State of Security

From: Dave (yodave@hargray.com)
Date: 03/18/02


Date: Mon, 18 Mar 2002 12:58:12 -0500
From: Dave <yodave@hargray.com>
To: pen-test@securityfocus.com

All,

I've been asked to speak before an executive audience (C*Os)
about the state of security. The group that's invited me wants
some data points for these folks, i.e., whether security is
improved/same, etc.

The problem I am having with all the material I've so far
encountered is that it's been provided by (you bet) C*Os.

Alfred Huger has request that you please direct
all responses to me (mailto:yodave@hargray.com)

I'll post the summary results to the list.

I appreciate that the questions are not specific. They are
only intended to help frame the presentation for the C*Os

Disclosure: I won't be paid for this presentation.

1: Our organizations' network security is better than it was prior to 911
(Y or N)

2: We have purchased and use better and more security technology than we
did prior to 911

Better (Y or N)
More (Y or N)

3: Our security posture is more proactive today than 6 months ago (Y or N)

4: Our organization acknowledges the importance of security and
has

a) revised policy accordingly (Y or N)
b) increased funding for security (Y or N)
c) made corresponding changes to our security services (Y or N)

5: Business continuity and disaster avoidance planning
has received the most attention and funding (Y or N)

6: The concern with business continuity and disaster avoidance
has diverted attention and funding from other security issues (Y or N)

Thanks in advance for your assistance.

Regards,

Dave

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • RE: SQL
    ... Subject: SQL ... >> This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Insurance
    ... property--data beign deemed "intangible" for the purposes of insurance. ... for physical security testing there are often 3rd parties ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Pen-Testing Lotus Notes/Domino
    ... Subject: Pen-Testing Lotus Notes/Domino ... of document security. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • R: Pen-Testing help (Compaq Insight & htsearch)
    ... This web server happens to be in front of their ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Application & Iplanet/Apache web server vulnerability and penetration testing
    ... I don't know what to do on the web servers other than delete example ... Any suggestions on iPlanet and Apache security? ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)