Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Is there any way to measure IT Security?? |
|---|---|
| Date: | Thu, 4 Aug 2005 11:09:40 -0400 |
"Measuring IT security" is a broad concept, but a comprehensive risk assessment is the best way to gage overall security posture. Vulnerability assessment is just one piece of that. Standards for best practice, like ISO17799, force you to consider every part of your organization as it relates to infosec. There are many risk assessment frameworks, guidelines and tools available from sites like sans.org, nist.gov, issa.org, etc., as well as commercial offerings. Unfortunately, there's no cut & dried scoring system, nor a universally adopted measurement standard, so keep your expectations (and management's expectations) realistic. Involve EVERYONE in your assessment and in your security program. I've seen companies ignore outside contractors, cleaning services and maintenance workers because they weren't permanent, full-time employees. That's like ignoring the key under the door mat. - Rich "Toto A Atmojo" <toto@playon.co.id> 07/28/2005 06:02 AM To <pen-test@securityfocus.com>, <security-management@securityfocus.com>, <secpapers@securityfocus.com>, <focus-linux@securityfocus.com>, <libnet@securityfocus.com>, <firewalls@securityfocus.com>, <security-basics@securityfocus.com> cc Subject Is there any way to measure IT Security?? Dear all, Currently I?m looking for a tool, or a technique to measure IT security? The baseline for security is CIA (Confidentiality, Integrity and Availability), that is every organization which want to called secure must be guarantee that their system comply this matter. But the problem is, we need a tool/technique to measure how secure are we. Therefore, wee need a tool/technique to measure how close that our system status now to CIA. Please share your experience about this matter. If there any link about this issue, I really appreciate if you share to us (You may contact me privately) . Best Regs, Toto
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Is there any way to measure IT Security??, Alberto Cardona II |
|---|---|
| Next by Date: | Bay Area Security User Group, Salaets, Steven |
| Previous by Thread: | Re: Is there any way to measure IT Security??, John Alexander |
| Next by Thread: | Bay Area Security User Group, Salaets, Steven |
| Indexes: | [Date] [Thread] [Top] [All Lists] |