Windows 7 / Getting Started

Discovering Updates

The security update process starts when Microsoft releases or updates a security bulletin. Reissued bulletins that have a higher severity rating should be evaluated again to determine whether an already-scheduled security release should be reprioritized and accelerated. You might also initiate the security update process when a new service pack is released.

You can be notified of Microsoft-related security issues and fixes by subscribing to the Microsoft Security Notification Services. You can register for this service from the following Web site: http://www.microsoft.com/technet/security/bulletin/notify.mspx. If you subscribe to this service, you will receive automatic notification of security issues by e-mail. Note that you will never receive the update as an attachment from Microsoft. E-mail is easy to spoof, so Microsoft includes a digital signature that can be verified. However, it's generally easier to simply check the Microsoft Web site to ensure that the bulletin is officially listed.

In addition, use non-Microsoft sources to receive an objective opinion of vulnerabilities. The following sources provide security alert information:

  • Security alert lists, especially SecurityFocus (http://www.securityfocus.com)
  • Security Web sites, such as http://www.sans.org and http://www.cert.org
  • Alerts from antivirus software vendors
[Previous] [Contents] [Next]