Re: SME risk assessment (Was: Bank Assessment)

From: fergus (fergus_at_cobbled.net)
Date: 04/24/04

  • Next message: Leewarner, Joshua (US - Seattle): "RE: Tools to test web services"
    Date: Fri, 23 Apr 2004 23:02:31 +0100
    To: pen-test@securityfocus.com
    
    

    On 23.04-09:57, Amit Deshmukh wrote:
    [ ... ]
    > ... would anyone know of
    > a simple risk assessment methodology that could be
    > employed for small to medium businesses?

    the problem is not the methodology it is the
    understanding. you need to understand the threat
    and risk on a number of levels to make an
    effective assessment.

    that is what you pay for at the end of the day;
    experience and knowledge.

    for a simple example, it would be difficult to implement
    a password policy if you do not understand the
    relevant issues; that comes down to users,
    distribution, environment, etc, etc. all these
    things are logical and if you have the necessary
    understanding then you do not need methodology -
    not for small businesses.

    it's basically an issue of common sense (once you
    can ably cover the issues).

    if you mean a vulnerability assessment or pen-test
    then you are better (for the small business
    sector) to simply use tools. nessus basically; it
    will be adequate for the target.

    the problem is that small companies have low value
    assets and most have very little relating to
    information/computers. even the ones that should
    know better (i.e. accountants and solicitors) are
    ill able to afford and digest a detailed report.
    they simply need a solution that puts them a
    couple of levels higher than the next guy.

    to summarise - perceived risk is low and therefore
    over investment in detailing actual risk is
    difficult, costly and unpopular.

    -- 
    : fergus cameron                :   [ .]        cobbled    :
    : ^^^^^^@cobbled.net            : [ ~][ ]             .net :
    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------
    

  • Next message: Leewarner, Joshua (US - Seattle): "RE: Tools to test web services"

    Relevant Pages

    • Re: project risk analysis
      ... I totally understand what you mean, I was in a similar place on a risk ... assessment - being thoroughly confused. ... it's applicable methodology to a number of different problem domains. ... 'Project Risk Management' Chapman and read it. ...
      (microsoft.public.project)
    • RE: Bank Assessment
      ... My thinking would be to not include pen testing with the risk ... the "risk assessment" is more of the political part of ... > pen testing experience in our state of the art hacking lab. ...
      (Pen-Test)
    • Re: How does a customer get PCI audited?
      ... You can be purple in the face with controls and training, but if you are never PROPERLY tested by a REAL team then you will never know where your REAL risks are. ... You must have a strong understanding of the threat and how the threat might align with your risk and exposure profile. ... Suggesting that anyone build controls without first having a GOOD and REAL assessment is horrible advice. ... PCI-DSS compliance is at least a small defence. ...
      (Security-Basics)
    • Re: while socialist new labours bbc try to distract with the the griffin circus....cameron prepares
      ... This would underwrite lending from banks to businesses? ... By underwriting the loans to businesses, ... government guarantees will of course lower the risk to the banks ...
      (uk.politics.misc)
    • Re: while socialist new labours bbc try to distract with the the griffin circus....cameron prepares
      ... By underwriting the loans to businesses, they will encourage lending to businesses because HMG has effectively said they'll step in if the loan goes bad. ... and to the businesses (that risk is then shifted to the population/ ...
      (uk.politics.misc)