Nearly six and a half years ago, in the aftermath of the September 11 terrorist attacks and amid concerns about growing online threats, then-Microsoft CEO Bill Gates sent out a companywide e-mail that some consider his most important ever.
The January 15, 2002, memo was simply titled "Trustworthy Computing," and it stressed the need for Microsoft to focus on security and build more-reliable products that could withstand future threats.
"If we don't do this, people simply won't be willing -- or able -- to take advantage of all the other great work we do," Gates wrote. "Our responsiveness has been unmatched -- but as an industry leader we can and must do better."
On Monday, when Gates retires officially from Microsoft, he will leave behind a company which, by most accounts has done just that, at least on the security front.
"Gates set the vision" with his memo, said Khalid Kark an analyst at Forrester Research. According to Kark, Gates set into motion a series of fundamental changes at Microsoft and how it develops its products -- changes that have helped the company make considerable progress in addressing security issues. Windows Server 2003, released in late 2003, became the first operating system to ship after the Trustworthy Computing initiative went into effect.
Gates' memo gave marching orders to then-Microsoft Chief Technology Officer Craig Mundie and led to the creation of a costly new process at Microsoft called the Security Development Lifecycle (SDL), which was meant to ensure that security flaws were caught during the product development cycle -- not after products were released. Millions of dollars were spent to ensure that every single in-house developer went through an SDL training process.
The memo also yielded a new monthly patch delivery cycle, which despite the occasional hiccups, many consider a model in the software industry. Over the years, the memo also set the tone for a gradual thawing of the once icy relationship between Microsoft and the security research and bug-hunter community.
The memo was in many ways an acknowledgment by Gates that Microsoft's single-minded focus on ease-of-use and new features had trumped product security at a time when malicious attackers were using the Internet to lethal effect. "When we face a choice between adding features and resolving security issues, we need to choose security," Gates wrote in his memo.
"In the pre-2001 days, Gates was the biggest reason why Microsoft was having so many security problems," said John Pescatore an analyst at Gartner. "He was a market-driven guy who said that consumers didn't want more security but more ease of use.
"When Gates had his epiphany and wrote his memo, he really forced a lot of changes at Microsoft," Pescatore said. Importantly, the changes were not just at the technical level but also in the manner in which Microsoft evaluated product managers, how it reviewed product performance internally and how it decided something was ready to be released. The focus was no longer just on product functionality but also on security, he said.
While Gates' memo may have set the tone at Microsoft, it did little immediately to change public perceptions about the insecurity of Microsoft's enterprise products, Kark said. In fact, the company has had a harder time than it probably expected convincing buyers that the changes it implemented have resulted in more-secure products, he said.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Achieving the impossible: Unlimited application scalability
Taking On Demand CRM Integration to the Next Level
How to improve employee productivity in small and medium businesses
Discover the advantages of an open architecture multi-vendor network solution
Strategies for Eliminating .PST Files
Controlling storage costs with Oracle database 11g
Best Practice in Building an Integrated Information Management Strategy
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
AOC Launches 18.5” Widescreen Green 16:9 LCD Monitor in Australia and New Zealand 2008-12-03 15:30:00+11
FrontRange Solutions eases software license management with new License Manager 3.0 2008-12-03 14:56:00+11
Progress Software's Cure for Managing Services-based Applications 2008-12-03 14:42:00+11
S3 Graphics Unleashes Full OpenGL® 3.0 API Support with Beta Driver for Chrome 500 Series GPUs 2008-12-03 14:08:00+11
Informatica Powercenter added to Nec Infoframe Solution Suite 2008-12-03 11:36:00+11
Taking On Demand CRM Integration to the Next Level
Discover the current integration challenges facing businesses attempting to deploy on demand CRM systems. Learn how to create comprehensive integration of your data, user interface and business process levels and transform a portfolio of disparate applications into a unified, virtual application suite.












