Jerry Bryant [MS] has an excellent post with links to Security resources that are provided by Microsoft. I am copying this here so that I do not have to go looking for them later:

Tools

  • Microsoft Baseline Security Analyzer (MBSA)
    Use this tool to identify common security misconfigurations and missing security updates. MBSA runs on the Windows Server™ 2003, Windows® 2000, and Windows XP operating systems and will scan for vulnerabilities in multiple products and technologies, including Microsoft Internet Information Services (IIS) and SQL Server™.
  • Software Update Services (SUS) / Windows Update Services (WUS)
    Quickly and reliably deploy the latest security updates, and service packs with Software Update Services. This new site now has the latest info on WUS.
  • Windows Update
    Scans your computer and provides a selection of updates tailored for your operating system, software, and hardware.
  • Microsoft Office Product Updates
    Scans and updates Microsoft Office products.
  • IIS Web Server Lockdown Wizard
    Reduces the attack surface of Internet Information Services (IIS) and includes URLScan to provide multiple layers of protection against attackers.
  • UrlScan Security Tool
    Helps prevent potentially harmful HTTP requests from reaching IIS Web servers.
        Removal Tools:
    Other Tools:
Updating
Isolation and Resiliency
Engineering Excellence
 
Guidance and Training