By Tim Wilson
DarkReading
May 06, 2010
The chief security officers at major federal agencies are worried about the threats currently faced by their organizations, and many of them don't think have the resources they need to defend against them, according to a study published today.
In a report compiled by Cisco and (ISC)2, only half of federal CSOs think they have a significant ability to affect the security posture of their agencies. Half of the CSOs say their postures have improved since 2009; 28 percent feel that things are worse, and approximately 20 percent feel that no change has occurred.
Twenty-seven percent of federal CSOs say software vulnerabilities are the most severe threat to their agencies; 24 percent cited insider threats. Only 21 percent cited threats from foreign nation-states as the most severe threat to their agencies.
Yet federal CSOs are feeling the pressure to do more on the political side than on the technical side, the study says. More than half (54
percent) say their jobs are becoming more political/policy-oriented, while 51 percent say their jobs are becoming more managerial in nature.
Only 26 percent said their duties are becoming more technical.
"The nature of their jobs is changing," says Lynn McNulty, (ISC)2's director of government affairs. "What they do is becoming much more policy-oriented, and their duties are becoming less technical and more managerial."
[...]
Friday, 7 May 2010
Hacker develops multi-platform rootkit for ATMs
By Robert McMillan
IDG News Service
May 5, 2010
One year after his Black Hat talk on Automated Teller Machine security vulnerabilities was yanked by his employer, security researcher Barnaby Jack plans to deliver the talk and disclose a new ATM rootkit at the computer security conference.
He plans to give the talk, entitled "Jackpotting Automated Teller Machines," at the Black Hat Las Vegas conference, held July 28 and 29.
Jack will demonstrate several ways of attacking ATM machines, including remote, network-based attacks. He will also reveal a "multi-platform ATM rootkit," and will discuss things that the ATM industry can do to protect itself from such attacks, he writes in his description of the talk, posted this week to the Black Hat Web site.
Jack was set to discuss ATM security problems at last year's conference, but his employer, Juniper Networks, made him pull the presentation after getting complaints from an ATM maker that was worried that the information he had discovered could be misused.
The security researcher found a straightforward way of getting around Juniper's objections, however. Last month, he took a new job as director of security research with IOActive.
[...]
IDG News Service
May 5, 2010
One year after his Black Hat talk on Automated Teller Machine security vulnerabilities was yanked by his employer, security researcher Barnaby Jack plans to deliver the talk and disclose a new ATM rootkit at the computer security conference.
He plans to give the talk, entitled "Jackpotting Automated Teller Machines," at the Black Hat Las Vegas conference, held July 28 and 29.
Jack will demonstrate several ways of attacking ATM machines, including remote, network-based attacks. He will also reveal a "multi-platform ATM rootkit," and will discuss things that the ATM industry can do to protect itself from such attacks, he writes in his description of the talk, posted this week to the Black Hat Web site.
Jack was set to discuss ATM security problems at last year's conference, but his employer, Juniper Networks, made him pull the presentation after getting complaints from an ATM maker that was worried that the information he had discovered could be misused.
The security researcher found a straightforward way of getting around Juniper's objections, however. Last month, he took a new job as director of security research with IOActive.
[...]
Tuesday, 4 May 2010
Federal mortgage watchdog agency struggles with its information security
By William Jackson
GCN.com
May 03, 2010
The Federal Housing Finance Agency, a fledgling organization created in
2008 to oversee federal mortgage activities, has not fully implemented an information security program, resulting in weaknesses in its information technology security, according to the Government Accountability Office.
"FHFA has made important progress in developing and documenting its policies and procedures for the agency's information security program,"
GAO concluded in its report. "However, policies, procedures, plans, and technical standards related to information security did not always reflect the current agency operating environment; and FHFA did not always effectively monitor its systems."
GAO found that FHFA did not always maintain authorization records for network and system access, and did not enforce least-privilege policies for system and application users. It also did not have adequate physical security and environmental safety controls for facilities housing IT resources.
