RE: [fw-wiz] concerning ~el8 / project mayhem

From: Kalat, Andrew (ISS Atlanta) (akalat@iss.net)
Date: 08/19/02


From: "Kalat, Andrew (ISS Atlanta)" <akalat@iss.net>
To: "Barney Wolff" <barney@tp.databus.com>, "Paul D. Robertson" <proberts@patriot.net>
Date: Mon Aug 19 13:35:03 2002


>
> But seriously, I think a security expert owes it to the
> clients to follow the same guidelines s/he's touting.
> Otherwise you lose touch with the impact on the user of what
> you're prescribing.

That's often impossible for any security practitioner of any experience.
For that to be true in all cases, the clients of our fictional
consultant would have to be of very similar size, scope, focus, and
security budget as our consultant's company. It's simply not
conceivable.

A security consultant can be very effective in advising a Fortune 500
company how to secure their data center within their budget and desires
without having to a Fortune 500 themselves...

Note: Comments are my own, not my companies... Yadda... Yadda...

---------------------------------------------------------
Andrew J. Kalat, | Direct:(404)236-2713
                                        | Main: (404)236-2600
Internet Security Systems, Inc. | E-Mail: akalat@iss.net
6303 Barfield Road | <http://www.iss.net/>
Atlanta, GA 30328 | PGP key available.



Relevant Pages

  • RE: Dhcp security
    ... Setting up a 802.1x wired network requires: ... vendors, including Cisco, provide solutions to ensure that only properly ... trust agent collects security state information from multiple security ... software clients, such as anti-virus clients, and then communicates this ...
    (Focus-Microsoft)
  • Re: [Full-Disclosure] SSH vs. TLS
    ... > frowned upon by network ops and security. ... > - There must be a secure means by which all server keys are distributed to ... > appropriate ssh clients. ... > servers from using expired keys. ...
    (Full-Disclosure)
  • Re: Shared Win98 Printing in 2003 Mixed Domain
    ... are a lot of security settings - particularly security options in security ... network access:do not allow anonymous access to sam and sam and shares, ... manager authentication level to send ntlmv2 responses only, ... make sure that the W2003 servers are also wins clients. ...
    (microsoft.public.win2000.printing)
  • Re: Shared Win98 Printing in 2003 Mixed Domain
    ... are a lot of security settings - particularly security options in security ... network access:do not allow anonymous access to sam and sam and shares, ... manager authentication level to send ntlmv2 responses only, ... make sure that the W2003 servers are also wins clients. ...
    (microsoft.public.win2000.networking)
  • Re: Shared Win98 Printing in 2003 Mixed Domain
    ... are a lot of security settings - particularly security options in security ... network access:do not allow anonymous access to sam and sam and shares, ... manager authentication level to send ntlmv2 responses only, ... make sure that the W2003 servers are also wins clients. ...
    (microsoft.public.win2000.security)