Re: Assessment Methodology

robert_at_dyadsecurity.com
Date: 10/26/04

  • Next message: xyberpix: "RE: 0.0.0.0 Probes"
    Date: Mon, 25 Oct 2004 16:58:20 -0700
    To: Paul Ryan <pryan@rogers.wave.ca>
    
    

    Paul Ryan(pryan@rogers.wave.ca)@Mon, Oct 25, 2004 at 02:40:53PM -0400:
    > I am in the process of doing an audit on various portions of our IT
    > infrastructure. I wanted to know everyone's opinions on what the preferred
    > metric system is. I've been researching OCTAVE - my objective is to provide
    > a report with a scheme that easily reflects the status based on our current
    > policy. Something like pass,fail or compliance % - just brainstorming here

    We've always done tests based on what we can actually measure. We try to represent findings in terms that clearly articulate what we measured. As far as methodologies that we've seen, evaluated, and used, I have had the best practical results by using the Open Source Security Testing Methodology Manual (www.OSSTMM.org) from the Institute for Security and Open Methodologies (www.ISECOM.org).

    Robert

    -- 
    Robert E. Lee
    CTO, Dyad Security, Inc.
    W - http://www.dyadsecurity.com
    E - robert@dyadsecurity.com
    M - (949) 394-2033
    

  • Next message: xyberpix: "RE: 0.0.0.0 Probes"

    Relevant Pages

    • Assessment Methodology
      ... I am in the process of doing an audit on various portions of our IT ... infrastructure. ... I wanted to know everyone's opinions on what the preferred ... metric system is. ...
      (Security-Basics)
    • Re: How to JUDGE what is "Good COBOL"
      ... frequently states) the criteria set by the person signing the timesheet, ... Robert is presenting opinions and arguments; he is not requiring you to ... My point is that Robert ... Why should I value opinions that seem to exclude all or most COBOL ...
      (comp.lang.cobol)
    • Re: Layers, Levels, and DIP
      ... "Robert C. Martin" wrote in message ... layer. ... When the infrastructure is developed as a distinct ...
      (comp.object)
    • Re: Color code for home alarm wiring
      ... "Robert L Bass" wrote in message ... but that is open to opinions. ... You advertise it every chance you get here on the ...
      (alt.security.alarms)
    • Re: IPT payouts
      ... On Oct 13 2006 3:52 PM, Robert Rodriguez wrote: ... a not so friendly reminder of why I left RSB in the first place. ... I really don't need to justify my opinions, ... Jack is just blunt, that's all. ...
      (rec.sport.billiard)

  • Quantcast