Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Management
[Top] [All Lists]

RE: A question on security guidelines

Subject: RE: A question on security guidelines
Date: Thu, 23 Sep 2004 14:53:09 -0500
MIKE,  try this one OSSTMM.en.3.0.pdf.  Release 3 will be released soon..you 
can start with releas 2.1 :

OSSTMM - Open Source Security Testing Methodology Manual by Pete Herzog

http://www.isecom.org/osstmm/

Best Regards

Cesar T.



-----Mensaje original-----
De:     Jakob Fredriksson [mailto:jf@rfc.se]
Enviado el:     jue 23/09/2004 13:10
Para:   security-management@securityfocus.com
CC:     miker@otunet.com
Asunto: Re: A question on security guidelines
Evaluation is allways done compared to some set of goals.  Look to the 
security framework of the organisation that you shall evaluate.  Pick 
the evaluation questions that fits them.

But, it there are no security framework or controls, their issue is much 
bigger than any set of questions can show.

When/if you decide to start preparing and implementing security 
framework/procedures/etc you really should try to do it in a 
well-structured manner.  There are a lot of good procedures out there 
(some cost money, some don't).  I would start by considering PAPAI 
procedures http://www.papai.se/papai/papai_en/index.htm

They could seem to be simple, but simple is beautiful.


/Jakob


From: Mike Rodriques [mailto:miker@otunet.com] 
Sent: Thursday, September 23, 2004 12:03 AM
To: security-management@securityfocus.com
Subject: A question on security guidelines




I am wondering if you all can point me in the right direction to find a 
template
or guide that I can use to evaluate the overall security on a client network. 
 I
am looking for something along the lines of a questionnaire or something of 
that
nature.
 
 
Thanks in advance
 

Mike Rodriques


-- 
Jakob Fredriksson <jf@rfc.se>            Network & Security
Phone: +46 733 776036




<Prev in Thread] Current Thread [Next in Thread>