Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Moving from Defense to Offense (or vice versa) to secure your network |
|---|---|
| Date: | Sun, 27 Nov 2005 17:59:05 +0100 |
Fred.
All,
I was having an interesting discussion with a coworker the other day about the differences between pen-testing (offense) and network security work (defense) which we do in our day jobs. The majority of my security background has been from a penetration standpoint so the way I view network security defense setups and priorities tends to be of the "how would I break this and get in" viewpoint rather than the "how do I secure this and ensure reliable reporting/monitoring" view that my coworker is more centered on. The differences in the priorities and methods we would choose to secure our network for defense was much different than I anticipated.
So I was hoping some list members would share some similar experiences with us. How many of you have switched between offense/defense and what were some of the stumbling blocks or key differences you found in how you approached your goals? Is it worth it to cross-train in some manner? How have you sold someone on the advantages of penetration-testing your network to quantify and test the effectiveness of your existing defenses?
I would be interested to hear some cases you have run into out there.
--
Erin Carroll
"Do Not Taunt Happy-Fun Ball"
-- Frederic Charpentier - Xmco Partners Security Consulting / Pentest web : http://www.xmcopartners.com/tests-intrusion.html
http://www.securityfocus.com/sponsor/pen-test_050831 -------------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Moving from Defense to Offense (or vice versa) to secure your network, Byron Sonne |
|---|---|
| Next by Date: | Re: Moving from Defense to Offense (or vice versa) to secure your network, Bob Radvanovsky |
| Previous by Thread: | Re: Moving from Defense to Offense (or vice versa) to secure your network, Byron Sonne |
| Next by Thread: | Re: Moving from Defense to Offense (or vice versa) to secure your network, Bob Radvanovsky |
| Indexes: | [Date] [Thread] [Top] [All Lists] |