"Until the agency strengthens its logical access and physical access controls and fully implements an information security program that includes policies and procedures reflecting the current agency environment, increased risk exists that sensitive information and resources will not be sufficiently protected from inadvertent or deliberate misuse, improper disclosure, or destruction," GAO concluded.
[...]
GCN.com
May 03, 2010
The Federal Housing Finance Agency, a fledgling organization created in
2008 to oversee federal mortgage activities, has not fully implemented an information security program, resulting in weaknesses in its information technology security, according to the Government Accountability Office.
"FHFA has made important progress in developing and documenting its policies and procedures for the agency's information security program,"
GAO concluded in its report. "However, policies, procedures, plans, and technical standards related to information security did not always reflect the current agency operating environment; and FHFA did not always effectively monitor its systems."
GAO found that FHFA did not always maintain authorization records for network and system access, and did not enforce least-privilege policies for system and application users. It also did not have adequate physical security and environmental safety controls for facilities housing IT resources.
"Until the agency strengthens its logical access and physical access controls and fully implements an information security program that includes policies and procedures reflecting the current agency environment, increased risk exists that sensitive information and resources will not be sufficiently protected from inadvertent or deliberate misuse, improper disclosure, or destruction," GAO concluded.
[...]
Laptop stolen from mammo suite with data on 5,400 patients
By Editorial Staff
HealthImaging.com
May 2, 2010
The Medical Center in Bowling Green, Ky., is currently notifying 5,418 patients of a breach of personal protected health information, resulting from the theft of computer equipment from its mammography suite containing information on patients who underwent bone density testing between 1997 and 2009.
At this point the provider said it had no reason to believe the device was stolen for the information on it or that any personal information has been released or used.
On April 1, the Medical Center said it discovered that the laptop had been stolen from its mammography suite. Upon learning of the theft, the facility launched an investigation of the incident, and the theft has been reported to the Bowling Green Police Department.
The facility has since discovered the data on the device included each patient's name, date of birth, address, medical record number and physician name. Some patients' records also included information, such as social security numbers, weight, height and menopause age. The data on the hard drive was not encrypted; however, the hard drive was maintained in a locked, non-public, private area, according to the hospital.
[...]
HealthImaging.com
May 2, 2010
The Medical Center in Bowling Green, Ky., is currently notifying 5,418 patients of a breach of personal protected health information, resulting from the theft of computer equipment from its mammography suite containing information on patients who underwent bone density testing between 1997 and 2009.
At this point the provider said it had no reason to believe the device was stolen for the information on it or that any personal information has been released or used.
On April 1, the Medical Center said it discovered that the laptop had been stolen from its mammography suite. Upon learning of the theft, the facility launched an investigation of the incident, and the theft has been reported to the Bowling Green Police Department.
The facility has since discovered the data on the device included each patient's name, date of birth, address, medical record number and physician name. Some patients' records also included information, such as social security numbers, weight, height and menopause age. The data on the hard drive was not encrypted; however, the hard drive was maintained in a locked, non-public, private area, according to the hospital.
[...]
data loss weekly summary
Open Security Foundation - DataLossDB Weekly Summary Week of Sunday, April 25, 2010
11 Incidents Added.
========================================================================
DataLossDB is a research project aimed at documenting known and reported data loss incidents world-wide. The Open Security Foundation asks for contributions of new incidents and new data for existing incidents. For any questions about the project or the data contained within this email or the website (http://www.datalossdb.org), please contact us at curators@datalossdb.org.
========================================================================
DataLossDB News/Updates
No news this week!
