RE: Proxy server hit... Any ideas?

From: Jonathan Bloomquist (bocasolutions@yahoo.com)
Date: 11/22/02

  • Next message: Hugo van der Kooij: "SMTP harrasment by nie2.infomail.es?"
    Date: Fri, 22 Nov 2002 10:45:32 -0800 (PST)
    From: Jonathan Bloomquist <bocasolutions@yahoo.com>
    To: incidents@securityfocus.com
    
    

    --- Mike Cain <mikec@lpinsurance.com> wrote:
    > Yeah, the box came to me basically because the guy
    > above me doesn't have
    > a clue about NT or about ANY security... Bad timing
    > I guess or good
    > depending on how you look at it... I have just got
    > back from meeting
    > with management to suggest some policies, now they
    > want me to write an
    > IT policies handbook, guess I asked for that one
    > huh? :)
    >
    > So where should I start looking for de-facto
    > policies, and such? Or
    > should I just use my best judgment? I'm thinking the
    > latter is a bad
    > idea because if one doesn't pan out, then they say,
    > "Well... YOU wrote
    > them..." :)

    I would start here:

    http://www.sans.org/newlook/resources/policies/policies.htm

    =====
    Jonathan Bloomquist, CISSP

    __________________________________________________
    Do you Yahoo!?
    Yahoo! Mail Plus – Powerful. Affordable. Sign up now.
    http://mailplus.yahoo.com

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: Proxy server hit... Any ideas?
      ... > IT policies handbook, guess I asked for that one huh? ... > learning the security scene A LOT less painful. ... I also recommend the short topics booklets on ... A Management Perspective," which are also useful to anyone in the security ...
      (Incidents)
    • Re: writing security policy
      ... Getting management support can sometimes be tricky. ... "feel the pain" of bad security. ... Next step after getting policies signed off is enforcing it. ...
      (comp.security.misc)
    • Re: Audit Framework
      ... > My company has recently asked me to perform a high-level security audit of ... > - General policies and procedures ... > - Password management ... > - Security training ...
      (Security-Basics)
    • Re: Presentation on Information Security
      ... > I need to convince my management that they should ... > impliment information security procedures etc. ... > concepts not a very technical one, just to convince my ... > Do You Yahoo!? ...
      (Security-Basics)
    • RE: Proxy server hit... Any ideas?
      ... > IT policies handbook, guess I asked for that one huh? ... RFC 2196 aka Site Security Handbook is usable on a technical level. ... Use standards as a checklist. ... For more information on this free incident handling, management ...
      (Incidents)