Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Management
[Top] [All Lists]

Re: Is there any way to measure IT Security??

Subject: Re: Is there any way to measure IT Security??
Date: Thu, 4 Aug 2005 11:09:40 -0400
"Measuring IT security" is a broad concept, but a comprehensive risk 
assessment is the best way to gage overall security posture. Vulnerability 
assessment is just one piece of that. Standards for best practice, like 
ISO17799, force you to consider every part of your organization as it 
relates to infosec. There are many risk assessment frameworks, guidelines 
and tools available from sites like sans.org, nist.gov, issa.org, etc., as 
well as commercial offerings.

Unfortunately, there's no cut & dried scoring system, nor a universally 
adopted measurement standard, so keep your expectations (and management's 
expectations) realistic. Involve EVERYONE in your assessment and in your 
security program. I've seen companies ignore outside contractors, cleaning 
services and maintenance workers because they weren't permanent, full-time 
employees. That's like ignoring the key under the door mat.

- Rich


 



"Toto A Atmojo" <toto@playon.co.id> 
07/28/2005 06:02 AM

To
<pen-test@securityfocus.com>, <security-management@securityfocus.com>, 
<secpapers@securityfocus.com>, <focus-linux@securityfocus.com>, 
<libnet@securityfocus.com>, <firewalls@securityfocus.com>, 
<security-basics@securityfocus.com>
cc

Subject
Is there any way to measure IT Security??






Dear all,
 
Currently I?m looking for a tool, or a technique to measure IT security?
 
The baseline for security is CIA (Confidentiality, Integrity and 
Availability), that is every organization which want to called secure must 
be guarantee that their system comply this matter.
But the problem is, we need a tool/technique to measure how secure are we. 
Therefore, wee need a tool/technique to measure how close that our system 
status now to CIA.
 
Please share your experience about this matter.
If there any link about this issue, I really appreciate if you share to us 
(You may contact me privately) .
 
 
Best Regs,
 
Toto
 
<Prev in Thread] Current Thread [Next in Thread>