RE: Bank Audit Best practices

From: Frank Knobbe (frank_at_knobbe.us)
Date: 03/24/04

  • Next message: Josh Tolley: "Re: FTP Window of opportunity?"
    To: Mike Shaw <mike@shawnuff.net>
    Date: Wed, 24 Mar 2004 02:05:39 -0600
    
    
    

    On Tue, 2004-03-23 at 10:19, Mike Shaw wrote:
    > * It's about *risk*management*. FI's don't understand many technical
    > things, but they understand this. Thus, many consultants end up looking
    > pretty silly to FI's when they can't tie technical benefit to risk reduction.

    In addition, links owned by processors etc are typically excluded from
    vulnerability studies, and sure as hell from pentests. But you can
    inquire about copies of the processors assessment. There are few
    technical solutions to the issues raised by linking via a router to a
    processor. If that link can be segmented and firewalled, fine. If not,
    then this is something that should be highlighted in a risk assessment.
    A vulnerability assessment should clearly mark it as excluded -- it can
    not make any assertions about it, regarding vulnerabilities or
    otherwise.

    It's a business decision. After all, it's a business partner, not a
    business scumbag, that they link up with. They may talk with each other,
    they may know something about their networks, they may work together,
    they may strive for security together, they rise and fall together. And
    I bet there are agreements and insurance policies that protect them from
    each other :)

    Regards,
    Frank

    
    



  • Next message: Josh Tolley: "Re: FTP Window of opportunity?"

    Relevant Pages

    • RE: Vulnerability Assessment vs. PenTest
      ... Vulnerability assessment ... as well as their assessment in terms of technical and/or ... Scope is left out. ... all trying to define our own standards for what we consider ...
      (Pen-Test)
    • RE: Email Pen-testing
      ... regular vulnerability assessment is usually the most useful approach ... Pentests do sometimes occur only to prove a point with management. ... Anything that broadens and increases security ... They should be followed by vulnerability studies, ...
      (Pen-Test)
    • Re: New Binary Bruteforcing Method Discovered
      ... Internet time, predating as it does the Internet) and the ... assessment world are converging. ... Unfortunately, the vulnerability ... Do You Yahoo!? ...
      (Vuln-Dev)
    • Re: Business model for penetration testing and vulnerability finding
      ... What should be agreen between client and tester before the beginning of work ( ... For a vulnerability assessment, I think that two documents: ... assessment. ... and continuous integration along with a formal software life ...
      (Pen-Test)
    • Re: CSA Payments
      ... assessment. ... Talk to your enterprise company about start-up help, ... your now in business and registering for tax purposes. ... Forget about CSA till ...
      (uk.gov.agency.csa)