========================================================================
Incidents Added
Reported Date: 2010-04-29
Summary: Stolen computers expose 20,000 patients names, dates of birth and Social Security numbers
Organizations: St. Jude Heritage Medical Center
http://datalossdb.org/incidents/2759
---------------------
Reported Date: 2010-04-28
Summary: Payroll services company erroneously merges two organizations' data, exposing names, Social Security numbers, and benefits information of employees
Organizations: Paychex
http://datalossdb.org/incidents/2757
---------------------
Reported Date: 2010-04-28
Summary: Stolen hard drive exposes 5,418 patients names, addresses, dates of birth, and medical numbers
Organizations: The Medical Center at Bowling Green
http://datalossdb.org/incidents/2758
---------------------
Reported Date: 2010-04-28
Summary: Employee accidentally emails students names, addresses and Social Security numbers
Organizations: Montana Tech of The University of Montana
http://datalossdb.org/incidents/2756
---------------------
Reported Date: 2010-04-26
Summary: Email attachment exposes 33 students email including names, GPAs and student ID numbers
Organizations: University of Wisconsin - Milwaukee
http://datalossdb.org/incidents/2750
---------------------
Reported Date: 2010-04-26
Summary: Employee steals at least 70 adoptive and foster parents personal details
Organizations: Texas Child Protective Services Division
http://datalossdb.org/incidents/2751
---------------------
Reported Date: 2010-04-26
Summary: Hundreds of patients medical files dumped outside closed office exposing names, addresses, Social Security numbers
Organizations: DRC Physical Therapy Plus
http://datalossdb.org/incidents/2749
---------------------
Reported Date: 2010-04-23
Summary: Data backup inadvertently sent to an unauthorized storage source
Organizations: ESB Financial
http://datalossdb.org/incidents/2754
---------------------
Reported Date: 2008-12-08
Summary: Lost Computer contained personal information
Organizations: YMCA of Metropolitan Los Angeles
http://datalossdb.org/incidents/2752
---------------------
Reported Date: 2008-05-02
Summary: Problem with data processing caused mail documents to goto wrong customers
Organizations: Sterling Jewlers Inc.
http://datalossdb.org/incidents/2753
---------------------
Reported Date: 2008-02-12
Summary: Individual found to have copies of confidential documents including personal information.
Organizations: Marlborough Hospital
http://datalossdb.org/incidents/2755
---------------------
========================================================================
Blotter Posts
Added: 2010-05-01
Title: Palin hacker found guilty on two counts http://feedproxy.google.com/~r/SCMagazineHome/~3/wKD2hi43Ugw/
---------------------
Added: 2010-04-29
Title: Report: Palin e-mail snooping jury deadlocked http://www.computerworld.com/s/article/9176146/Report_Palin_e_mail_snooping_jury_deadlocked?source=rss_networking
---------------------
Added: 2010-04-29
Title: Medicare scam makes the rounds statewide http://blog.dispatch.com/wallet/2010/04/medicare_scam_makes_the_rounds.shtml
---------------------
Added: 2010-04-29
Title: How Data Laws Slap Insecure Companies http://www.forbes.com/2010/04/27/breach-disclosure-data-technology-security-laws.html?feed=rss_home
---------------------
Added: 2010-04-29
Title: Washington driver license changing to protect IDs http://seattletimes.nwsource.com/html/localnews/2011720527_apwadriverlicensechange.html?syndication=rss
---------------------
Added: 2010-04-27
Title: US court sentences Indian to 81 months in prison http://timesofindia.indiatimes.com/World-Indians-Abroad/US-court-sentences-Indian-to-81-months-in-prison/articleshow/5862167.cms
---------------------
Added: 2010-04-27
Title: Vets use settlement millions from identity-theft suit against VA to help other vets http://feeds.nydailynews.com/~r/nydnrss/news/~3/3ktvti24xvc/2010-04-27_vets_use_settlement_millions_to_help_vets.html
---------------------
Added: 2010-04-27
Title: Tidal wave of ID theft fraud sweeps the UK, survey reveals http://www.computerweekly.com/Articles/2010/04/26/241034/tidal-wave-of-id-theft-fraud-sweeps-the-uk-survey-reveals.htm
---------------------
Added: 2010-04-27
Title: How Well Do Hospitals Protect Your Data? Abysmally
http://feeds.informationweek.com/click.phdo?i=aaa3646e7ef5598a22fdf42cc604f880
---------------------
_______________________________________________
Dataloss Mailing List (dataloss@datalossdb.org)
CREDANT Technologies, a leader in data security, offers advanced data encryption solutions.
