Home
Resources
Training
About Us
eStore
<a href="http://www.isdecisions.com/en/software/userlock/?xtor=SEC-230"><img src="http://www.isdecisions.com/images/pubs/Randy/userlock.gif" alt="UserLock" border="0" /></a>

>

resources > newsletter > archive > issue #34

 

 

 

 

 

 

 

Latest Blog: WinReporter 4.0 Makes It Easy to Assess Attack Surface

 

Ultimate Windows Security Newsletter:

Issue #34, 1/05/07

I hope 2007 is getting off to a good start for you.  Perhaps this will make it even better: I’m excited to announce a number of updated and new resources at www.ultimatewindowssecurity.com.

First, I’ve revised my eBook, The Windows Server 2003 Security Log Revealed.  We fixed typos, made a few corrections and added new features such as links for event IDs back to the Security Log Encyclopedia.  A free copy of the revised book is available to all previous purchasers.  Just logon to the eStore with your email address and download the new copy.  You have all month to download the eBook after which the link will break.  For those of you that don’t already have a copy and wish to purchase one, please use coupon code QR323 to save $10. 

Second, I’ve made numerous revisions to the free Security Log Encyclopedia at www.ultimateWindowsSecurity.com.  We’ve added new event IDs, made a corrections and added additional information throughout the encyclopedia. 

Third, I’ve built a new section on the site for Vista’s BitLocker drive encryption feature.  If laptop security is important to you, you need to learn about BitLocker.  BitLocker is an important security improvement to Windows but there are some very important caveats and decisions of which you should be aware.  At www.UltimateWindowsSecurity.com/bitlocker.asp you’ll find 2 FAQs and 2 decision trees to help you understand BitLocker and all the important issues related to it.  You’ll find my take on questions like “Should we require USB drive startup keys?” and “Which of the 4 recovery options should we use?”.  The site will also be an important resource in the future for keeping up with developments in BitLocker such driver availability for different laptop models, utilities for managing BitLocker deployments and more.

Fourth, we have a special webinar coming up on auditing and monitoring databases.  In this webinar you will learn why the classic use of audit logs for monitoring databases doesn’t work.  For starters additional resource load isn’t an option for most database servers which are already “redlining” much of the day just handling transactions.  Then there’s the resistance from database administrators when you to install any software they aren’t familiar with.  In addition to my presentation you’ll also get to see the unique Informant product from RippleTech which audits every SQL command executed against popular database servers without any software, logging or communication with the database server.  Instead – and this is what I think is really cool – Informant sniffs the packets going to and from the database server and reconstructions every command and its results.  When Mel Shakir showed me Informant I immediately asked them to sponsor a webcast.  I think you’ll be as impressed as me.

OS audit logs receive all the attention but face it: the database is where the real business information resides.  The database is where financial transactions take place and where confidential customer information is accessed.  . 

Fifth, we made all the past Webinars I’ve done on the Windows security log available as video podcasts for you to download for a very small fee and watch in either high resolution on your PC or on your media player/iPod.  This is a great way to get deep education on Windows security log in easy to digest bites and perfect to watch over your lunch hour or on your commute (not for you drivers though!).  As we record new webinars we’ll add them to the site. 

As always, thank you so much for your support and patronage.  You made 2006 a good year at UltimateWindowsSecurity.com and we plan to provide you with even more and better resources for you this year.  Speaking of which, the security log poster is almost finalized.  I am committed to getting it in the mail by the end of the month.  Thank you for your patience.  If you have not requested your free copy of the 18”x24” poster yet go to https://www.ultimatewindowssecurity.com/poster/.

Have a good weekend and I’ll see you on Patch Tuesday.  Looks like it’s going to be a doozie – 8 security bulletins.

 

(c) copyright 2006 Monterey Technology Group, Inc. You may forward this email in full.  All other rights reserved.

Disclaimer: We do our best to provide quality information and expert commentary but use all information at your own risk.


Additional Links

A
D
V