Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: sesecuring access to workgroup for notebooks

Subject: Re: sesecuring access to workgroup for notebooks
Date: 24 Nov 2004 15:36:51 -0000
In-Reply-To: <41A043F9000277DF@vsmtp2alice.tin.it (added by 
postmaster@aliceposta.it)>

thank you alessandro for your answer.
Risk assessment is performed by an external resource (consultant). I'm part of 
internal tech staff that should interact with the consultant during analisys.
Moreover we like "to hear from more than one bell" 
(italian adagio, do not know if any english exists
for this...). Motivations are:
1. knowing what's going on (I got this job a few weeks ago, and I found a very 
anarchy in the IT department...) and what risks we are exposed;
2. legal: you got the point: italian law brings us to this, and I DO want this 
not be only a legal hassle,
but the chance to reorganize procedures kick off
any bad practice.

The first of such I did notice is that there is quite a lot of people (mostly 
interns as I said) coming in the office, plugging his/her notebook to the 
corporate net
(modifing by hand IPs and so on) and getting access.

but this only the first thing...
There's no defined way to organize, on the server,
access to folders (anything is public...) and so on.
So can you please helpme? can you, for example, point me to some docs explainig 
how we should organize procedures and so on?

thanks
davide



First of all: what's the goal of the Risk Assessment? Technical? 
For budgeting purposes? For legal compliance (like, since we are 
both in Italy, the New Privacy Code)? The purpose will drive the 
[...]
Cheers,

-- 
Alessandro Bottonelli, CISSP & BS7799 Lead Auditor
AXIS-NET Privacy & InfoSec Consulting
http.//www.axis-net.it


<Prev in Thread] Current Thread [Next in Thread>