'Trustworthy' plan plods uphill
Computerworld - Wednesday will mark the one-year anniversary of the day that Bill Gates decreed, via a companywide memo, that "Trustworthy Computing" would be the highest priority for all the work Microsoft Corp. employees do (see story).
Plenty of hurdles still lie ahead for Microsoft as it tries to strike the proper balance between ensuring the security of its software and pushing out the sort of innovative, increasingly scalable and more complex products it needs to keep its business thriving.
"There is always a trade-off between new functionality and security exposures, and a perfect example of that is BSD," said Andre Mendes, chief technology integration officer at the Public Broadcasting Service, referring to the BSD Unix operating system. "It is fairly secure, but it is also fairly devoid of any but the simplest of operating system functionality."
Craig Mundie, chief technical officer of advanced strategies and policy at Microsoft, likened the technological challenge Microsoft faces to "chasing a rocket ship."
"We continue to scale up the capability of the systems. As they get bigger and bigger, complexity mounts, and to some extent, those things all work against the idea that, well, can we really get this thing stabilized and improved?" Mundie said. He said he worries about maintaining the balance "between having to make the product and the business go forward and trying to lock it all down."
"If things weren't moving, it would be easier," Mundie said. "But they have to keep moving, or there would be no business."
Looking at it from a business management standpoint, he noted the challenges the company faces in coming up with audit measurements to ensure that "the effort doesn't dissipate," especially since it could take 10 to 20 years to achieve technological success. Yet another problem is the testing issues the company confronts when it decides that it needs to make a security fix that will affect a system as large as Windows, Mundie said.
Several IT managers said they think Microsoft's Trustworthy Computing progress should be judged based on the number of vulnerabilities they see in future releases. But many customers may continue to use older products that haven't been the focal point of Microsoft's security push.
"In the short term, I'm resigned to an increasing cycle of patches and updates to existing systems that my already overwhelmed technicians have to implement," said Paul Lanham, senior vice president and chief technology officer at Jones Apparel Group Inc. in Bristol, Pa. "I'm hoping that the next generation of products from Microsoft addresses these issues so that there is a reasonable balance between the features that customers insist upon and basic security measures in the products offered."



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- VMware View Optimization Guide for Windows 7
- This document provides guidelines for configuring a standard Windows 7 image to be used within a VMware View™ environment, providing administrators with the...
- Watson - A System Designed for Answers. The future of workload optimized systems design
- Watson is a workload optimized system designed for complex analytics, made possible by integrating massively parallel POWER7 processors and DeepQA technology. Read the...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring... All Operating Systems White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Operating Systems Webcasts