---------------------------------------------------------------------------- Customer Warning System (CWS) SunFLASH Vol 22 #8 October 1990 ---------------------------------------------------------------------------- This is an updated article. Note that phone number for reporting security problems has changed. Please work with your Sun Sales Rep to register a "Security Contact" for your site. - johnj ---------------------------------------------------------------------------- Announcing Sun Microsystem's Customer Warning System for Security Incident Handling In order to best serve our customers' service needs, Sun has established a Customer Warning System (CWS) for handling security incidents. This is a formal process which includes: - Having a well advertised point of contact in Sun for reporting security problems. - Pro-actively alerting customers of worms, viruses or other security holes that could affect their systems. - Distributing the patch (and/or work-around) to our customers as quickly as possible. More specifically, the CWS is being set up as follows: We have created an email address ( security-alert@sun ) which will enable both internal and external people to have a single place to report security problems. We have provided a voice-mail back-up ( 415-688-9081) for the cases where sending email is not possible. *ALL* SECURITY HOLES SHOULD BE REPORTED TO THIS ALIAS. We have filled the position of "Security Coordinator" in our Customer Service Organization. The Security Coordinator is responsible for manning the email and voice mail hotlines and evaluating the security problems. We have a Customer Warning System "SWAT Team" in place to address severe security incidents. The CWS SWAT Team consists of knowledgeable senior people within Sun Corporate who are committed to being available to meet whenever required and who are empowered to make all necessary decisions. We plan on publicizing the CWS bi-monthly to internal Sun aliases (to encourage Sun Field personnel to tell their customers about this service). CWS will also be announced (and supported) by the various Computer Emergency Response Teams Sun that works with. Please pass this information along to whoever you feel is appropriate. Sales Representatives should be certain to send this information to all their security-conscious customers! Customers and Sun Field Offices may send us a "Security Contact" from their organizations. This is the person Sun should contact in the case of any new security problems. He or she will be sent information on the problem at hand, including work-arounds and how and when to obtain fixes. Preferably, your Security Contact should be technical. He or she should be your site's System Administrator (or System Security Administrator). The information we need for the Security Contact from the three geographies for customers is as follows: ---------------------- U.S. Security Contact Information -------------------- Company Name: Security Contact's Name: Customer Number (from Cullinet): Address ID (from Cullinet)*: Postal address: Email address: Phone number: Fax number: Preferred method of contact (from above: 1st, 2nd and 3rd choice): * If there is not an existing Address ID, we need the full address for the security contact. ----------------- Europe and ICON Security Contact Information --------- Company Name: Security Contact's Name: Customer Number: Address Id: If there is no customer number or Address ID, then we need the following information for each customer: Postal Address: Email Address: Phone Number: Fax Number: Preferred method of contact (from above: 1st, 2nd and 3rd choice): --------------- Sun Field Office Security Contact Information --------------- Office Location: Security Contact's Name*: Email address: *One per office ---------------------------------------------------------------------------- ***** PLEASE SEND THIS INFORMATION TO: ***** security-alert@sun.com or, if you prefer postal mail: Brad Powell c/o Sun Microsystems MTV18-04 2550 Garcia Ave. Mt. View, CA 94043 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Sunflash is an electronic mail news service from Sun Microsystems, Ft. Lauderdale, Florida, USA. It is targeted at Sun Users and Customers. For additional information about SunFlash send mail to info-sunflash@sunvice.East.Sun.COM SunFlash is distributed via a hierarchy of aliases. Try to address change requests to the owner of the alias that you belong to. If you want to be added to the SunFlash alias, please contact the systems engineers at your local Sun office and/or send mail to sunflash-request@sunvice.East.Sun.COM. "All prices, availability, and other statements relating to Sun or third party products are valid in the U.S. only. Please contact your local Sales Representative for details of pricing and product availability in your region." Address comments to the SunFlash editor (John McLaughlin) at sun!sunvice!flash or flash@sunvice.East.Sun.COM. (305) 776-7770.