Uncategorized

It is recommended that you read Microsoft memo on putting security first

Progress in Microsoft’s Security & Operations, and a View of “Inadequate” Responses to Russian Attacks and the Cyber Safety Review Board

The software maker is also trying to improve its security culture after it was branded “inadequate” by the Cyber Safety Review Board. The engineering leads at Microsoft are now holding weekly and monthly operational meetings that include a variety of management and senior individuals, with a goal to improve Microsoft’s security thinking across the company.

Microsoft has added CISOs to each product team as well as moving its threat intelligence team to report directly to the CISO. It should mean that security in the engineering team is a clear responsibility.

Progress has been made towards Microsoft’s security goals. The company has implemented multifactor by default across more than 1 million of its own tenants within Microsoft, including ones used for development, testing, demos, and production. It has also removed 730,000 apps so far that “were out-of-lifecycle or not meeting current SFI standards.”

Microsoft is now coordinating its engineering teams to complete this work in waves across the company. Bell says that the engineering waves involve teams across Azure Cloud, Windows, Microsoft 365 and Security with additional product teams integrating weekly.

Some of the goals are tied to Microsoft leadership compensation and are a direct response to Russian hacker intrusions and the Cyber Safety Review Board recommendations.

Securing by design, secure by default and secure operations are some of Microsoft’s three security principles. These principles are designed to put security first during the design phases of products and services, place a greater focus on protections that are enabled by default, and improve controls and monitoring for current and future threats.

Do Security? Or Do You Need Security? Do Security to Protect the Future of the Internet – The SFI Story from Midnight Blizzard

Security is a team sport and SFI is everyone’s top priority, even if it is the first job for our security teams.

If you are faced with the dilemma of choosing between security and another priority, the answer is clear: do security. In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems. This is key to advancing both our platform quality and capability such that we can protect the digital estates of our customers and build a safer world for all.

We must approach the challenge with rigor and focus on continuous improvement. Every task we take on – from a line of code, to a customer or partner process – is an opportunity to help bolster our own security and that of our entire ecosystem. We were able to learn from our adversaries and their advanced capabilities, as we did with Midnight Blizzard. We monitor trillions of signals to strengthen our posture. It involves stronger, more structured collaboration between the public and private sectors.

Going forward, we will commit the entirety of our organization to SFI, as we double down on this initiative with an approach grounded in three core principles: