Special OPS: Host and Network Security for Microsoft, UNIX, and Oracle

Chapter 5: Attacking and Defending Windows 2000
Chapter 6: Securing Active Directory
Chapter 10: Securing IIS
Chapter 17: Architecting the Human Factor
Chapter 18: Creating Effective Corporate Security Policies
Even as recently as five years ago, many computer industry experts would never have guessed how pervasive and "business critical" electronic messaging would eventually become. The degree to which some information technology professionals are surprised by the pervasive nature of today's electronic mails systems is merely amusing to those of us that have had an e-mail address for more than 20 years.
I have been using electronic mail of one type or another since 1980 and have specialized in messaging systems since 1988, so it comes as no surprise to me the current dependency that businesses and government entities have on e-mail. However, this dependency has introduced a number of issues surrounding usage, administration, and security of e-mail.
I began working with Exchange 4.0 during the beta period in 1995; for me it was love at first sight since it introduced many features that were sorely missing from LAN-based electronic mail systems of the day. However, I suspect that for each of these new features, I have found an equal number of new headaches; yet Exchange remains my favorite Microsoft product. To this day, the product remains fairly stable and secure; there have been few bugs or security problems directly attributed to the Exchange product. Most security problems related to Exchange end up being related to the underlying...