Protect sensitive data on desktops, laptops, smartphones and USB sticks transparently across your enterprise to ensure regulatory compliance.
http://www.credant.com/stopdataloss
11 Incidents Added.
========================================================================
DataLossDB is a research project aimed at documenting known and reported data loss incidents world-wide. The Open Security Foundation asks for contributions of new incidents and new data for existing incidents. For any questions about the project or the data contained within this email or the website (http://www.datalossdb.org), please contact us at curators@datalossdb.org.
========================================================================
DataLossDB News/Updates
No news this week!
========================================================================
Incidents Added
Reported Date: 2010-04-29
Summary: Stolen computers expose 20,000 patients names, dates of birth and Social Security numbers
Organizations: St. Jude Heritage Medical Center
http://datalossdb.org/incidents/2759
---------------------
Reported Date: 2010-04-28
Summary: Payroll services company erroneously merges two organizations' data, exposing names, Social Security numbers, and benefits information of employees
Organizations: Paychex
http://datalossdb.org/incidents/2757
---------------------
Reported Date: 2010-04-28
Summary: Stolen hard drive exposes 5,418 patients names, addresses, dates of birth, and medical numbers
Organizations: The Medical Center at Bowling Green
http://datalossdb.org/incidents/2758
---------------------
Reported Date: 2010-04-28
Summary: Employee accidentally emails students names, addresses and Social Security numbers
Organizations: Montana Tech of The University of Montana
http://datalossdb.org/incidents/2756
---------------------
Reported Date: 2010-04-26
Summary: Email attachment exposes 33 students email including names, GPAs and student ID numbers
Organizations: University of Wisconsin - Milwaukee
http://datalossdb.org/incidents/2750
---------------------
Reported Date: 2010-04-26
Summary: Employee steals at least 70 adoptive and foster parents personal details
Organizations: Texas Child Protective Services Division
http://datalossdb.org/incidents/2751
---------------------
Reported Date: 2010-04-26
Summary: Hundreds of patients medical files dumped outside closed office exposing names, addresses, Social Security numbers
Organizations: DRC Physical Therapy Plus
http://datalossdb.org/incidents/2749
---------------------
Reported Date: 2010-04-23
Summary: Data backup inadvertently sent to an unauthorized storage source
Organizations: ESB Financial
http://datalossdb.org/incidents/2754
---------------------
Reported Date: 2008-12-08
Summary: Lost Computer contained personal information
Organizations: YMCA of Metropolitan Los Angeles
http://datalossdb.org/incidents/2752
---------------------
Reported Date: 2008-05-02
Summary: Problem with data processing caused mail documents to goto wrong customers
Organizations: Sterling Jewlers Inc.
http://datalossdb.org/incidents/2753
---------------------
Reported Date: 2008-02-12
Summary: Individual found to have copies of confidential documents including personal information.
Organizations: Marlborough Hospital
http://datalossdb.org/incidents/2755
---------------------
========================================================================
Blotter Posts
Added: 2010-05-01
Title: Palin hacker found guilty on two counts http://feedproxy.google.com/~r/SCMagazineHome/~3/wKD2hi43Ugw/
---------------------
Added: 2010-04-29
Title: Report: Palin e-mail snooping jury deadlocked http://www.computerworld.com/s/article/9176146/Report_Palin_e_mail_snooping_jury_deadlocked?source=rss_networking
---------------------
Added: 2010-04-29
Title: Medicare scam makes the rounds statewide http://blog.dispatch.com/wallet/2010/04/medicare_scam_makes_the_rounds.shtml
---------------------
Added: 2010-04-29
Title: How Data Laws Slap Insecure Companies http://www.forbes.com/2010/04/27/breach-disclosure-data-technology-security-laws.html?feed=rss_home
---------------------
Added: 2010-04-29
Title: Washington driver license changing to protect IDs http://seattletimes.nwsource.com/html/localnews/2011720527_apwadriverlicensechange.html?syndication=rss
---------------------
Added: 2010-04-27
Title: US court sentences Indian to 81 months in prison http://timesofindia.indiatimes.com/World-Indians-Abroad/US-court-sentences-Indian-to-81-months-in-prison/articleshow/5862167.cms
---------------------
Added: 2010-04-27
Title: Vets use settlement millions from identity-theft suit against VA to help other vets http://feeds.nydailynews.com/~r/nydnrss/news/~3/3ktvti24xvc/2010-04-27_vets_use_settlement_millions_to_help_vets.html
---------------------
Added: 2010-04-27
Title: Tidal wave of ID theft fraud sweeps the UK, survey reveals http://www.computerweekly.com/Articles/2010/04/26/241034/tidal-wave-of-id-theft-fraud-sweeps-the-uk-survey-reveals.htm
---------------------
Added: 2010-04-27
Title: How Well Do Hospitals Protect Your Data? Abysmally
http://feeds.informationweek.com/click.phdo?i=aaa3646e7ef5598a22fdf42cc604f880
---------------------
_______________________________________________
Dataloss Mailing List (dataloss@datalossdb.org)
CREDANT Technologies, a leader in data security, offers advanced data encryption solutions.
