Sign In
Information Security
Thoughts & Experiences from Todd Kutzke
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
About
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
A&P
Anti-XSS
CISF
Dogfooding
Risk Tracker
Archive
Archives
January 2010
(1)
November 2009
(2)
October 2009
(1)
September 2009
(4)
August 2009
(1)
July 2009
(3)
June 2009
(7)
May 2009
(1)
April 2009
(1)
March 2009
(2)
MSDN Blogs
>
Information Security
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Information Security
Reducing Operational Risk through Business Continuity Management
Posted
over 2 years ago
by
Todd Kutzke
0
Comments
Hi all, I’m Tom Easthope, Sr. Program Manager on the Enterprise Business Continuity team at Microsoft. This blog entry is a companion to the video featuring my colleagues Phil Sodoma and Traci Bishop. In their video they talked about the several aspects...
Information Security
InfoSec A&P Suite – How to Use the Tools
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
InfoSec recently released their Assessment & Protection (A&P) Suite . To get the details of this suite, you can check out my last blog . Anil Revuru (RV) from the IST ( Information Security Tools ) team in his recent blog discusses how Web...
Information Security
InfoSec Assessment & Protection (A&P) Suite Released
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
The Information Security Tools (IST) team has released the InfoSec Assessment & Protection (A&P) Suite . The suite is made up of a technology stack of protection and assessment tools. Anil Revuru (RV) and Mark Curphey in their recent podcast...
Information Security
Dogfooding: How Microsoft IT Information Security Dogfoods
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Hi Mark Smith here. I’m a senior program manager on the Microsoft Information Security . I’m kicking off our blog series providing you a glimpse into how Microsoft’s IT Information Security (InfoSec) dogfoods. When launching a new product naturally there...
Information Security
How to Integrate Risk Tracker with Internal HR Feeds
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
I’ve been discussing the Risk Tracker v1.0 application built on the CISF (Connected Information Security Framework) developed by our own team, Microsoft Information Security Tools (IST) team . Organizations who would like to deploy Risk Tracker in their...
Information Security
Risk Tracker v1.0 Release
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Recently I shared with you the release of the CISF (Connected Information Security Framework) and Risk Tracker version 1.0 application developed by the Microsoft Information Security Tools (IST) team . Risk Tracker built on CISF framework will help...
Information Security
Anti-XSS Library v3.1 Released!
Posted
over 3 years ago
by
Todd Kutzke
2
Comments
The Microsoft Information Security Tools (IST) team has released the latest Microsoft Anti-Cross Site Scripting (Anti-XSS) Library version 3.1 . How does a cross-site scripting (XSS) vulnerability occur? An example is when a web application does not encode...
Information Security
Announcing the Connected Information Security Framework (CISF) and Risk Tracker
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
I’m excited to announce the release of the Connected Information Security Framework (CISF) developed by our own Microsoft Information Security Tools (IST) team. This software development framework comprises of API’s and reusable components that is designed...
Information Security
Awareness – Part 3: Learning & Optimizing from Experience
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
In my last 2 posts on Information Security Awareness, I provided a little overview of the program and then discussed our framework around socializing security . I’d like to now discuss some of the things we’ve learned from driving awareness over the years...
Information Security
Awareness – Part 2: Socializing Security
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
In my last post on Awareness , I discussed an overview of our Awareness program and how we break up our initiative into breadth campaigns and depth programs to cover both the generic and the specific. In this post, I’d like to discuss a little bit about...
Information Security
Awareness – Part 1: Empowering the People
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
It’s well understood that security is a 3-pronged problem covering people, process and technology. Any solution devised to manage a given information security risk must effectively harmonize the people, the processes and the technologies to optimize the...
Information Security
Risk Analysis
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Risk analysis is an intimidating topic for security risk management organizations. Analysis takes precious time and can be complicated. Many times identified risks are vague and there are not a lot of facts to put around the risks. Organizations want...
Information Security
Beautiful Security
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Mark Curphey , who also leads our Information Security Tools team , contributed a chapter in a security book that was recently released. It’s a great book and you can get his chapter online for free… read more here . -Todd
Information Security
From Hyderabad: Over The Weekend
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Over the weekend, I had an opportunity to visit a few orphanages around Hyderabad. It’s an incredibly humbling experience. A little while back, I read a fantastic book titled “ Three Cups of Tea ” which really gets you thinking about the importance of...
Information Security
From Hyderabad: Teamwork
Posted
over 3 years ago
by
Todd Kutzke
2
Comments
I had a chance to play Cricket with the InfoSec India team this week. It was a great blast and it helped me frame an example I like to use to promote team work. Cricket, like a lot of sports, has many different roles that come together to make up a team...
Information Security
From Hyderabad: Local Leadership
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
I arrived in Hyderabad earlier this week and am underway meeting with the team members here. As I mentioned in the previous post , we realized early on how important it was to the overall success of InfoSec that we have presence in India. After we started...
Information Security
Information Security in India
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Next week I’m going to be in India to visit our team in Hyderabad. Outside of Redmond, USA, Hyderabad is our largest presence that makes up about 20% of our overall globally distributed Information Security team. It’s always a blast for me to visit India...
Information Security
Announcing SDL-LOB
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
I’m very excited to announce the recently released SDL-LOB. You can read more here and be sure to check back regularly on www.msinfosec.com as we will be highlighting various aspects of SDL-LOB. -Todd
Information Security
Rethinking Information Security: Align vs. Govern
Posted
over 3 years ago
by
Todd Kutzke
1
Comments
There is little doubt that information is fast becoming ubiquitous. In its digital form, you can have access to information over your desktop PC at home or work, your mobile laptop, your phone or even your entertainment system in your living room. The...
Information Security
Data Collection & Fact Gathering
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Information security risk management serves organizations best when it is proactive versus reactive. A reactive risk management program identifies a risk after the organization has been affected by the risk and has possibly experienced a risk event. This...
Information Security
Process of Managing Risk
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Information Security’s core function includes managing information security risk. Now there is a lot of content on the topic of “risk management” from both the academic world and the professional world that you can easily find on the internet. While we...
Information Security
Information Security & Performance
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Our mission in Information Security is to enable secure & reliable business . In going about our mission, we’ve constantly tried to take a very deliberate service-oriented view of information security rather than a purely enforcement approach. Like...
Information Security
Welcome...
Posted
over 3 years ago
by
Todd Kutzke
0
Comments
Welcome… My name is Todd Kutzke and I help lead the Information Security group within Microsoft. Organizationally, we sit inside Microsoft IT and together with our business partners, we help manage information security risk for Microsoft. The intent of...
Page 1 of 1 (23 items)