News

Microsoft Products Get Security Certified

Microsoft recently took another small step in its Trustworthy Computing initiative by obtaining security certification for a number of updated products.

The offerings that gained Common Criteria certification:

  • Windows Server 2003, Standard Edition (32-bit version) with SP1
  • Windows Server 2003, Enterprise Edition (32-bit and 64-bit versions) with SP1
  • Windows Server 2003, Datacenter Edition (32-bit and 64-bit versions) with SP1
  • Windows Server 2003 Certificate Server, Certificate Issuing and Management Components (CIMC) (Security Level 3 Protection Profile, Version 1.0)
  • Windows XP Professional with SP2
  • Windows XP Embedded with SP2

    Some earlier versions of those products had already attained CC certification, but without the service pack additions. The announcement hasn’t garnered much media attention, but it should boost Microsoft’s security reputation, which continues to suffer hits over vulnerabilities in Internet Explorer.

    That’s because CC certification is independent of Microsoft. CC is an international consortium of organizations that’s established a set of common security standards it applies to products, which are submitted by companies for testing. If the products meet those standards, it’s awarded the CC certification. The higher the certification level, the better it meets agreed-upon security guidelines. And all products, whether they be from Microsoft, Oracle, CA and so on, get tested the same way for the same level. The Microsoft products attained Evaluation Assurance Level (EAL) 4, the top level for operating systems.

    Microsoft compares favorably with other competing OS vendors. For example, Sun Solaris 9 achieved EAL 4; Mac OS X achieved EAL 3; Red Hat Enterprise Linux 3 achieved EAL 2; and SuSE Linux Enterprise Server Version 9, SP2 achieved EAL 3.

  • About the Author

    Keith Ward is the editor in chief of Virtualization & Cloud Review. Follow him on Twitter @VirtReviewKeith.

    Featured

    • Closeup of the new Copilot keyboard key

      Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

      Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

    • Windows 365 Cloud Apps Now Available for Public Preview

      Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.

    • Report: Security Initiatives Can't Keep Pace with Cloud, AI Boom

      The increasingly fast adoption of hybrid, multicloud, and AI systems is easily outgrowing existing security measures, according to a recent global survey by the Cloud Security Alliance (CSA) and exposure management firm Tenable.

    • World Map Image

      Microsoft Taps Nebius in $17B AI Infrastructure Deal To Alleviate Cloud Strain

      Microsoft has signed a five-year, $17.4 billion agreement with Amsterdam-based Nebius Group to expand its AI computing capabilities through third-party GPU infrastructure.