<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet type='text/xsl' href='http://drewby.spaces.live.com/mmm2008-05-17_13.22/rsspretty.aspx?rssquery=en-US;http%3a%2f%2fdrewby.spaces.live.com%2fcategory%2fSecurity%2ffeed.rss' version='1.0'?><rss version="2.0" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:msn="http://schemas.microsoft.com/msn/spaces/2005/rss" xmlns:live="http://schemas.microsoft.com/live/spaces/2006/rss" xmlns:dcterms="http://purl.org/dc/terms/" xmlns:cf="http://www.microsoft.com/schemas/rss/core/2005" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Drewby: Security</title><description /><link>http://drewby.spaces.live.com/?_c11_BlogPart_BlogPart=blogview&amp;_c=BlogPart&amp;partqs=catSecurity</link><language>en-US</language><pubDate>Thu, 03 Jul 2008 21:09:05 GMT</pubDate><lastBuildDate>Thu, 03 Jul 2008 21:09:05 GMT</lastBuildDate><generator>Microsoft Spaces v1.1</generator><docs>http://www.rssboard.org/rss-specification</docs><ttl>60</ttl><cf:parentRSS>http://drewby.spaces.live.com/blog/feed.rss</cf:parentRSS><live:type>blogcategory</live:type><live:identity><live:id>9197700824605289741</live:id><live:alias>drewby</live:alias></live:identity><cf:listinfo><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="typelabel" label="Type" /><cf:group ns="http://schemas.microsoft.com/live/spaces/2006/rss" element="tag" label="Tag" /><cf:group element="category" label="Category" /><cf:sort element="pubDate" label="Date" data-type="date" default="true" /><cf:sort element="title" label="Title" data-type="string" /><cf:sort ns="http://purl.org/rss/1.0/modules/slash/" element="comments" label="Comments" data-type="number" /></cf:listinfo><item><title>SQL Server 2005 Tool for Row and Cell Level Security</title><link>http://drewby.spaces.live.com/Blog/cns!7FA4CC2B20EA6D0D!130.entry</link><description>&lt;p&gt;I often get asked about best practices for restricting data access at the Row and Cell level in SQL Server. Most often my answer is “I’m just a Developer Evangelist!” As of today, I have a new answer.
&lt;p&gt;The Federal practice for Microsoft Consulting Services released a toolkit for implementing Row and Cell-level security in SQL Server 2005. The toolkit includes best practices, design guidance and a tool for implementing a framework based on what type of labeling scheme you want to use.
&lt;p&gt;From the &lt;a href="http://blogs.msdn.com/federaldev/archive/2006/03/13/550585.aspx"&gt;Federal Developer Weblog&lt;/a&gt;: 
&lt;blockquote dir=ltr&gt;
&lt;p&gt;&lt;em&gt;The toolkit comes from our Federal MCS practice.  The centerpiece is a tool which allows you to logically define the security labeling scheme you wish to be used in your app's database.  Based on this, at the click of a button the tool generates an implementation of the supporting framework described in the whitepaper.  All you need to do is create a simple view over the table(s) you wish to protect.  Support for insert/update/delete is added by writing simple instead-of triggers to capture these operations.  The toolkit documentation includes extensive design guidance and examples of implementing different scenarios.  Several working code samples are included as well.&lt;/em&gt;&lt;/blockquote&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=9197700824605289741&amp;page=RSS%3a+SQL+Server+2005+Tool+for+Row+and+Cell+Level+Security&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=drewby.spaces.live.com&amp;amp;GT1=drewby"&gt;</description><comments>http://drewby.spaces.live.com/Blog/cns!7FA4CC2B20EA6D0D!130.entry#comment</comments><guid isPermaLink="true">http://drewby.spaces.live.com/Blog/cns!7FA4CC2B20EA6D0D!130.entry</guid><pubDate>Mon, 13 Mar 2006 21:09:02 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://drewby.spaces.live.com/blog/cns!7FA4CC2B20EA6D0D!130/comments/feed.rss</wfw:commentRss><wfw:comment>http://drewby.spaces.live.com/Blog/cns!7FA4CC2B20EA6D0D!130.entry#comment</wfw:comment><dcterms:modified>2006-03-13T21:09:02Z</dcterms:modified></item><item><title>Microsoft Threat Analysis &amp; Modeling Tool</title><link>http://drewby.spaces.live.com/Blog/cns!7FA4CC2B20EA6D0D!123.entry</link><description>&lt;div&gt;We held a great workshop in Columbus this past week on Security Development Lifecycle - IT. It went through Microsoft's methodology for writing secure code and preventing issues early on in the development lifecycle. &lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;The ACE team also showed their Threat Analysis &amp;amp; Modeling tool which is now in its second version. It was very impressive and looks to be useful for not only building secure software but better understanding your application through out the development lifecycle.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;I only wish it integrated with Visual Studio Team System a little more. I talked with Anil from the ACE team a bit about ideas to integrate and he shared that they are working with the VSTS team for a future more integrated version.&lt;/div&gt;
&lt;div&gt; &lt;/div&gt;
&lt;div&gt;It looks like the tool is ready for customers, but I still don't see the link. In the meantime, you can check out a &lt;a href="http://blogs.msdn.com/threatmodeling/archive/2006/03/10/548051.aspx"&gt;video over at the Threat Modeling blog&lt;/a&gt;.&lt;/div&gt;&lt;img src="http://c.services.spaces.live.com/CollectionWebService/c.gif?cid=9197700824605289741&amp;page=RSS%3a+Microsoft+Threat+Analysis+%26+Modeling+Tool&amp;referrer=" width="1px" height="1px" border="0" alt=""&gt;&lt;img style="position:absolute" alt="" width="0px" height="0px" src="http://c.live.com/c.gif?NC=31263&amp;amp;NA=1149&amp;amp;PI=73329&amp;amp;RF=&amp;amp;DI=3919&amp;amp;PS=85545&amp;amp;TP=drewby.spaces.live.com&amp;amp;GT1=drewby"&gt;</description><comments>http://drewby.spaces.live.com/Blog/cns!7FA4CC2B20EA6D0D!123.entry#comment</comments><guid isPermaLink="true">http://drewby.spaces.live.com/Blog/cns!7FA4CC2B20EA6D0D!123.entry</guid><pubDate>Mon, 13 Mar 2006 06:45:25 GMT</pubDate><slash:comments>0</slash:comments><msn:type>blogentry</msn:type><live:type>blogentry</live:type><live:typelabel>Blog entry</live:typelabel><wfw:commentRss>http://drewby.spaces.live.com/blog/cns!7FA4CC2B20EA6D0D!123/comments/feed.rss</wfw:commentRss><wfw:comment>http://drewby.spaces.live.com/Blog/cns!7FA4CC2B20EA6D0D!123.entry#comment</wfw:comment><dcterms:modified>2006-03-13T15:26:39Z</dcterms:modified></item></channel></rss>