RE: How much do you disclose to customers?

From: Gary Everekyan (geverekyan_at_univision.net)
Date: 12/19/03

  • Next message: Martin Mačok: "Re: How much do you disclose to customers?"
    Date: Thu, 18 Dec 2003 20:00:20 -0500
    To: <pen-test@securityfocus.com>
    
    

    In general...
    It all depends on the agreement. Usually the agreement is with executive
    level and they may pose time and ingress restrictions.
    It is important to define the scope, deliverables and stick to it.
    (when, from where, which tests, which members of MIS will participate,
    etc)
    As always having more recourses (people, tools, source addresses etc)
    will help greatly.

    Regards,
     
    Gary Everekyan
    CISSP, CISM, MCSE, MCT
    Information Security Manager
    Security and Audit
     

    -----Original Message-----
    From: Alfred Huger [mailto:ah@securityfocus.com]
    Sent: Thursday, December 18, 2003 3:14 PM
    To: pen-test@securityfocus.com
    Subject: How much do you disclose to customers?

    I am posting this for a user who is having difficulty posting directly
    to the list. Please reply to the list.

    -al

    To: Joe P <joe_nasdaq@yahoo.com>
    Cc: pen-test@securityfocus.com
    Subject: Re: How much do you disclose to customers?

    On Tue, 16 Dec 2003, Joe P wrote:

    > Hi everyone,
    >
    > I have a question on customer disclosure. Is it wise to tell the
    customer which IP addresses you'll be
    using before starting pen tests?
    >
    > Cons for Telling:
    > I was thinking that if you did tell them you may get an over zealous,
    insecure admin that just sets up a
    filter to block you out to make him/herself look good.
    >
    > Pros for Telling:
    > 1) if you don't tell them your IP address they may think your doing
    testing when in actuallity it's someone
    else (ie: a true cracker trying to break in).
    > 2) Audit trail reasons - if you trip up an IDS while doing testing
    > they
    can ignore those alarms.
    >
    > Also, how do testers handle multiple IP addresses? Is there any
    > benefit
    to doing it from multiple IP
    addresses??
    >
    > How do testers distribute a test amongst multiple people?
    >
    > Lastly, do you keep logs of tests performed just to cover yourself?
    (Ie: "Our server crashed on Saturday,
    it must have been something you did!!"")
    >
    > thanks ahead of time,
    > Joe
    >
    >
    >

    Alfred Huger
    Symantec Corp.

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ----
    The information contained in this e-mail and any attached documents 
    may be privileged, confidential and protected from disclosure.  If you 
    are not the intended recipient you may not read, copy, distribute or 
    use this information.  If you have received this communication in 
    error, please notify the sender immediately by replying to this 
    message and then delete it from your system.
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Martin Mačok: "Re: How much do you disclose to customers?"

    Relevant Pages

    • Re: Screwed By Verizon!! BEWARE!!!!!
      ... agreement were provided as outlined for the life of that agreement. ... Once the contract expires, they are free to do whatever they like and so ... I've seen plenty of threads here about VZW ... your customers to see you-- in an adversarial, ...
      (alt.cellular.verizon)
    • Re: compromise agreements
      ... and made a compromise agreement with this employer and in the section ... under confidential info - it says not to use, ... information of the company which includes the list of customers, ... saying i broke this compromise agreement by contacting my ex-employers ...
      (uk.legal)
    • Re: Using Ogust
      ... If you know that every so often your partner will bid 2NT on a weak hand ... so yourself] then that is a disclosable agreement: ... pairs who play it do their best to disclose it adequately. ...
      (rec.games.bridge)
    • Re: Network topology questions from a new sbs user
      ... of the agreement and right to use the software. ... install the AP for their customers where the customer was in total ... resellers, consultants, VARs, value-added providers, system integrators, ... developers, system builders, hosts, service providers or IT professionals ...
      (microsoft.public.windows.server.sbs)
    • Re: how to conserv ink on Canon ip3000?
      ... >>disclose because they have earned the trust of their customers. ... > BEDCAUSE THEY DO NOT LABEL WHAT THEY SELL PROPERLY AND DO NOT ... If that doesn't suit you then you need to find an ink vendor that does ...
      (comp.periphs.printers)