Protect sensitive data on desktops, laptops, smartphones and USB sticks transparently across your enterprise to ensure regulatory compliance.
http://www.credant.com/stopdataloss
Hacked US Treasury websites serve visitors malware
By Dan Goodin in San Francisco
The Register
3rd May 2010
Updated - Websites operated by the US Treasury Department are redirecting visitors to websites that attempt to install malware on their PCs, a security researcher warned on Monday.
The infection buries an invisible iframe in bep.treas.gov, moneyfactory.gov, and bep.gov that invokes malicious scripts from grepad.com, Roger Thompson, chief research officer of AVG Technologies, told The Register. The code was discovered late Sunday night and was active at time of writing, about 12 hours later.
To cover their tracks, the miscreants behind the compromise tailored it so it attacks only IP addresses that haven't already visited the Treasury websites. That makes it harder for white hat-hackers and law enforcement agents to track the exploit. Indeed, Thompson initially reported that the problem had been fixed until he discovered the sites were merely skipping over laboratory PCs that had already encountered the attack.
The attack is most likely related to mass infections that two weeks ago hit hundreds of sites hosted by Network Solutions and GoDaddy, said Dean De Beer, founder and CTO of security consultancy Zero(day) Solutions.
[...]
The Register
3rd May 2010
Updated - Websites operated by the US Treasury Department are redirecting visitors to websites that attempt to install malware on their PCs, a security researcher warned on Monday.
The infection buries an invisible iframe in bep.treas.gov, moneyfactory.gov, and bep.gov that invokes malicious scripts from grepad.com, Roger Thompson, chief research officer of AVG Technologies, told The Register. The code was discovered late Sunday night and was active at time of writing, about 12 hours later.
To cover their tracks, the miscreants behind the compromise tailored it so it attacks only IP addresses that haven't already visited the Treasury websites. That makes it harder for white hat-hackers and law enforcement agents to track the exploit. Indeed, Thompson initially reported that the problem had been fixed until he discovered the sites were merely skipping over laboratory PCs that had already encountered the attack.
The attack is most likely related to mass infections that two weeks ago hit hundreds of sites hosted by Network Solutions and GoDaddy, said Dean De Beer, founder and CTO of security consultancy Zero(day) Solutions.
[...]
Sunday, 2 May 2010
Microsoft: 'Prepare for 15 billion more clients'
If you're an IT professional, Microsoft made an announcement last week that may increase both your capital expenditures budget and your job security.
At the Embedded Systems Conference (ESC) in San José, California, Microsoft announced that the latest version of its OS for embedded systems, Windows Embedded Standard 7, had graduated to RTM status.
"Embedded systems?" you might say. "I manage servers, PCs, and laptops - I care not a whit for an OS that runs ATMs, fuel pumps, kiosks, in-car entertainment systems, and the like."
