RE: Security Audit

From: Christopher Ray (crayat_private)
Date: Thu Aug 30 2001 - 15:12:01 PDT

  • Next message: anindya: "Re: Using Airsnort through vmware on Red Hat 7.1"

    Simon,
    
    From personal experience with bidding on these type of contracts, there's a
    lot that can be involved with conducting these audits.  For example:
    
    - Is the audit a purely technical assessment or is the company you're
    looking at going to be reviewing policy, business practices, architecture,
    etc.
    - Is the company going to review each and every machine to include checks on
    the OS, applications, specific usage of services, etc.
    - Is physical penetration involved
    - Is there a remote assessment as well as an on-site assessment
    - Is training involved for the your personnel
    - Is the company going to be part of the "fix" or simply identify the
    problems
    - Last, but certainly not least, is a follow-up visit factored in
    
    Good luck,
    
    Christopher H. Ray, Director Technical Sales and Operations
    TTL Unlimited
    Phone: 210-710-1141
    Email: crayat_private
    
    -----Original Message-----
    From: Simon Wellborne
    [mailto:simon.wellborne@initiative-technology.co.nz]
    Sent: Wednesday, August 29, 2001 12:26 AM
    To: 'pen-testat_private'
    Subject: Security Audit
    
    
    Hello all,
    
    We have a company or two providing quotes on a security audit, including
    penetration tests.
    
    I am a little concerned about the amount of hours being quoted for some of
    these tests.
    
    From peoples experience (and I would like to hear from Professionals who
    comduct audits) about what timeframes are 'normally' used.
    
    Our network is relatively small (20-40 users + servers).
    
    Appreciate all replies
    
    Regards
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Tue Sep 04 2001 - 10:49:06 PDT