Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Is there any way to measure IT Security?? |
|---|---|
| Date: | Fri, 29 Jul 2005 08:27:56 +0200 |
Toto, I am afraid that no tool can fulfill your requirement. I think in order to be able to measure the effectiveness of your IT security controls; you should first start with defining security policies fitting your organizational requirements. Based on these policies and your corporate security strategy you can define security metrics to measure conformance with the security policies. As an example the number/percentage of audited/security accredited systems (against the system security policy) is a metric you can use in order to measure the effectiveness of your system security policy (preventive control). I wouldn't rather think in tools, but processes within your IT security department to help you out drive performance, and achieve policy compliance. Hope this helps Salah ________________________________ From: Toto A Atmojo [mailto:toto@playon.co.id] Sent: Thursday, July 28, 2005 12:02 PM To: pen-test@securityfocus.com; security-management@securityfocus.com; secpapers@securityfocus.com; focus-linux@securityfocus.com; libnet@securityfocus.com; firewalls@securityfocus.com; security-basics@securityfocus.com Subject: Is there any way to measure IT Security?? Dear all, Currently I'm looking for a tool, or a technique to measure IT security? The baseline for security is CIA (Confidentiality, Integrity and Availability), that is every organization which want to called secure must be guarantee that their system comply this matter. But the problem is, we need a tool/technique to measure how secure are we. Therefore, wee need a tool/technique to measure how close that our system status now to CIA. Please share your experience about this matter. If there any link about this issue, I really appreciate if you share to us (You may contact me privately) . Best Regs, Toto
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Next by Date: | Re: Infosec User Awareness And Training Handbook, Gunnar Kopperud |
|---|---|
| Next by Thread: | RE: Is there any way to measure IT Security??, Craig Wright |
| Indexes: | [Date] [Thread] [Top] [All Lists] |