Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: A question on security guidelines |
|---|---|
| Date: | Thu, 23 Sep 2004 14:53:09 -0500 |
MIKE, try this one OSSTMM.en.3.0.pdf. Release 3 will be released soon..you can start with releas 2.1 : OSSTMM - Open Source Security Testing Methodology Manual by Pete Herzog http://www.isecom.org/osstmm/ Best Regards Cesar T. -----Mensaje original----- De: Jakob Fredriksson [mailto:jf@rfc.se] Enviado el: jue 23/09/2004 13:10 Para: security-management@securityfocus.com CC: miker@otunet.com Asunto: Re: A question on security guidelines Evaluation is allways done compared to some set of goals. Look to the security framework of the organisation that you shall evaluate. Pick the evaluation questions that fits them. But, it there are no security framework or controls, their issue is much bigger than any set of questions can show. When/if you decide to start preparing and implementing security framework/procedures/etc you really should try to do it in a well-structured manner. There are a lot of good procedures out there (some cost money, some don't). I would start by considering PAPAI procedures http://www.papai.se/papai/papai_en/index.htm They could seem to be simple, but simple is beautiful. /Jakob
From: Mike Rodriques [mailto:miker@otunet.com] Sent: Thursday, September 23, 2004 12:03 AM To: security-management@securityfocus.com Subject: A question on security guidelines I am wondering if you all can point me in the right direction to find a template or guide that I can use to evaluate the overall security on a client network. I am looking for something along the lines of a questionnaire or something of that nature. Thanks in advance Mike Rodriques
-- Jakob Fredriksson <jf@rfc.se> Network & Security Phone: +46 733 776036
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: A question on security guidelines, Jakob Fredriksson |
|---|---|
| Next by Date: | COBIT Users - Questions and Comments, Bemis, Brad |
| Previous by Thread: | Re: A question on security guidelines, Jakob Fredriksson |
| Next by Thread: | COBIT Users - Questions and Comments, Bemis, Brad |
| Indexes: | [Date] [Thread] [Top] [All Lists] |