Solved

Security Assessments

Posted on 2009-05-05
10
498 Views
Last Modified: 2012-05-06
Experts,

I wonder if you could provide a basic overview on what types of security assessment, audits etc you perform on your IT infrastrucuture, and how often you perform it, i.e. assess your firewall every quarter, your physical security every 6 months, your IDS 6 monthly etc etc.

We have come up with some plans to fit in security assessments of certain components of our IT infrastructure and security, to be performed by an external vendor but would just like to compare the plans to your setup.

Any pointers most welcome, and timelines on how often you assess certain parts of your IT setup, infrastructure and key systems would be most appreciated.

Regards
0
Comment
Question by:pma111
  • 5
  • 4
10 Comments
 
LVL 32

Assisted Solution

by:Kamran Arshad
Kamran Arshad earned 150 total points
Comment Utility
Hi,

You need to place the IT Security Policy which includes assessment as well. There are many security policy templates available on Internet. A few are as below;

www.sans.org/resources/policies/
www.ruskwig.com/security_policies.htm
www.dir.state.tx.us/security/policies/templates.htm
www2.wlv.ac.uk/its/everyone/projects_and_policies/info_security_policy.pdf
www.altiusit.com/policies.htm
0
 
LVL 3

Author Comment

by:pma111
Comment Utility
Hi uetian1707:

We do have a policy in place, it was more just to get a flavour of how accurate our policy was in terms of the assessment, and how others assess which parts of their IT infrastrucuture and how often.

Regards
0
 
LVL 51

Expert Comment

by:ahoffmann
Comment Utility
do you have web servers also in your IT infrastructure?
0
 
LVL 3

Author Comment

by:pma111
Comment Utility
Hi ahoffman, yes we do...
0
 
LVL 51

Expert Comment

by:ahoffmann
Comment Utility
should your web applications be part off the assessment?
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 
LVL 3

Author Comment

by:pma111
Comment Utility
Anything really specific to IT infrastructure, major web based apps (Oracle etc)... Just wanted to see other peoples IT assessment schedules as a point of reference more than anything
0
 
LVL 51

Accepted Solution

by:
ahoffmann earned 350 total points
Comment Utility
web based assessments are very different to traditional network security tests.
There're not much tools for that, most tests need to be done manually from experienced people.
If someone offers security testing including web apps, and then hands over a beautified nessus or nmap report, you could be sure that it's not worth reading it (except for your amusement:).

Just my 2 pence about pen testing web apps.
0
 
LVL 3

Author Comment

by:pma111
Comment Utility
Thanks ahoffman, thanks for the tip..

I would be interesting to hear how often and what parts of your network (outside the web apps) do your company by someone in to test, i.e. every 6months?
0
 
LVL 51

Expert Comment

by:ahoffmann
Comment Utility
I'm not used to network test (beside web apps are involved), hence cannot give valuable information, sorry.

For the network itself, a tests every 6 month and/or when the network or its components chage should be more than sufficient, IMHO.
0
 
LVL 3

Author Comment

by:pma111
Comment Utility
Thanks for the pointers ahoffman
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
turbotax on windows 10 57
nmap scanner? 7 77
Cheap SSL Certificates 3 54
How to best manage folder and file security 4 29
Nothing in an HTTP request can be trusted, including HTTP headers and form data.  A form token is a tool that can be used to guard against request forgeries (CSRF).  This article shows an improved approach to form tokens, making it more difficult to…
Never store passwords in plain text or just their hash: it seems a no-brainier, but there are still plenty of people doing that. I present the why and how on this subject, offering my own real life solution that you can implement right away, bringin…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now