The pros and cons of Windows 7 security

In some cases, third-party security products might be a better fit than Windows 7's integrated security features

Businesses are eyeing a transition to Microsoft Windows 7, and with a wealth of security features that are part of it, it's worth figuring out the good and bad about each of them, says Gartner analyst Neil MacDonald, who notes in some cases, third-party security products might be the better fit.

The six greatest threats to U.S. cybersecurity

The AppLocker feature in Windows 7 offers an application-control capability that lets the IT manager set up a list of applications allowed to run, said MacDonald in his presentation at the Gartner Summit & Risk Management Summit 2010 last week. Often called whitelisting, this type of security control offers a possible lock-down technique, but the downside is that applications used within organizations by employees tend to grow, "and the trick is managing the whitelist over time."

"Care and feeding of the whitelist becomes cumbersome over time," MacDonald said, noting that there are several vendors in the application-control market, including Bit9, CoreTrace and McAfee (which acquired SolidCore) .

BitLocker, Microsoft's full-disk encryption capability for protecting system files and data, will be another security feature that businesses will want to evaluate in Microsoft Windows 7, MacDonald said. Calling it "good but not great," he noted that on the minus side of BitLocker, it has no self-service key recovery, no Windows single sign-on, and no smart card support for boot drive.

"By license restriction, it cannot be used where operating system virtualization is used," MacDonald pointed out. In addition, there's no support for non-Windows machines or Windows Mobile.

"It's another of those good but not great technologies," MacDonald said. "You should be encrypting all mobile devices."

Enterprises might want to look at product alternatives, including McAfee Safeboot, Sophos-acquired Utimaco, Credant Technologies, and PGP and GuardianEdge, both of which Symantec recently announced it was acquiring.

Prices for this type of desktop encryption product have been dropping from US$75 to $90 five years ago to today's range of about $10 to $15, he noted. Encryption today is often something "thrown in to get your business from the antivirus vendor," MacDonald said.

Windows 7 BitLocker has not yet been certified under the federal government's FIPS 140 program though it's in process to receive that certification, he pointed out.

Other security controls in Windows 7 also have their pros and cons, according to MacDonald.

For instance, the user-account control, which limits the ability of either applications or users to make unsanctioned system changes, has been improved to minimize prompts. But on the downside, it won't prevent someone running as a standard user from still installing software, so application control may still be needed.

There are third-party products from vendors that include BeyondTrust, (acquired by Symark International) Avecto, Symantec Altiris, and ScriptLogic, as well as Viewfinity, that IT managers may want to evaluate as alternatives.

Another security feature in Windows 7 is what's called DirectAccess, an "always-on VPN client that uses IPv6 underneath to uniquely address a workstation anywhere in the world," MacDonald noted. But supporting this type of IPSec tunnel can be highly problematic for a variety of reasons. "There's a lot of complexity," MacDonald said, particularly if organizations don't have an IPv6 network internally.

The advantage, though, would be it wouldn't be necessary to deploy an additional VPN client as a special agent and it can be viewed as extending encrypted access to the enterprise network in a way that's transparent to the user. While generally positive about what DirectAccess seeks to accomplish, MacDonald said he wouldn't recommend activating it in an initial Windows 7 deployment because of this underlying network complexity that would need to be well understood.

Internet Explorer 8 is included in the OS with Windows 7 and it is a definite positive step in terms of a protected browser, added McDonald, who recommends its use over earlier IE versions. But the firewall in Windows 7 "is not particularly good," he said. "It doesn't support deep-packet inspection or IDS." The firewall is often part of a core security package from the antivirus vendors, and if you "use Microsoft as a red herring," you may be able to strike some good deals with vendors.

IT managers opting to deploy Windows 7 may also want to determine if they should go with the "Enterprise" or the "Ultimate" versions, MacDonald suggested. Although the Windows 7 Ultimate version is officially a consumer version, it's considerably less expensive than the Windows 7 Enterprise version, so if the IT manager at a small business can consider manually activating each version, it might be worth going with Ultimate, even if it only has five years of fixes, not 10.

Read more about wide area network in Network World's Wide Area Network section.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags GartnermcafeeMicrosoftsecurityBit9WindowssoftwareWindows 7 securityoperating systems

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Ellen Messmer

Network World
Show Comments

Most Popular Reviews

Latest News Articles


PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?