Securing our future: September 2024 progress update on Microsoft’s Secure Future Initiative (SFI)
ID: 902b9ba4-2cee-5ef0-b508-014e7bb88325
STIX ID: report--902b9ba4-2cee-5ef0-b508-014e7bb88325
Feed Name: Microsoft Security
Microsoft provides a progress update on its Secure Future Initiative, highlighting governance and culture shifts (Deputy CISOs, Security Skilling Academy, leadership accountability) and concrete advances across six pillars: identity protection (HSM-backed signing key rotation, standardized token validation/logging), tenant and production isolation (removal of unused apps/tenants, locked-down devices), network protection (asset inventory, isolation of virtual networks and PaaS resources), secure engineering systems (governed pipelines, reduced token lifetimes, SSH disabled, proof-of-presence checks), threat monitoring (standardized audit logs with two-year retention, centralized network device logging), and response (faster mitigation, publishing critical cloud CVEs, new Customer Security Management Office), reaffirming transparency and Secure by Design commitments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
