Solved

Is ITIL an audit benchmark for vulnerability management

Posted on 2012-03-12
6
704 Views
Last Modified: 2012-03-15
Is ITIL more geared towards audit as opposed to vulnerability assessment?
Say for example if you looked at a set of web servers and found they were insecure due to multiple vulnerabilities, it is really an "as is" type review, as opposed to an "how things came to be this way", which I guess ITIL procedures could provide?

So could ITIL be used to identify "How things came to be that way" for security issues? If so are there any specific ITIL modules that focus specifically on security and security management?
0
Comment
Question by:pma111
  • 3
  • 3
6 Comments
 
LVL 6

Accepted Solution

by:
ashunnag earned 500 total points
ID: 37709559
ITIL is not security or security management course! it is a library of best practices and guidelines on how to develop and maintain you IT systems and make it align with business.

It contains modules about managing your services you offer to your clients or customers, how to develop them, provide them, maintain SLA and enhance your services continually.

if your looking for security audit and vulnerability, check CompTIA Sercurity+, CISM, or CISSP. these will help you alot.
0
 
LVL 3

Author Comment

by:pma111
ID: 37709630
What I was getting at however was, a pen test or vuln assessment just shows "as is - i.e. here are your security weaknesses", not "how this came to be - through poor patch mgmt/hardening/account mgmt these problems arose".

My question is what do you check to identify "how this came to be", what benchmarks or platofrms can be used in this area? ITIL seems to have access mgmt, account mgmt, patch mgmt etc.

I dont think waiting for a vuln assessment to flag up problems then apply quick fixes is a very good practice at all. They should serve as assurance or identify anything overlooked, but not be the justifacation to start doing things properly.
0
 
LVL 3

Author Comment

by:pma111
ID: 37709632
And im not after a course of qualifacation either.
0
Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

 
LVL 6

Expert Comment

by:ashunnag
ID: 37709839
No ITIL don't have Access management, account managemnt, patch management, .... it might talk about for better system development. if you are looking for such tools or references you should check ISO standards, or refer to the mentioned above courses they have what you need.
0
 
LVL 3

Author Comment

by:pma111
ID: 37709965
Any specific ISO standard?

I am after the management processes and a benchmark that can be used that will identify "How things came to be so insecure".

Surely there must exist such in the year 2012.

I am thinking NIST may be more what we are after.

http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf
0
 
LVL 6

Expert Comment

by:ashunnag
ID: 37713561
Yup NIST is one of the standards organizations and you can follow their standards and procedures.

For ISO refer to ISO 27000 standards, below is the link:
http://www.27000.org/
0

Featured Post

Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Router Security Commands. 2 46
Cisco ASA blocks some https sites. 27 64
Report to police 8 45
Behavior-based and anomalies detection for Trend Micro 2 26
The related questions "How do I recover the passwords for my Q-See DVR" and "How can I reset my Q-See DVR to eliminate a password" are seen several times a week.  Here we discuss the grim reality of the situation.
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question