Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: [Full-Disclosure] Top 15 Reasons Why Admins Use Security Scan ners |
|---|---|
| Date: | Wed, 28 Apr 2004 16:13:23 -0400 |
First an auditor checks for vulnerabilities of course (this is for validation not to make that determination based on the auditee's saying or reports from third party scanners). Then the auditor will determine the extent and security surrounding those vulns and what the auditee is either required (policy/procedure) or recommended (best practice) to fix those vulnerabilities and stay secure. __________________________________________________ Christopher D. Starford SAIC Enterprise Security Sulutions
-----Original Message----- From: Harlan Carvey [mailto:keydet89@yahoo.com] Sent: Wednesday, April 28, 2004 3:05 PM To: Starford, Christopher D. Cc: 'full-disclosure@netsys.com' Subject: RE: [Full-Disclosure] Top 15 Reasons Why Admins Use Security Scan ners And you know something, Chris...that's fine. Really. I just left a position in the private sector w/ a company that was audited over a dozen times a year by various customers. Even their external auditors (ie, *not* customers) were clueless when it comes to IT or security. One audit did include a knowledgeable security professional on staff...but just one. But there's also another way to look at the original comment...security is a process. Running a vulnerability scanner isn't a process...it's a point-in-time check, a snapshot. A good IT security auditor won't focus on the fact that certain systems have vulnerabilities...he or she will focus on *why* they have the vulnerabilities.I believe many true IT Security Auditors out there would agree that your wrong on this one.-How will I ever pass my IT Security Audits? Don't worry about it...most audits don't seem tohavean IT background, and even when they do, theydon'ttake the time to understand your businessprocesses oryour network infrastructure.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: AW: [Full-Disclosure] no more public exploits, Soderland, Craig |
|---|---|
| Next by Date: | RE: [Full-Disclosure] Microsoft's Explorer and Internet Explorer long share name buffer overflow., Bryce Porter |
| Previous by Thread: | RE: [Full-Disclosure] Top 15 Reasons Why Admins Use Security Scan ners, Starford, Christopher D. |
| Next by Thread: | RE: [Full-Disclosure] Top 15 Reasons Why Admins Use Security Scan ners, Ng, Kenneth (US) |
| Indexes: | [Date] [Thread] [Top] [All Lists] |