Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Measuring Risk Assessment |
|---|---|
| Date: | Fri, 23 Sep 2005 08:19:56 +1000 |
Have a look at COBIT, ITOL or COSO all other these have sections on
mapping controls and there are templates to map these to 17799
Have a look at
http://www.auditnet.org/
They have a large number of audit documents and controls tests. They
have a large number of 17799 documents and checklists on the site
Craig
-----Original Message-----
From: shankarnarayan.d@netsol.co.in
[mailto:shankarnarayan.d@netsol.co.in]
Sent: 21 September 2005 9:07
To: security-basics@securityfocus.com
Subject: Measuring Risk Assessment
Hi,
We have successfully enabled an Organization achieve BS7799. We have
conducted a Qualitative Risk Assessment for the different IT assets
As a part of periodic improvements the client periodically adds
additional security measures/ tweaking current controls etc. The Client
wants to now measure the effectiveness of adopting these controls to
show visible proof to his management about the effectiveness of these
controls and maybe adopting the standard.
Can I get some suggestions (irrespective of whether it is relevant to
BS7799 or not) as to how this client may show improvements to his
management. Specifically, any metrics on how he may show effectiveness
w/ respect to the "qualitative risk assessment". When he first
implemented the Risk Treatment plan, he could show significant risk
reduction, but (as an example), tweaks and changes now dont reduce a
risk which is "High" to "Medium", they only bring it a few notches lower
but still in "High"
Any inputs would be greatly appreciated. I am looking for something
apart from standard inputs like compare the number of vulnerabilities/
security issues faced/ measuring the hits on Firewall/ IDS etc
Thanks,
Shankar
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Restrict the Domain Admin, Craig Wright |
|---|---|
| Next by Date: | Re: PGP email encryption, Harrison Holland |
| Previous by Thread: | Measuring Risk Assessment, shankarnarayan . d |
| Next by Thread: | RE: Measuring Risk Assessment, security |
| Indexes: | [Date] [Thread] [Top] [All Lists] |