Microsoft has published some material about a new product under the security brand of Forefront called “Stirling”. Stirling aims to provide an integrated suite of security solutions for the network. The material is still pretty fluffy (marketing muck) but it gives you an idea of where MS is going with their security product set. There will be a CTP (customer technology preview) in H2 2007, a public beta in H1 2008 and a release in mid 2009. Here’s how MS are describing it:
Comprehensive Protection
By providing integrated protection technologies across clients, server applications, and the network edge, and dynamic responses to emerging threats, IT pros will be able to proactively protect their organization from emerging threats.
- “Stirling” integrates comprehensive protection technologies, including anti-malware, anti-spam, content filtering, host firewall, multi-engine protection for messaging and collaboration systems, network edge protection, and other technologies to be announced at a later date.
- Stirling” technologies will act as a distributed system, sharing information with each other, allowing for correlation of security information to identify complex threats. Protection technologies included in “Stirling” can be set to dynamically respond to these threats, making it easier for the IT administrator to address new threats.
- Integration with Network Access Protection ensures administrators can control network access based on user and machine authorization as well as adherence to the company’s security policy for endpoint protection.
Unified Management
“Stirling” provides a single management console across client, server, and network edge security.
- IT professionals can easily define their corporate security policy and “Stirling” will automatically configure the relevant protection technologies and ensure compliance to those policies.
- “Stirling” deploys configuration settings to existing groups of machines or users in Active Directory.
- IT professionals can use existing Microsoft Windows Server Update Services (WSUS) infrastructure to deploy updates for “Stirling.”
Critical Visibility
Critical visibility into the security state, including insights into threats and vulnerabilities through one central console that easily communicates where action is required.
- “Stirling” collects security information from client, server, and network edge devices and provides both comprehensive reports as well as the ability to drill down and perform investigations on specific security incidents, all in one place.
- “Stirling” allows IT professionals to obtain real-time security state or identify emerging trends based on historical data.