Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Management
[Top] [All Lists]

Re: A question on security guidelines

Subject: Re: A question on security guidelines
Date: Thu, 23 Sep 2004 22:56:47 +0200
Hallo Mike,

the german BSI, a governmental department of the Home Office,
responsible for IS security, has developed a guide called the "IT
Baseline Protection Manual". Its a very formal guide but nevertheless
or because of its formality a very structured and a very generic guide
to define the appropriate level of security an organisation needs. By
answering the right questions you'll find out what security you'll
need and additonally you'll find out which threats you missed and
you've to define which counter measures are necessary.

There is an english section and an english version of this guide on
their home page:
go to http://www.bsi.de/english/index.htm
-- Selected Documents
-- IT Baseline Protection Manual
I think its not necessary to read the whole document (about 2500 page)
in detail, but the threats, counter measures etc. discussed provide a
good basis for a comprehensive questionnaire.

-- 
Regards
Robert Binder, CISSP
IT Security Consultant

+49 89 13039524  --  Phone
+49 171 4424823  --  Mobile

mailto:robert_binder@t-online.de


-----Original Message-----
From: miker@otunet.com
Date: 23.09.2004
To:   security-management@securityfocus.com


I am wondering if you all can point me in the right direction to find a
template or guide that I can use to evaluate the overall security on a
client network.  I am looking for something along the lines of a
questionnaire or something of that nature.
 
 
Thanks in advance
 

Mike Rodriques
Principal
Open Technologies Unlimited
"We make IT go"
mailto:miker@otunet.com
http://www.otunet.com
(914) 481-6128
(914) 481-6133 Fax
(914) 548-5646 Mobile

<Prev in Thread] Current Thread [Next in Thread>