-series-get-familiar-with-the-sdl-lob-security-development-lifecycle-for-line-of-business-applications-process.aspx</link><pubDate>Tue, 02 Jun 2009 18:14:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9685661</guid><dc:creator>ACE Team</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9685661</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/06/02/blog-series-get-familiar-with-the-sdl-lob-security-development-lifecycle-for-line-of-business-applications-process.aspx#comments</comments><description>&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Hello, Anmol Malhotra here. I’m a Senior Security Engineer with ACE Team, a part of Microsoft IT &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT color=#0000ff size=2 face=verdana,geneva&gt;&lt;A title="Microsoft Information Security" href="http://www.msinfosec.com/" target=_blank mce_href="http://www.msinfosec.com"&gt;Information Security&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; group. I’d like to introduce you to the &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=2 face=verdana,geneva&gt;&lt;A title=SDL-LOB href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;Security Development Lifecycle for Line-of-Business Applications (SDL-LOB)&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; process.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;As part of our continued commitment towards sharing security processes and recommendations with our customers, we’re excited to announce the addition of detailed security requirements and recommendations for LOB (line-of-business) applications with the release of &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: calibri; mso-bidi-font-size: 11.0pt; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=2 face=verdana,geneva&gt;&lt;A title="Microsoft SDL 4.1" href="http://msdn.microsoft.com/en-us/library/84aed186-1d75-4366-8e61-8d258746bopq.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/84aed186-1d75-4366-8e61-8d258746bopq.aspx"&gt;Microsoft SDL version 4.1&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt; on MSDN. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;SDL-LOB provides a mainstream approach to the SDL which focuses on development of applications that support the business such as accounting, human resources (HR), payroll, &lt;/FONT&gt;&lt;A href="http://searchcio.techtarget.com/sDefinition/0,,sid182_gci214546,00.html" mce_href="http://searchcio.techtarget.com/sDefinition/0,,sid182_gci214546,00.html"&gt;&lt;SPAN style="LINE-HEIGHT: 112%; COLOR: windowtext; TEXT-DECORATION: none; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-font-size: 11.0pt; mso-ascii-font-family: calibri; mso-hansi-font-family: calibri; text-underline: none"&gt;&lt;FONT face=verdana,geneva&gt;supply chain management&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT face=verdana,geneva&gt; and resource planning applications, etc. The SDL-LOB guidance is positioned exclusively for LOB applications or web applications; and not for ISV/rich client and server application development. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Here’s an overview of SDL-LOB process.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;High level tasks performed in each stage are listed in the table below:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;IMG alt="Dd831970.SDL Lifecycle(en-us,MSDN.10).png" src="http://i.msdn.microsoft.com/Dd831970.SDL%20Lifecycle(en-us,MSDN.10).png" width=548 height=31&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;TABLE style="WIDTH: 544px; HEIGHT: 111px" class=class border=1 cellSpacing=0 cellPadding=2 width=544 class="class"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top width=77 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Training&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=94 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Requirements&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=129 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Design&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=104 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Implementation&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=108 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Verification&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=48 class="class"&gt;&lt;FONT style="BACKGROUND-COLOR: #ffffff" size=2 face=Arial&gt;&lt;STRONG&gt;Release&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=class vAlign=top width=77 class="class"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-weight: bold"&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;LOB-specific training &lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=94 class="class"&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;Risk assessment &lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;-Application portfolio&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;-Application risk assessment&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;-Determine service level&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=129 class="class"&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;Asset-centric threat modeling &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;-Threat model&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=1 face=Verdana&gt;
&lt;P&gt;-Design review &lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;/P&gt;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=104 class="class"&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;Internal review &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;-Incorporate security checklists and standards&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=1 face=Verdana&gt;
&lt;P&gt;-Conduct “self” code review &lt;/P&gt;
&lt;P&gt;-Security code analysis &lt;/P&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=108 class="class"&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;Pre-production assessment &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;-Comprehensive security assessment &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=1 face=Verdana&gt;-Bug tracking &lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt; mso-list: l3 level1 lfo4; tab-stops: list .5in; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=1 face=verdana,geneva&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT size=1 face=verdana,geneva&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD class=class vAlign=top width=48 class="class"&gt;
&lt;P style="MARGIN: 2pt 0in" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=1 face=verdana,geneva&gt;Post-production assessment &lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 10pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;FONT size=1 face=verdana,geneva&gt;-Host level scan &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;FONT size=1 face=verdana,geneva&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;It is important to note that organizations should adapt rather than adopt “Microsoft SDL-LOB” process.&lt;B style="mso-bidi-font-weight: normal"&gt; &lt;/B&gt;Organizations are unique – given that fact we should expect and plan for differences in resources, executive support and security expertise.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Some of the highlights of SDL-LOB are:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;To weave security in SDLC by embedding various milestones/checkpoints in each of the phases.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;Identifying security vulnerabilities early in the development cycle and thereby improving the overall design.