Microsoft to simplify security alerts

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Microsoft is promising customers that it will simplify the security alerts it routinely issues on problems affecting its products. The company notified customers of pending changes to security alert bulletins in an email sent on Tuesday to the Microsoft Security Notification Service mailing list. "Customer feedback tells us that, while technical professionals value our security bulletins, many end-users find them overly detailed and confusing," Steve Lipner, director of Microsoft Security Assurance, wrote in the email. He also noted that many people receive notices that would be "of interest only to developers or system administrators." To address both issues, Microsoft plans to "create a less technical end-user security bulletin that we will host, while continuing to offer more technical alerts for technology professionals. The new end-user security bulletins will describe straightforward steps that customers can take to help keep their systems secure," Lipner wrote. Those bulletins, like the more business-oriented ones, will be available at Microsoft's security Web site. "In addition, before year's end, we will create a new End User Security Notification Service that will notify customers of security issues in end-user-oriented products and provide a link to the appropriate end-user security bulletin," Lipner wrote. Microsoft stepped up its emphasis on security in January, when chairman Bill Gates sent an email to employees making security the company's No. 1 priority -- ahead of adding new product features. The company then unleashed a torrent of security alerts, after Microsoft developers uncovered problems during several intensive rounds of code reviews. So far this year, Microsoft has issued 64 security bulletins, exceeding by October the number of alerts sent out in all of 2001. Each bulletin can sometimes describe two, three or more separate security problems. Analysts gave Microsoft high marks for attempting to clean up its security bulletins, which they agreed are too difficult for most people to decipher. "Existing Microsoft security bulletins assume that the reader is a programmer," said independent security consultant Richard Smith. "Of course, most Microsoft customers are not programmers and therefore need simpler explanations of security problems." According to Robert McLaws, President of Interscape Technologies, "Computer security is not just an IT concern, but as of right now the only way to get security bulletins is through their (Microsoft's) IT assistance channels. "Security alerts targeted to laypeople is definitely a good idea, although I'm sure it will be difficult for tech people to simplify the concepts into nontech terms. It is definitely a step in the right direction," McLaws said. Besides changes to alerts, Microsoft also is revamping how security alerts are rated. The company had been rating severity of security problems as "low," "moderate" or "critical." Many people "find that the ratings fail to clearly identify the most serious issues," Lipner wrote. "There is also a widespread feeling that the Severity Ratings are difficult to understand and apply." Microsoft has added a fourth severity designation, "important," and posted clearer explanations what each of the four ratings mean.
For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section. Have your say instantly, and see what others have said. Go to the Security forum. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 minutes ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 hour ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

3 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

3 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

4 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

4 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

4 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

5 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

5 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

5 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

8 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

9 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

9 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

11 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

12 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

13 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

21 hours ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility
txtrainguy

Replying to an old topic that I'm currently facing with my CEO (who is on a Mac). Our servers are primarily Windows Servers, office is about...

1 day ago by txtrainguy on Windows Server 2008 drops the ball for Mac compatibility
k0tcs3

Sure, that makes perfect sense. Pay wrong-doers money and thank them for breaching your security and pointing out your flaws, that would surely...

1 day ago by k0tcs3 on US indicts Romanian over NASA climate change hack