<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Forefront Client Security Team Blog : SSA</title><link>http://blogs.technet.com/clientsecurity/archive/tags/SSA/default.aspx</link><description>Tags: SSA</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Security State Assessment goes live on MU!</title><link>http://blogs.technet.com/clientsecurity/archive/2007/07/24/security-state-assessment-goes-live-on-mu.aspx</link><pubDate>Tue, 24 Jul 2007 20:34:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1597898</guid><dc:creator>AdrienneWu</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/clientsecurity/comments/1597898.aspx</comments><wfw:commentRss>http://blogs.technet.com/clientsecurity/commentrss.aspx?PostID=1597898</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;My name is Adrienne Wu, and I’m a Program Manager on the Forefront Client Security (FCS) team. When I first started here at Microsoft, I was an intern and I worked on the early planning for what would eventually become Security State Assessment, or SSA. When I returned as a full-time employee, I continued this work, only instead of a plan, it had become a reality!&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;Today is an interesting day for me; it is the day our original goal for SSA will truly be realized.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;With SSA, we wanted to provide visibility into critical vulnerabilities and configuration exposures on managed computers, enabling our customers to focus critical IT resources on the right security issues. Our solution was to include an SSA agent to scan and report on the security state of a computer, with security checks driving evaluations.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;We achieved this goal, and Forefront Client Security 1.0 shipped with some great checks out of the box.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;But we also wanted to be able to provide new checks, so that we could continue to extend, over time, the vulnerability coverage provided by SSA. We decided to implement our checks using a definitions file, which could be published to Microsoft Update, and downloaded much like antimalware signatures.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;Today, we’ve published our first new check using this channel.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;The Unapproved Updates check determines whether there are any missing Microsoft security updates that have not yet been approved. The Security Updates check, which is already included in SSA, scans for missing updates available through the default service registered with Automatic Update. For example, updates approved on WSUS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;The Unapproved Updates check scans against Microsoft Update, and determines if there are any missing updates that are available, but not approved for download. The score from this check doesn’t contribute to the number of computers reporting critical issues in the FCS console, but the results will show up in reports, and administrators can see how many computers are vulnerable while a required security update undergoes their company’s approval process.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;So if you’re using Forefront Client Security, take a look at your Deployment Summary. You should see your managed clients updating to vulnerability definition version 1.0.1709.0. The definition download should also be appearing on your WSUS server. In your Security State Assessment Summary report, you should start to see results from the Unapproved Updates check.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;You can learn more about the check in our &lt;A class="" title="Technical Reference" href="http://go.microsoft.com/fwlink/?LinkId=85056" target=_blank mce_href="http://go.microsoft.com/fwlink/?LinkId=85056"&gt;Technical Reference&lt;/A&gt;&amp;nbsp;on the Forefront Client Security TechCenter.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;We’ll have more checks to come, and I hope you’ll be as excited as we are to see new checks coming down from MU!&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;o:p&gt;&lt;FONT face=Calibri size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;Adrienne Wu&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;Program Manager&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 20.15pt 0pt 0.2in"&gt;&lt;FONT face=Calibri size=3&gt;Microsoft Forefront Client Security&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1597898" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/clientsecurity/archive/tags/SSA/default.aspx">SSA</category></item></channel></rss>