John Alexander
2005-08-03 09:21:02 UTC
Basically IT Security covers a gamut of areas, i am just listing some , on the fly
* Antivirus Solutions
* Intrusion Prevention
* Intrusion Detection
* Patch Management
* Firewall
* VPN Gateway
* Vulnerability Assessment & Reporting
* Identity Access Management (single-sign-on, SOX/HIPAA/GLB compliance....)
* Network Security
* Security Policy Compliance Management
* AntiSpam (mail protection software)
* Web Content Filtering
I'm not sure whether we have one-size-fits-all solution which can help us in measuring your enterprise IT Security posture.
I can list some good tools i have come across personally like NMap, ScanFi, Nessus, IdentityAccess Manager,GFI ....but the list is endless, so give them a try in google :-)
----- Original Message -----
From: "Gary Everekyan" <***@bluetie.com>
To: ***@trini.org, ***@playon.co.id
Subject: Re: Is there any way to measure IT Security??
Date: Tue, 02 Aug 2005 14:32:30 -0400
___________________________________________________________
Sign-up for Ads Free at Mail.com
http://promo.mail.com/adsfreejump.htm
------------------------------------------------------------------------------
FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't
Learn the hacker's secrets that compromise wireless LANs. Secure your
WLAN by understanding these threats, available hacking tools and proven
countermeasures. Defend your WLAN against man-in-the-Middle attacks and
session hijacking, denial-of-service, rogue access points, identity
thefts and MAC spoofing. Request your complimentary white paper at:
http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
-------------------------------------------------------------------------------
* Antivirus Solutions
* Intrusion Prevention
* Intrusion Detection
* Patch Management
* Firewall
* VPN Gateway
* Vulnerability Assessment & Reporting
* Identity Access Management (single-sign-on, SOX/HIPAA/GLB compliance....)
* Network Security
* Security Policy Compliance Management
* AntiSpam (mail protection software)
* Web Content Filtering
I'm not sure whether we have one-size-fits-all solution which can help us in measuring your enterprise IT Security posture.
I can list some good tools i have come across personally like NMap, ScanFi, Nessus, IdentityAccess Manager,GFI ....but the list is endless, so give them a try in google :-)
----- Original Message -----
From: "Gary Everekyan" <***@bluetie.com>
To: ***@trini.org, ***@playon.co.id
Subject: Re: Is there any way to measure IT Security??
Date: Tue, 02 Aug 2005 14:32:30 -0400
Google Risk reporting and you will get whole list of research links.
It would also be helpful to look at owasp www.owasp.org
HTH
Regards,
Gary Everekyan
CISSP, CISM, ISSAP, ISSPCS, MCSE, MCT
"High achievement always takes place in the framework of high
expectation" -Jack Kinder
-----Original Message-----
Date: 08/02/2005 01:09 PM
You should check out NSA IAM/IEM Methodology...it works well for me.
http://www.iatrp.com/iam.cfm
--It would also be helpful to look at owasp www.owasp.org
HTH
Regards,
Gary Everekyan
CISSP, CISM, ISSAP, ISSPCS, MCSE, MCT
"High achievement always takes place in the framework of high
expectation" -Jack Kinder
-----Original Message-----
Date: 08/02/2005 01:09 PM
You should check out NSA IAM/IEM Methodology...it works well for me.
http://www.iatrp.com/iam.cfm
Dear all,
Currently Im looking for a tool, or a technique to measure IT security?
The baseline for security is CIA (Confidentiality, Integrity and
Availability), that is every organization which want to called
secure must be guarantee that their system comply this matter.
But the problem is, we need a tool/technique to measure how
secure are we. Therefore, wee need a tool/technique to measure
how close that our system status now to CIA.
Please share your experience about this matter.
If there any link about this issue, I really appreciate if you
share to us (You may contact me privately) .
Best Regs,
Toto
Currently Im looking for a tool, or a technique to measure IT security?
The baseline for security is CIA (Confidentiality, Integrity and
Availability), that is every organization which want to called
secure must be guarantee that their system comply this matter.
But the problem is, we need a tool/technique to measure how
secure are we. Therefore, wee need a tool/technique to measure
how close that our system status now to CIA.
Please share your experience about this matter.
If there any link about this issue, I really appreciate if you
share to us (You may contact me privately) .
Best Regs,
Toto
___________________________________________________________
Sign-up for Ads Free at Mail.com
http://promo.mail.com/adsfreejump.htm
------------------------------------------------------------------------------
FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't
Learn the hacker's secrets that compromise wireless LANs. Secure your
WLAN by understanding these threats, available hacking tools and proven
countermeasures. Defend your WLAN against man-in-the-Middle attacks and
session hijacking, denial-of-service, rogue access points, identity
thefts and MAC spoofing. Request your complimentary white paper at:
http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
-------------------------------------------------------------------------------