Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: A question on security guidelines |
|---|---|
| Date: | Thu, 23 Sep 2004 22:56:47 +0200 |
Hallo Mike, the german BSI, a governmental department of the Home Office, responsible for IS security, has developed a guide called the "IT Baseline Protection Manual". Its a very formal guide but nevertheless or because of its formality a very structured and a very generic guide to define the appropriate level of security an organisation needs. By answering the right questions you'll find out what security you'll need and additonally you'll find out which threats you missed and you've to define which counter measures are necessary. There is an english section and an english version of this guide on their home page: go to http://www.bsi.de/english/index.htm -- Selected Documents -- IT Baseline Protection Manual I think its not necessary to read the whole document (about 2500 page) in detail, but the threats, counter measures etc. discussed provide a good basis for a comprehensive questionnaire. -- Regards Robert Binder, CISSP IT Security Consultant +49 89 13039524 -- Phone +49 171 4424823 -- Mobile mailto:robert_binder@t-online.de -----Original Message----- From: miker@otunet.com Date: 23.09.2004 To: security-management@securityfocus.com
I am wondering if you all can point me in the right direction to find a template or guide that I can use to evaluate the overall security on a client network. I am looking for something along the lines of a questionnaire or something of that nature.
Thanks in advance
Mike Rodriques Principal Open Technologies Unlimited "We make IT go" mailto:miker@otunet.com http://www.otunet.com (914) 481-6128 (914) 481-6133 Fax (914) 548-5646 Mobile
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Audit Programs Management for Security Teams, Bemis, Brad |
|---|---|
| Next by Date: | Project Plan for Assessments, Alt, Brandon C. |
| Previous by Thread: | Re: A question on security guidelines, Javier Blanque |
| Next by Thread: | Re: RSA vs. Versigin. How do I choose?, Saqib . N . Ali |
| Indexes: | [Date] [Thread] [Top] [All Lists] |