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;To enable effective application risk management from strategic, tactical, operational and legal perspective.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;At Microsoft, all line-of-business application development teams must go through the SDL-LOB process and if they fail to do so, the application cannot go live. Enforcement of the SDL-LOB process attributes to its success.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 12pt 0in 0pt" class=MsoBodyText&gt;&lt;FONT face=verdana,geneva&gt;In this blog series I’ll discuss the highlights of each of the phases in SDL-LOB.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Next time, I’ll go over &lt;B style="mso-bidi-font-weight: normal"&gt;Phase 1: Risk Assessment for LOB&lt;/B&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In the mean time get familiar with the SDL-LOB &lt;/FONT&gt;&lt;SPAN style="LINE-HEIGHT: 112%; FONT-FAMILY: 'Arial','sans-serif'; FONT-SIZE: 9pt; mso-bidi-font-family: 'Times New Roman'; mso-bidi-font-size: 11.0pt"&gt;&lt;FONT size=2 face=verdana,geneva&gt;&lt;A title="Microsoft SDL-LOB" href="http://msdn.microsoft.com/en-us/library/dd831975.aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/dd831975.aspx"&gt;here&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT face=verdana,geneva&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=verdana,geneva&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;-Anmol Malhotra &lt;BR&gt;Senior Security Engineer &lt;BR&gt;ACE Team&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9685661" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Security/">Security</category><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/SDL_2D00_LOB/">SDL-LOB</category></item><item><title>How Do I: Set Up Fiddler’s Reverse Proxy to Create a VSTS 2008 Web Test</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/05/29/how-do-i-set-up-fiddler-s-reverse-proxy-to-create-a-vsts-2008-web-test.aspx</link><pubDate>Sat, 30 May 2009 02:10:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9660625</guid><dc:creator>ACE Team</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9660625</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/05/29/how-do-i-set-up-fiddler-s-reverse-proxy-to-create-a-vsts-2008-web-test.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;VSTS 2008 has a great recording tool that allows you to create web test simply by recording your web traffic in the browser. But what if your application doesn’t use web browser, but still communicates with servers using HTTP or HTTPS protocols (such as Smart Client application). Then, you can use Fiddler to capture web traffic on the client side and create a VSTS test from Fiddler’s capture. Unfortunately, there might be one more problem… Since Fiddler acts as a proxy, you web application’s traffic has to go through Fiddler. But it doesn’t work for some application, which might have web server name hardcoded into code or configuration file. When this happens, there is another way to record application’s web traffic and create a VSTS 2008 web test – by using Fiddler’s reverse proxy. By reverse proxy I mean capturing web traffic on the web server side, and not on the client side. Basically, your application will think that it’s hitting web server, while it will be directing its traffic to Fiddler installed on web server, and then Fiddler will forward that traffic to the actual application. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Here are the steps on how to set up and use reverse proxy:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Log in to your web server and install the latest versions of Fiddler (http://www.fiddler2.com/Fiddler2/) and neXpert (http://www.fiddler2.com/fiddler2/addons/nexpert.asp)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open IIS manager (Start&amp;gt;Administrative Tools&amp;gt;Internet Information Services (IIS) Manager)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;3.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Find your application under Web Sites, right click it and select Properties&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;4.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Change TCP port from 80 to 81, and click OK &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&lt;IMG style="WIDTH: 471px; HEIGHT: 454px" title="IIS Manager Port Edit" alt="IIS Manager Port Edit" src="http://blogs.msdn.com/photos/ace_team/images/9651364/original.aspx" width=471 height=454 mce_src="http://blogs.msdn.com/photos/ace_team/images/9651364/original.aspx"&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;5.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open Fiddler on Web server&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;6.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Select Tools &amp;gt; Fiddler Options&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;7.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Make sure “Allow remote computers to connect” check box is checked on General tab&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;8.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Click on Connections tab, and Change “Fiddler listens on port:” from 8888 to 80, and click OK&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;IMG style="WIDTH: 550px; HEIGHT: 391px" title="Fiddler Port Edit" alt="Fiddler Port Edit" src="http://blogs.msdn.com/photos/ace_team/images/9651366/original.aspx" width=550 height=391 mce_src="http://blogs.msdn.com/photos/ace_team/images/9651366/original.aspx"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;9.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Select Rules &amp;gt; Customize Rules…&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;10.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Find “static function OnBeforeRequest(oSession: Session)”&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;11.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Add the following code inside of curly brackets: if (oSession.host.toLowerCase() == "webserver") oSession.host = "webserver:81"; &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;//(where webserver is the name of your web server, make sure you spell it in lower case)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&lt;FONT size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;So, it should look like this:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;static function OnBeforeRequest(oSession: Session)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;&lt;SPAN style="mso-tab-count: 2"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;if (oSession.host.toLowerCase() == "WebServer") oSession.host = "WebServer:81";&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&lt;FONT size=2&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;12.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Save it and close text editor.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;13.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Close Fiddler and open it again.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;14.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Make sure that Fiddler is capturing the traffic (Left bottom corner should say “Capturing” or if you click on File menu, “Capture traffic” will have a check mark next to it)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;15.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open the application you want to record on the client (not on web server) and perform activities you want to be recorded. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;16.