Re: Pen Test and Sec Org



I think that this really has to do with what is driving the security need in the organization. In my case there is a great regulatory need, that is why this office is the authority for the organization. If you were a hosting provider, then there would be more of an IT Security need because the majority of the security functions performed are at the technical level.

There is no real wrong way to do this; just determine who the stakeholders are, and call a meeting.

Joshua Gimer

On May 5, 2008, at 3:54 AM, Soso Aboso wrote:

I am also very interseting on how to split the rsponsibilities

----- Original Message ----
From: Soso Aboso <sosokkam@xxxxxxxxx>
To: pen-test@xxxxxxxxxxxxxxxxx
Sent: Monday, May 5, 2008 12:26:01 PM
Subject: Pen Test and Sec Org

Greetings,

In the organization I work for there are two security team, one with enterprise role “Information Security” and their mean focus on governance, awareness, and risk assessment. The second team is for IT “IT Security” and their mean focus on IT security projects and managing the security Devices. The question I have, did any of you came through such organization structure, is it recommended, what standards support such security organization, who should be the owner of penetration tests in such organization?

Thanks you in advance for your feedback

Regards



____________________________________________________________________________________
Be a better friend, newshound, and
know-it-all with Yahoo! Mobile. Try it now. http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ



____________________________________________________________________________________
Be a better friend, newshound, and
know-it-all with Yahoo! Mobile. Try it now. http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • Re: File extensions spoofable in MSIE download dialog
    ... File extensions spoofable in MSIE download dialog ... I don't have internet explorer to test but rfc 2616 describes some "security considerations". ... > extension without a sign of EXE, and issue no Security Warning dialog ...
    (Bugtraq)
  • Re: Some mail opens a blank page
    ... YW, Dan, and thanks again for your valuable feedback. ... Save that download link and Product or User ID for CA Internet Security ... and then run the Removal Tool to rid the machine of all Norton crapware. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Short List of Security Questions
    ... Do you have a list of recommendations for windows? ... I think there are three separate aspects to PC security: ... get and download the latest Firefox and Thunderbird. ...
    (microsoft.public.security)
  • RE: Smiley central Active X controls
    ... security setting was selected. ... It still will not allow me to download ... Does NOT monitor behavior on the Internet ... Why some spyware services may mistake Fun Web Products and its MyWebSearch ...
    (microsoft.public.windowsxp.help_and_support)
  • The ISECOM Top 10 Real Computer Crimes for 2007 and Beyond
    ... over-hyping done in the security industry and to put things to perspective. ... The ISECOM Top 10 Real Computer Crimes for 2007 and Beyond ... it's the codec, the program, or the file so you download more and more ... try to buy stuff and ship it to Indonesia but your bank calls to alert you ...
    (Pen-Test)