- Recommend:
- 0 Comments
Windows 2000 Security Recognized
Government certification a first for a Microsoft operating system, bolstering Trustworthy Computing effort.
After a nearly three-year process, Microsoft says Windows 2000 has been certified as secure through an evaluation process developed through the cooperative efforts of 15 national governments worldwide.
The certification means Windows 2000 with Service Pack 3 can be used as part of sensitive government security systems without buyers having to get special waivers from the National Security Agency or pass additional testing. Those security systems would be handling sensitive or classified data at government agencies including the U.S. Department of Defense and civilian contractors.
The certification does not mean the software is now bulletproof, but means the testing has confirmed the code is working as advertised.
Tough Evaluation
Microsoft admitted that the certification has no direct implications for non-government users beyond the awareness that the software has passed the test. But the company says that fact is confirmation that the vendor has been working hard on security even before it announced its Trustworthy Computing initiative in January.
"This is a demonstration that many aspects of the things that lead to trust, security being a notable one, are things that we have paying attention to for some period of time," said Craig Mundie, Microsoft chief technology officer. "For people who have concerns on an ongoing basis about our level of investment or focus on these questions about all the things that ultimately lead to security in computer systems, this is pretty strong testimony to the level of effort we have been applying."
The security certification is defined by the Common Criteria for Information Technology Security Evaluation (CCITSE), which is known in government circles as Common Criteria certification. The CC certification is a globally recognized ISO standard for evaluating security features in computer software.
Nearly 75 products have passed the CC evaluation. SGI in June of this year had its Trusted IREX 6.5 and its standard IREX 6.5 operating system certified. Sun has had two versions of its operating system CC certified. Solaris 8 was certified, as was a "trusted" version with strong access control, security labels and software compartmentalization. Oracle has had versions 7, 8, and 8i of its database evaluated and certified.
Those products along with Windows 2000 received an Evaluation Assurance Level 4 (EAL4), which is described as "the highest level at which it is likely to be economically feasible to retrofit to an existing application." As part of the evaluation, source code is examined and the vendor has to be prepared to "incur additional security-specific engineering."
EAL4 is the highest CC certification level doled out for the 75 products tested to date, and is the highest level that's recognized by all CC country signatories. Above that, vendors are likely to see specific demands from individual countries.
Although complex to decipher, the EAL scheme basically says EAL1 is appropriate when requirements for security are "not serious." EAL2 ups the ante in asking the product developer for design information and testing "consistent with good commercial practice." At EAL3, the product is going to be "methodically tested and checked" in a CC-accredited lab in a search "for obvious vulnerabilities."
Costly Process
Mundie said the certification process cost Microsoft "many millons of dollars," but would not disclose a specific amount. Other companies have reported similar costs. The independent evaluation was performed by the Science Applications International Common Criteria testing lab, which is one of two-dozen certified and accredited to perform the testing.
Windows 2000 is the first Microsoft product to be CC certified. Mundie said Windows XP and Windows .Net Server would also be put through the certification process. He said SQL Server, which is currently certified as C2 under the government's Orange Book system, is not currently slated to be submitted for CC evaluation.
Microsoft also went a step further, including certification of a number of services within the operating system including multi-master directory services, L2TP/IPSec-based virtual private networking, and single sign-on.
To supplement the CC certification, Microsoft will introduce resource materials and tools to provide guidance in the deployment and operation of Windows 2000 in secure network environments.
The company also received the highest level of Systematic Flaw Remediation certification for Window 2000 as issued by the National Information Assurance Partnership (NIAP). The certification means that the Microsoft Security Response Center (MSRC) meets the requirements for tracking and fixing problems with the software.
Microsoft officials say no other company has certified a procedure for ongoing software maintenance.
For more information about enterprise networking, go to NetworkWorld. Story copyright 2011 Network World Inc. All rights reserved.
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
Speed Up Everything!
PCWorld shows you the secrets to improve performance on all your hardware.
-
Stellar Tech Deals
Don't miss out on great deals from around the web.
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- Windows 8 Beta Expected in Early 2012
- BlackBerry OS Achieves Coveted Government Security Clearance
- Ashampoo WinOptimizer 8
- Windows XP: Pros and Cons of Not Upgrading
- Will Windows 8 PCs Shut the Door on Linux?
- Linux and Windows 8's Secure Boot: What We Know So Far
- 5 Things You May Have Missed About Windows Phone
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.

















