RE: Pen Test and Sec Org



I work for many customers that are set up in a similar manner, and would heartily recommend it. The core concept is to have a separation of duties, with one party performing the engineering/operation, and the other party providing the security requirements and assessing the system to determine any gap between implementation and requirements. This helps to avoid a conflict of interest where an engineer is assessing their own work. This is a pretty standard setup in mature security organizations. As for standards (United States federal, at least,) I would check out the NIST Special Publications series, specifically "SP 800-100 Information Security Handbook: A Guide for Managers." It's a solid overview of an entire security organization. It's tailored for US federal systems, but most of the theory applies to any larger organization.

All that said, I would put the pen tests under the "Information Security" group in your model.

Justin Townsend

I-Assure, LLC | Defense In Depth Solutions
justin.townsend@xxxxxxxxxxxx
________________________________________
From: listbounce@xxxxxxxxxxxxxxxxx [listbounce@xxxxxxxxxxxxxxxxx] On Behalf Of Soso Aboso [sosokkam@xxxxxxxxx]
Sent: Monday, May 05, 2008 2:54 AM
To: pen-test@xxxxxxxxxxxxxxxxx
Subject: Re: Pen Test and Sec Org

I am also very interseting on how to split the rsponsibilities

----- Original Message ----
From: Soso Aboso <sosokkam@xxxxxxxxx>
To: pen-test@xxxxxxxxxxxxxxxxx
Sent: Monday, May 5, 2008 12:26:01 PM
Subject: Pen Test and Sec Org

Greetings,

In the organization I work for there are two security team, one with enterprise role “Information Security” and their mean focus on governance, awareness, and risk assessment. The second team is for IT “IT Security” and their mean focus on IT security projects and managing the security Devices. The question I have, did any of you came through such organization structure, is it recommended, what standards support such security organization, who should be the owner of penetration tests in such organization?

Thanks you in advance for your feedback

Regards



____________________________________________________________________________________
Be a better friend, newshound, and
know-it-all with Yahoo! Mobile. Try it now. http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ



____________________________________________________________________________________
Be a better friend, newshound, and
know-it-all with Yahoo! Mobile. Try it now. http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



Relevant Pages

  • RE: Pen Test of a ESX Server
    ... Pen Test of a ESX Server ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • Re: How to report a Vulnerability to a Company
    ... in my eyes, unless you make it a habit of yours to pen test systems you weren't paid for, you shouldn't even try and hack them if you decide do something illegal I would expect that it is all a matter of time and money, how much for how long that company is willing to pay in order to find out who infiltrated their systems. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • RE: Block OS Detection
    ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • Re: Astalavista?
    ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)
  • Re: Port Scanner Challenge Revisited: Nmap, Unicornscan, Portbunny
    ... Need to secure your web apps NOW? ... Cenzic finds more, "real" vulnerabilities fast. ... buy it or download a solution FREE today! ...
    (Pen-Test)