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Make sure to add a step description after each step you perform by going back to Fiddler on Web server, selecting neXpert tab and clicking Add for Step Description.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;IMG style="WIDTH: 587px; HEIGHT: 361px" title=neXpert alt=neXpert src="http://blogs.msdn.com/photos/ace_team/images/9651365/original.aspx" width=587 height=361 mce_src="http://blogs.msdn.com/photos/ace_team/images/9651365/original.aspx"&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;17.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;After you recorded all steps, go back to Fiddler on Web server and stop capturing.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;18.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Select all recorded sessions (Ctrl + A), right click them and select Save&amp;gt;Selected Sessions&amp;gt;as Visual Studio Web Test…&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;19.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Also, make sure to check out neXpert report, by clicking Create Report button on neXpert tab.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;20.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Change Fiddler listen port back to 8888 (Tools &amp;gt; Fiddler Options &amp;gt; Connections tab). And close fiddler&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;21.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Change application’s TCP port back to 80 in IIS manager (See step 4)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;22.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Then, copy the Web test you created with Fiddler in step 18 to your machine (Where you have VSTS 2008 installed).&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;23.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open or Create a VSTS 2008 test project. &lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;24.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Right click Project name in Solution Explorer and select Add &amp;gt; Existing Item. Browse to your recorded web test and click OK.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;25.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Open web test from Solution Explorer and remove “:81” from all requests (by pressing CTRL + H, and replacing all “webserver:81” with “webserver”, where webserver is the name of your Web server)&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l1 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;26.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;Then, save the Web test and run it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Notice that web test has transactions already for each step that you recorded, if you added step description using neXpert tab.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Also, this method works the best for http traffic. If your application uses https, you can disable it while recording the test, by:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpFirst&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;opening IIS manager on the web server&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;right clicking your web site and selecting Properties&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;selecting Directory Security tab&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpMiddle&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;clicking Edit on Secure Communications session&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo2" class=MsoListParagraphCxSpLast&gt;&lt;FONT size=2&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt; mso-bidi-font-family: Verdana; mso-fareast-font-family: Verdana"&gt;&lt;SPAN style="mso-list: Ignore"&gt;-&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;and unchecking “Require secure channel (SSL)”&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Make sure to switch it back on when you done recording the test and replacing all HTTP requests in your Web test with HTTPS (the same method we used in step 25).&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;I also created a video on how to set up a Reverse proxy. You can view it here: &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://msdn.microsoft.com/en-us/teamsystem/dd876614.aspx"&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;http://msdn.microsoft.com/en-us/teamsystem/dd876614.aspx&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;---------------------------------------- &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Vitaliy Konev&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;/SPAN&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Performance Engineer&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-FAMILY: 'Verdana','sans-serif'; COLOR: black; FONT-SIZE: 8pt"&gt;&lt;FONT size=2&gt;Microsoft – ACE Team&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9660625" width="1" height="1"&gt;</description></item><item><title>TechNet Webcast: Configuring with Least Privilege in SQL Server 2008 (Level 300)</title><link>http://blogs.msdn.com/b/ace_team/archive/2009/05/29/technet-webcast-configuring-with-least-privilege-in-sql-server-2008-level-300.aspx</link><pubDate>Sat, 30 May 2009 00:46:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9658944</guid><dc:creator>ACE Team</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.msdn.com/b/ace_team/rsscomments.aspx?WeblogPostID=9658944</wfw:commentRss><comments>http://blogs.msdn.com/b/ace_team/archive/2009/05/29/technet-webcast-configuring-with-least-privilege-in-sql-server-2008-level-300.aspx#comments</comments><description>&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3 face=Calibri&gt;TechNet Webcast&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Configuring with Least Privilege in SQL Server 2008 (Level 300)&lt;BR&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Tuesday, June 02, 2009 8:00 AM Pacific Time (US &amp;amp; Canada)&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Presenter:&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt; &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;Varun Sharma, Security Engineer, Microsoft Corporation&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;U&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;Overview&lt;/SPAN&gt;&lt;/U&gt;&lt;/B&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;With SQL injection attacks on the rise, it is imperative to configure Microsoft SQL Server with least privilege. In this webcast, we provide an overview on how to configure a SQL Server installation with least privilege for a typical line-of-business application. We cover configuring least-privileged service accounts for SQL Server services, best practices for configuring least-privileged principals used by the front-end or middle tiers to connect to the SQL Server back end, and the details of configuring SQL Server job steps with least privilege.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A title="Configuring with Least Privilege in SQL Server 2008 (Level 300)" href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032415806&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US" target=_blank mce_href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032415806&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;Register Here&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; mso-layout-grid-align: none" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9658944" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/b/ace_team/archive/tags/Security/">Security</category></item></channel></rss>
