Re: Security Audit
From: H C (keydet89@yahoo.com)Date: 09/13/01
- Previous message: José J. Cintrón: "Re: Brute force web/ftp/telnet tool"
- In reply to: R. DuFresne: "Re: Security Audit"
- Next in thread: R. DuFresne: "Re: Security Audit"
- Reply: R. DuFresne: "Re: Security Audit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Message-ID: <20010913004938.80679.qmail@web14606.mail.yahoo.com> Date: Wed, 12 Sep 2001 17:49:38 -0700 (PDT) From: H C <keydet89@yahoo.com> Subject: Re: Security Audit To: "R. DuFresne" <dufresne@sysinfo.com>, ben.nagy@marconi.com.au, proberts@patriot.net, danielc@compman.co.uk
For the most part, I agree with Ben's comments. For
completeness, a system can be as secure as possible if
a vulnerability assessment of that system is
conducted, and that information is then used to launch
a "full disclosure pen-test" or perhaps more
appropriately, a "verification analysis".
However, like anything else, this is only a snapshot
of the system in time. We then get into the change
control/management process, and where verification
testing fits in such a process.
> But any "analysis" process should include external
> verification - ie that
> the box is doing what you told it to do, right?
>
> This is quite distinct from the traditional pen-test
> in that it isn't blind.
>
> I think that to create the most secure system
> possible, blind pen-testing is
> a waste of time -
__________________________________________________
Do You Yahoo!?
Get email alerts & NEW webcam video instant messaging with Yahoo! Messenger
http://im.yahoo.com
----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/
- Previous message: José J. Cintrón: "Re: Brute force web/ftp/telnet tool"
- In reply to: R. DuFresne: "Re: Security Audit"
- Next in thread: R. DuFresne: "Re: Security Audit"
- Reply: R. DuFresne: "Re: Security Audit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|