Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: sesecuring access to workgroup for notebooks |
|---|---|
| Date: | 24 Nov 2004 15:36:51 -0000 |
In-Reply-To: <41A043F9000277DF@vsmtp2alice.tin.it (added by postmaster@aliceposta.it)> thank you alessandro for your answer. Risk assessment is performed by an external resource (consultant). I'm part of internal tech staff that should interact with the consultant during analisys. Moreover we like "to hear from more than one bell" (italian adagio, do not know if any english exists for this...). Motivations are: 1. knowing what's going on (I got this job a few weeks ago, and I found a very anarchy in the IT department...) and what risks we are exposed; 2. legal: you got the point: italian law brings us to this, and I DO want this not be only a legal hassle, but the chance to reorganize procedures kick off any bad practice. The first of such I did notice is that there is quite a lot of people (mostly interns as I said) coming in the office, plugging his/her notebook to the corporate net (modifing by hand IPs and so on) and getting access. but this only the first thing... There's no defined way to organize, on the server, access to folders (anything is public...) and so on. So can you please helpme? can you, for example, point me to some docs explainig how we should organize procedures and so on? thanks davide
First of all: what's the goal of the Risk Assessment? Technical? For budgeting purposes? For legal compliance (like, since we are both in Italy, the New Privacy Code)? The purpose will drive the
[...]
Cheers, -- Alessandro Bottonelli, CISSP & BS7799 Lead Auditor AXIS-NET Privacy & InfoSec Consulting http.//www.axis-net.it
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: DOS Attack?, Suramya Tomar |
|---|---|
| Next by Date: | RE : USB Security, John Robot |
| Previous by Thread: | Re: sesecuring access to workgroup for notebooks, Alessandro Bottonelli |
| Next by Thread: | Grading System, Paul Ryan |
| Indexes: | [Date] [Thread] [Top] [All Lists] |