Here goes my first post... Better make it useful! [:D]
The Microsoft Security Security Assessment Tool (MSAT) is an excellent tool to help both you and your customers with regard to security. Ever have trouble framing a conversation around security for lack of knowing the right questions to ask? The MSAT's whole purpose is to ask those questions in order to build a Business Risk Profile for your customer and then can compare that profile to peer organzations to put the results into perspective.
It takes about an hour to complete an assessment and the questions are focused moreso on behavoirs rather than on specific technologies or brands. An example question might be "do external companies or organixzations have access to your network?" It is also important to note that the MSAT was in fact developed by Microsoft, Symantec, and Ziff Davis Media. After completion of the Business Risk profile reommendations are offered. These too are general in nature.
I had the opportunity to see a demonstration by one of the product group members and was really blown away with what this free tool could do, especially for partners. I sincerely hope you investigate the MSAT with haste as it will undoubtably become part of your arsenal moving forward.
To quote the MSAT FAQ
The Microsoft® Security Assessment is an interactive session that uses the Microsoft Security Assessment Tool (MSAT) and includes an on-site questionnaire. The Microsoft Security Assessment, a customer self-led or partner-facilitated session lasting from one to two hours, is designed to help customers gain a better understanding of their security gaps and risks.
The assessment provides a customer with a broad overview of its company and IT organization and results in a clearly defined map to becoming more secure through prioritized activities, solutions, and prescriptive guidance. The MSAT is a repeatable, scalable, and predictable tool focused on core solutions and services that leverages partner skill sets and demonstrates value to customers.
Upon completion of the assessment, customers receive a complimentary report with findings and recommendations specific to business issues addressed in the assessment. This report is designed to help the customer understand a baseline of security and prioritize steps to mitigate identified risks through Microsoft products and partner solutions.
Here are some links to MSAT related information:
The Microsoft Security Assessment Tool FAQ
https://www.securityguidance.com/faq.htm
The Microsoft Security Assessment Tool
https://www.securityguidance.com
TTFN,
Woody