RE: [Full-Disclosure] Top 15 Reasons Why Admins Use Security Scanners

From: Joe User (joe.user_at_shaw.ca)
Date: 04/28/04

  • Next message: SGI Security Coordinator: "[Full-Disclosure] SGI Advanced Linux Environment security update #19"
    To: full-disclosure@netsys.com
    Date: Wed, 28 Apr 2004 11:47:01 -0600
    
    

    Now what are the top 15 security scanners that admin's use?

    Joe
    Kererra I.S.

    -----Original Message-----
    From: Joel R. Helgeson [mailto:joel@helgeson.com]
    Sent: April 28, 2004 1:36 AM
    To: full-disclosure@netsys.com
    Subject: [Full-Disclosure] Top 15 Reasons Why Admins Use Security
    Scanners

    Top 15 Reasons Why Admins Use Security Scanners

    This list has been compiled by emailing various Security/Admin lists...
    Anyone care to offer their input - add to the list?

    -Am I sure that I have found all vulnerabilities in my network?
    -Have I configured my network properly?
    -Am I finding and closing security holes fast enough?
    -How do I know which machines have a missing patch?
    -Are we resistant enough to network-savvy viruses that spread via known
    exploits?
    -Are we in compliance with HIPAA, Sarbanes-Oxley and other regulations?
    -What have I missed in locking down a server or environment?
    -Do I have my network perimeter and interior sufficiently protected?
    -Have I identified and protected my network resources from external threats?
    -Do I know which systems are now well protected?
    -How vulnerable are we from the inside?
    -How will I ever pass my IT Security Audits?
    -How do I locate computers on my network, that are not within compliance?
    -How do I report to Management that we have done all we could to lock down?
    -How do I detect unknown and/or rogue devices/connections?

    Joel R. Helgeson
    Director of Networking & Security Services
    SymetriQ Corporation

    "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll
    be warm for the rest of his life."

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: SGI Security Coordinator: "[Full-Disclosure] SGI Advanced Linux Environment security update #19"

    Relevant Pages

    • [fw-wiz] Re: Best Practices
      ... No matter how you slice the Internet connected network space up (financial, ... any security setup or general 'rules of thumb' so to speak. ... Now let's publish and promote those lists (or the process to create the ... the context of infrastructure and worm/virus attacks because people are up ...
      (Firewall-Wizards)
    • Re: Use iptables to block all non-US ssh traffic
      ... >> basicly class C addresses, That would be 16,777,216 network ... asking for the lists to begin with????? ... methods that are far more secure and far easier to manage that what you are ... Isn't security the reason you are doing this in the first ...
      (comp.os.linux.security)
    • [Full-Disclosure] Top 15 Reasons Why Admins Use Security Scanners
      ... Top 15 Reasons Why Admins Use Security Scanners ... This list has been compiled by emailing various Security/Admin lists... ... -Am I sure that I have found all vulnerabilities in my network? ... "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll ...
      (Full-Disclosure)
    • Re: [Full-disclosure] Corporate Virus Threats
      ... I think this thread is more appropriate for focus-virus and not Full-disclosure. ... can we have more Full-Disclosure lists setup for ... FD voice over internet protocol list - discussion of VoIP security issues ... FD bug disclosures list - discussion of new security threats and analysis ...
      (Full-Disclosure)
    • RE: [Full-disclosure] Corporate Virus Threats
      ... An opportunity to focus and filter the broad spectrum of security issues ... Subject: [Full-disclosure] Corporate Virus Threats ... Full-Disclosure should setup its own dedicated lists for individual ...
      (Full-Disclosure)