There aren't that many IT security literate people in organisations so when they need some assurance they are doing the right thing they ask a 3rd party with specialist experience for testing . The reality of the situation is that if someone is looking for assurance that they are doing a good job security wise they probably aren't . Some questions that security people often dont dare to ask or ask pretty much knowing the answers when approached to conduct a pen test include
% do you have a security policy
% do you have up to date technical security standards for the kit in use ?
%has someone been tasked with applying the standards ?
%has someone checked that the standards have been applied?
%is someone monitoring for intrusion?
%is there a risk assessment for this project ?
%there any security requirements for this project ?
%is there a security architecture document and detailed design docs for the key security controls ?
% has functional testing of the key controls been undertaken to check they work in the intended manner ?
----
Sent using a Sony Ericsson videophone
About Me
- Matthew Hackling
- Matt runs his own security consultancy called Ronin Security. His focus is information security management and he has a keen interest in infrastructure and web application security. He's a CISSP and the current Branch Executive of the Melbourne chapter of the Australian Information Security Association.
Blog Archive
-
▼
2009
(56)
-
▼
January
(17)
- It is hot
- Tool Kit
- PCI-DSS
- Access to security tools
- Cross Site Request Forgery in the Wild
- Builders vs breakers
- Pen testing is dead? Part two
- Pen testing is dead?
- nice article from grossman
- Ask a question
- What is the next big thing?
- Affiliate program now online
- What are the hard things to tackle that no one tal...
- Mandatory Internet Filtering
- just registered www.infamousagenda.com
- 2009 Predictions
-
▼
January
(17)
Labels
- AISA (1)
- australian information security market (1)
- career advice (1)
- causes (1)
- DoS (1)
- economics (1)
- FUD (1)
- futurism (1)
- information security governance (4)
- IPS (1)
- privacy (2)
- sacred cows (1)
- security patching (1)
- vulnerability management (1)
- webappsec (1)
Thursday, January 15, 2009
Subscribe to:
Post Comments (Atom)
Handy Links
Matt's list of blogs
-
-
-
TEDxMaui -- Hack Yourself First3 weeks ago
-
-
-
FedRAMP: It’s Here but Not Yet Here2 months ago
-
Bunraku V0.0.36 months ago
-
GoGrid Security Breach10 months ago
0 comments:
Post a Comment