Microsoft thinks you should care. "For an IT professional, it's now becoming critical that you think through how to be able to manage, provision, monitor, and provide security to [embedded] devices just like you do today with a laptop or a PC," says Kevin Dallas, GM of Microsft's embedded unit. "That's the radical change that is starting to happen, and that's the future that we're building to."
Dallas' suggestion that you add embedded devices to your worry list is due to the fact that Windows Embedded Standard 7 is in essence a "componentized" version of Windows 7 that can provide all the internet connectivity of that operating system. And when your share of billions of internet-capable embedded devices start to communicate with your company's servers, you'll be the one who'll be told to manage them.
And, yes, we said billions. As the VP of Microsoft's OEM division Steve Guggenheimer noted in a recent blog post, the Artemis Embedded Computing Initiative estimates that there will be over 40 billion embedded devices by 2020. Intel's embedded chieftain Doug Davis has cited an IDC prediction that 15 billion embedded devices will be internet-connected by 2015.
"These devices will significantly outnumber the number of PCs, which will be in the hundreds of millions; will outnumber the number of TVs, which will be in the tens of millions; will outnumber the number of mobile phones that are shipped," Microsoft's Dallas told his audience at an ESC keynote.
Understandably, Dallas hopes that a sizable chunk of internet-enabled embedded devices will be built around Windows Embedded Standard 7. And Microsoft's offering has a few things going for it that may entice OEMs to use it in the specialized embedded systems that may one day be connected to your company's servers.
For one, as we mentioned above, it's "componentized" - meaning that Windows Embedded Standard 7 is essentially Windows 7 broken down into over 200 components that an OEM can assemble in any combination that works for their device. Among those components, of course, are internet-connectivity services.
As Dallas put it: "All the benefits of Windows 7 in the PC, laptop, netbook, and server arena can now be extended into the specialized devices space, into the embedded space."
The good news, from Dallas' point of view, is that since Windows Embedded Standard 7 is at heart Windows 7, all of the Microsoft back-end services that IT pros now use will be available to manage embedded devices.
"These devices need to connect seamlessly to back-end services. These services can range from management, to System Center, be able to participate in an Active Directory so you can set policies, you can push out software updates," he said.
He also cited some of Windows Embedded Standard 7's other virtues. "Agile VPN that really drives a more reliable VPN connection that can actually take advantage of multiple network paths. Also, you can build redundancy into your overall network with fail-over clustering - another feature that works in concert with Windows Server 2008 R2. We have the latest Remote Desktop client, RDP 7, also included in this, which supports one of the virtual-computing thin-client scenarios."
Irena Andonova, an exec in Microsoft's Embedded Windows and Enterprise Devices division, was even more direct about the new embedded OS's ability to work with existing management systems. "What is really, really important for us is for the enterprise customers to know that they can rely on the same infrastructure investment that they have made, therefore driving their TCO down by managing their devices in the same manner that they manage their PCs or servers, using the same technologies, plugging into the same existing infrastructure," she told us.
Andonova was ready with examples. "You want to bring in web services? You want to feed in data into SQL Server? Sure, we can do that. You want to read data from SQL Server? Sure, we can do that. Business intelligence where it makes sense? We'll take care of that."
The business intelligence information that embedded devices might provide to managers could include customer-specific data from point-of sale systems, machine-usage stats from production lines, real-time worldwide supply-chain analysis, and so on.
"These specialized devices are becoming mission-critical," Dallas explained. "Critical in terms of the tasks that they perform, but also critical in terms of the information that they can deliver back to that enterprise in terms of business intelligence. And...because you have that business intelligence, you can drive additional revenues."
And some of those additional revenues would reasonably be spent on the additional infrastructure needed to support some of those 15 billion internet-connected devices by 2015. Maybe some might be used to hire more IT staff.
"Raises?" you may ask. Sorry, but Windows Embedded Standard 7 can only do so much.
At the Embedded Systems Conference (ESC) in San José, California, Microsoft announced that the latest version of its OS for embedded systems, Windows Embedded Standard 7, had graduated to RTM status.
