We are looking at starting an internal "white hat" security team made up of some of our tech savvy employees.  These users would, from time to time, try to access folders they shouldn't have access to, try to make themselves domain admins, try to change other users' passwords, etc.  This would be in addition to their primary duties.  Does anyone know of something like this being done?  I know outside firms are available to do security testing, but it might be advantageous to have our own team.  Thanks for any feedback!
chiefsmanSystems AdministratorAsked:
"Does anyone know of something like this being done?" - sure, why not. As long as those people try those "attacks" (if any) on test networks first, go ahead.
What do you want to know in particular?
i would make damned sure those employees are legit.  That's all you need is for one of them to find an exploit and not tell you about it.
chiefsmanSystems AdministratorAuthor Commented:
We just want to make sure our network stays as secure as possible and was curious if anyone else did this.  Thanks!
But what if anyone else does this, do you feel supported in doing this?
It surely depends on how you let them do this. If they run tools and they don't know how those work, they might disrupt working.
chiefsmanSystems AdministratorAuthor Commented:
Yeah, we have a lot of questions.  We were just seeing if anyone else is doing this so we could get some tips on how they are doing it and if it has been successful.
Thing is: what expertise would they need to find more than the admin? A lot. Unless the admin has failed to do his job properly, they will maybe find nothing at all. I'd vote for having your network pentested/audited by professionals.

btanExec ConsultantCommented:
You can still have an internal security team setup to do such review and security acceptance but most of the time, the objective is to ensjre independent assessment done rather tham having same admin team to do it. Who guards the guards. The competency and certified party varied and compliance needs may not necessary allows internal team unless strong justification provider. There are penetration testing standard publicly available to kickstart. Note that revjew should not be audit unless that is the intent. Audit requires independent party so internal is mostly not engaged though helps in preparing the internal.
