NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Social Responsibility's Strategic Benefits

December 15, 11:30 AM - 12:30 PM US/Eastern (GMT-5)

Join Ed Granger-Happ, CIO of Save the Children, for a discussion of how creating an organization that is socially responsible improves staffing, retention, leadership development and overall corporate health.

Working With and Communicating to Your Board of Directors

January 13, 2009, 4:00 PM - 5:00 PM US/Eastern (GMT-5)

CIO panelists who will share tips and experiences working with their boards: Twila Day of SYSCO; Jeff O'Hare, West Corp.; Marc West, formerly with H&R Block.

IT's Role in Growing Mid-Market Companies

January 14, 4:00 PM - 5:00 PM ET (GMT-5)

Mid-market Council members will share their companies' stories and challenges in driving or coping with growth. Panelists represent Veterinary Pet Insurance, Medicis Pharmaceutical, and Intrax Cultural Exchange.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
 

Scott Charney: Microsoft's Ax Man

Some people might dream of having the power to kill a product just before launch at a company the size of Microsoft, but for Scott Charney, that's just part of the job.

 

April 25, 2008 — IDG News Service —

Some people might dream of having the power to kill a product just before launch at a company the size of Microsoft, but for Scott Charney, that's just part of the job.

Charney, vice president of trustworthy computing, was hired by Microsoft in early 2002 to spearhead the company's security strategy. He built a team that looks for vulnerabilities in products during development and works to implement security into product design. If the team finds an issue, even if the product is just about to ship, Charney can order the product back to the drawing board until the problem is fixed.

Microsoft's implementation of its secure-development lifecycle process has led the industry, said Andrew Jaquith, an analyst at Yankee Group. "They have really been a pacesetter in this area," he said.

Still, Microsoft didn't create the initiative out of choice, Jaquith said. "It was born out of necessity because customers were threatening to defect," he said. Microsoft once had an internal list, called the executive hot list, made up of "customers so furious with security that they called [Bill] Gates or [CEO Steve] Ballmer personally," Jaquith said. "In many respects, that caused the trustworthy computing initiative to be born." Microsoft's public-relations firm said that the company would not comment on the matter.

Since Charney joined Microsoft, on five occasions vice presidents in charge of products have disagreed with his no-ship order, Charney said recently to a group of reporters at Microsoft's headquarters in Redmond, Washington. Craig Mundie, chief research and strategy officer at Microsoft, was called to settle the disputes, and each time he sustained Charney's no-ship order.

Once, Charney reversed his no-ship order himself. That was after his team found out about an issue in Windows Mobile 2003 that should have been fixed before it shipped, he said. But then Pieter Knook, who was in charge of Microsoft's mobile communications business until he left the company this February, explained that delaying the product launch would mean missing the end-of-year holiday season -- and that the issue could be fixed after the launch. Charney decided to let the operating system ship.

His team typically finds issues during development and makes sure the problems are fixed, he said.

"Every now and again we get surprised," he said. Sometimes a vulnerability is discovered in an older version of a product, and his team realizes that a newer version in development might also have the same problem.

Microsoft hired Charney, who had worked for the U.S. Department of Justice and served as assistant district attorney in the Bronx, at what he said was a unique time. The Sept. 11 attacks had just happened, and two major computer viruses, Code Red and Nimba, had recently spread rapidly across the Internet. That combination of events created a unique environment, when previously complacent vendors and governments realized they needed to get more serious about computer security, he said.

Loading...
 
 
IT Jobs
 
 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Virtualization Benchmark and TCO Analysis-Read Now

White Paper: Scaling Down HPC for Smaller Organizations

White Paper: Never Enough Compute Power?

Microsoft Windows Vista Cost and Benefit Estimator

White Paper: Efficient Desktop Application Management

White Paper: Take your Call Center to the Next Level

Is Your WLAN Helping You Comply with Security Guidelines of the PCI Standard?

White Paper: Improve Employee Efficiency and Reduce Telecom Costs

White Paper: Green Issues for Networking

New IDG Survey Results on Data Center Automation

Operational Excellence Is Key to Maximizing IT Investments

The Right and Wrong Master Data Management Strategies to Start Small and Grow Big

Find out how to manage virtualization's risks and reap the rewards.

Conquer the realities of managing virtualization

Remote Infrastructure Management - What Your Peers are Thinking

Complementary BI: The New Approach to Business Intelligence

Unified Communications & Collaboration: Game-Changing Business Results

The ECM Paradox: Extending Local Flexibility to Strengthen Central Control

Customer Insight Yields Sales, Marketing Gains

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

File Integrity Monitoring: Prove compliance and secure your IT environments

Affordable technology-no compromise. HP server solutions

SOA Educational Library at the TIBCO SOA Resource Center

CIO Viewpoints: Migrating to Exchange 2007

Server Virtualization Benchmark Results

Learn to Leverage Maximum Computing Power

Windows Vista: Essential Benefits and Deployment Strategies

Best Practices: Safe and Secure Hardware Asset Recovery

White Paper: Migrating to Windows Vista and Microsoft Office 2007 Together

White Paper: Enabling Next Generation IP Communications

White Paper: A Cohesive Network Security Approach

Why Your Firewall, VPN, and IEEE Aren't Enough to Protect Your Network

Dramatically boost network capacity and speed-up to 600 Mbps

White Paper: The Roadmap to Data Center Automation

Learn how companies are changing how they reach out to their most profitable customers.

Get help navigating the management challenges of virtualization.

Narrow the gap between virtualization's benefits and the management risks.

Cash in on the promise of virtualization

Webcast - "Into the Wild: Managing Laptops Outside the Office"

Mobility is Growing: Survey Shows Why CIOs are Concerned

Learn what it takes to build a holistic digital collaboration platform

Make Hidden Trends, Inter-Relationships and Influences Visible.

Improve delivery of product information to customers.

Renowned Engineering Institution Chooses AMD Processor-Based Servers

Corral, configure and control all your mischievous machinery with a Lantronix device server

Spend less. Get hosted UC. Get cash back. It's easy under a Cypress

Predict the future with HP Insight Power Manager

Log onto Hitachi True Stories, films inspired by the next great achievement

Earn PROFESSIONAL DOCTORATE Part-Time, Online at Syracuse University's iSchool