Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Paper - Audit Taxonomy |
|---|---|
| Date: | 20 Jun 2007 20:45:54 -0000 |
Hello, A while back now I mentioned that I was going to write a definative paper on audit terminology. A few people asked me to forward this and I know a people had been looking to pick it apart ;). The paper is now released (a little latter than anticipated, but such is life). It is titled: "A Taxonomy of Information Systems Audits, Assessments and Reviews" It is available directly from: http://www.sans.org/reading_room/whitepapers/auditing/1801.php Or via the SANS reading room at: http://www.sans.org/reading_room/last.php and http://www.sans.org/reading_room/whitepapers/auditing/ The assertions made in the paper are validated experimentally in the second half of the paper for those who enjoy a little math. Regards, Craig S Wright Abstract: Common misconceptions plague information systems audit as to the nature of security, audit and assessment types and definitions. The dissertation aims at being a definitive guide to define the terminology and detail the related methodologies across the range of information assurance services. The idea is to not only detail and define the types of audit, assessment inspections [etc], but to compare and evaluate the various strengths and benefits of each in a simple and referential critique that may remove an abstraction of error and confusion surrounding these services. The paper will cover the types, history and basis for each type of service. The paper statistically compares the strengths and weaknesses of each and sets out a scientifically repeatable foundation for the deterministic nomenclature used in the industry. ------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: How Would I Find the Actual Name of the Honeypot Software via a Pen Test?, Dragos Ruiu |
|---|---|
| Next by Date: | Re: Security and VPN, Ben Nell |
| Previous by Thread: | sqlninja 0.1.2 released, A. R. |
| Next by Thread: | Safe keeping super-user / root IDs, kelvinshen |
| Indexes: | [Date] [Thread] [Top] [All Lists] |