"Embedded systems?" you might say. "I manage servers, PCs, and laptops - I care not a whit for an OS that runs ATMs, fuel pumps, kiosks, in-car entertainment systems, and the like."
Microsoft thinks you should care. "For an IT professional, it's now becoming critical that you think through how to be able to manage, provision, monitor, and provide security to [embedded] devices just like you do today with a laptop or a PC," says Kevin Dallas, GM of Microsft's embedded unit. "That's the radical change that is starting to happen, and that's the future that we're building to."
Dallas' suggestion that you add embedded devices to your worry list is due to the fact that Windows Embedded Standard 7 is in essence a "componentized" version of Windows 7 that can provide all the internet connectivity of that operating system. And when your share of billions of internet-capable embedded devices start to communicate with your company's servers, you'll be the one who'll be told to manage them.
And, yes, we said billions. As the VP of Microsoft's OEM division Steve Guggenheimer noted in a recent blog post, the Artemis Embedded Computing Initiative estimates that there will be over 40 billion embedded devices by 2020. Intel's embedded chieftain Doug Davis has cited an IDC prediction that 15 billion embedded devices will be internet-connected by 2015.
"These devices will significantly outnumber the number of PCs, which will be in the hundreds of millions; will outnumber the number of TVs, which will be in the tens of millions; will outnumber the number of mobile phones that are shipped," Microsoft's Dallas told his audience at an ESC keynote.
Understandably, Dallas hopes that a sizable chunk of internet-enabled embedded devices will be built around Windows Embedded Standard 7. And Microsoft's offering has a few things going for it that may entice OEMs to use it in the specialized embedded systems that may one day be connected to your company's servers.
For one, as we mentioned above, it's "componentized" - meaning that Windows Embedded Standard 7 is essentially Windows 7 broken down into over 200 components that an OEM can assemble in any combination that works for their device. Among those components, of course, are internet-connectivity services.
As Dallas put it: "All the benefits of Windows 7 in the PC, laptop, netbook, and server arena can now be extended into the specialized devices space, into the embedded space."
The good news, from Dallas' point of view, is that since Windows Embedded Standard 7 is at heart Windows 7, all of the Microsoft back-end services that IT pros now use will be available to manage embedded devices.
"These devices need to connect seamlessly to back-end services. These services can range from management, to System Center, be able to participate in an Active Directory so you can set policies, you can push out software updates," he said.
He also cited some of Windows Embedded Standard 7's other virtues. "Agile VPN that really drives a more reliable VPN connection that can actually take advantage of multiple network paths. Also, you can build redundancy into your overall network with fail-over clustering - another feature that works in concert with Windows Server 2008 R2. We have the latest Remote Desktop client, RDP 7, also included in this, which supports one of the virtual-computing thin-client scenarios."
Irena Andonova, an exec in Microsoft's Embedded Windows and Enterprise Devices division, was even more direct about the new embedded OS's ability to work with existing management systems. "What is really, really important for us is for the enterprise customers to know that they can rely on the same infrastructure investment that they have made, therefore driving their TCO down by managing their devices in the same manner that they manage their PCs or servers, using the same technologies, plugging into the same existing infrastructure," she told us.
Andonova was ready with examples. "You want to bring in web services? You want to feed in data into SQL Server? Sure, we can do that. You want to read data from SQL Server? Sure, we can do that. Business intelligence where it makes sense? We'll take care of that."
The business intelligence information that embedded devices might provide to managers could include customer-specific data from point-of sale systems, machine-usage stats from production lines, real-time worldwide supply-chain analysis, and so on.
"These specialized devices are becoming mission-critical," Dallas explained. "Critical in terms of the tasks that they perform, but also critical in terms of the information that they can deliver back to that enterprise in terms of business intelligence. And...because you have that business intelligence, you can drive additional revenues."
And some of those additional revenues would reasonably be spent on the additional infrastructure needed to support some of those 15 billion internet-connected devices by 2015. Maybe some might be used to hire more IT staff.
"Raises?" you may ask. Sorry, but Windows Embedded Standard 7 can only do so much.
Subscribe to:
Posts (Atom)