Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Gartner's Security 3.0 |
|---|---|
| Date: | Wed, 17 Oct 2007 18:17:32 -0300 |
Greetings, On 10/16/07, xelerated <xelerated@gmail.com> wrote:
I think it should be far more. And not even from a pen tester perspective.
That's for sure Chris; "Security 3.0" addresses INFOSEC as a whole, but this is a pen-testing professionals' list, aint it? It is sort of natural to seek for results in this particular market. Anyway, give us your numbers' idea, then. Show us how reasonable they are face to Gartner's.
If you think about it, the pen tester has the easy job.
Yeah, right... What about the years of hard study? One can pentest easily today because somewhere in the past he spent hours learning that.
Its the people that have to secure the network that have the hard job. Think of all the vectors that are never addressed, either because of its not thought of, or its not part of a regulation or audit. How many companies focus on securing desktop (or logging for that matter) as much as they do servers? Sure there are policies and common sense to lock the desktop, but a fair amount the non IT, and older folk dont even consider it.
Shocking truth.
I personally think that the #1 problem in INFOSEC today is many companies do not look at the big picture. Its all about "passing the audit" not REAL security.
I have already stated this idea on this list and here it goes again: PRODUCTIVITY is so against SECURITY. Yours faithfully,
On 10/16/07, M.B.Jr. <marcio.barbado@gmail.com> wrote:Pentesters, Gartner's recently -- during its 2007 IT Security Summit -- released it's new corporative Information Security approach, named "Security 3.0". Basically, it suggests that 8 percent (and no less whatsoever than 5%) of the companies' IT budget be focused on security. It is something no doubt but personally I think it could be more, say 10%. The thing is: how are you, as a pentester, feeling such, concerning your incomes? Yours faithfully, -- Marcio Barbado, Jr. ============== ============== "In fact, companies that innovate on top of open standards are advantaged because resources are freed up for higher-value work and because market opportunities expand as the standards proliferate." Scott Handy Vice President Worldwide Linux and Open Source, IBM ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
-- Marcio Barbado, Jr. ============== ============== "In fact, companies that innovate on top of open standards are advantaged because resources are freed up for higher-value work and because market opportunities expand as the standards proliferate." Scott Handy Vice President Worldwide Linux and Open Source, IBM ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Executing PHP Code from MSSQL table, Danux |
|---|---|
| Next by Date: | Re: Gartner's Security 3.0, Pete Herzog |
| Previous by Thread: | Re: Gartner's Security 3.0, xelerated |
| Next by Thread: | Re: Gartner's Security 3.0, Santiago Barahona |
| Indexes: | [Date] [Thread] [Top] [All Lists] |