<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-420</id>
	<title>Nabble - Libnet</title>
	<updated>2009-06-10T12:08:58Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Libnet-f420.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Libnet-f420.html" />
	<subtitle type="html">Discuss Libnet packet creation library</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-23968975</id>
	<title>Add support for a new frame type</title>
	<published>2009-06-10T12:08:58Z</published>
	<updated>2009-06-10T12:08:58Z</updated>
	<author>
		<name>Ck_Noob</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I'm new to libnet, and I'm trying to add support for a new frame format in libnet as part of a project I've to do. Could anyone point me to the files and existing functions where I will need to add/edit code to add the data structures and APIs to accomplish this task?
&lt;br&gt;&lt;br&gt;Thanks! </content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Add-support-for-a-new-frame-type-tp23968975p23968975.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-3187301</id>
	<title>how to use libnet in ARM</title>
	<published>2006-03-01T09:22:10Z</published>
	<updated>2006-03-01T09:22:10Z</updated>
	<author>
		<name>sriram-newbie</name>
	</author>
	<content type="html">hello ppl,

we are doing our project basically in N\W and it needs to use libnet and we are stuck up with a problem ..the problem is we need to use libnet in pc and ARM board back and forth while using libnet in pc it works well while using it ARM board its not working good is there any prob with respect to Endianess..please help us out.

Newbie</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/how-to-use-libnet-in-ARM-tp3187301p3187301.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-591824</id>
	<title>Bay Area Security User Group</title>
	<published>2005-08-08T05:29:15Z</published>
	<updated>2005-08-08T05:29:15Z</updated>
	<author>
		<name>Salaets, Steven</name>
	</author>
	<content type="html">&lt;html xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:st1=&quot;urn:schemas-microsoft-com:office:smarttags&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;
&lt;o:SmartTagType namespaceuri=&quot;urn:schemas-microsoft-com:office:smarttags&quot; name=&quot;City&quot; /&gt;
&lt;o:SmartTagType namespaceuri=&quot;urn:schemas-microsoft-com:office:smarttags&quot; name=&quot;place&quot; /&gt;
&lt;!--[if !mso]&gt;
&lt;style&gt;
st1\:*{behavior:url(#default#ieooui) }
&lt;/style&gt;
&lt;![endif]--&gt;


&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;All,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;I recently moved from &lt;st1:City w:st=&quot;on&quot;&gt;Paris&lt;/st1:City&gt;
to the Bay Area, working for a company named &lt;st1:place w:st=&quot;on&quot;&gt;Wind River&lt;/st1:place&gt;
where I am responsible for Information Security and currently I try to
establish a security group in the bay area. The goal is to provide a forum for
experts to encourage discussion and share expertise in understanding the latest
trends and security threats facing computer networks, systems and data. &lt;br&gt;
&lt;br&gt;
Members should be Information Security practitioners, managers, network administrators,
etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;The meetings are intended to be performed on a monthly basis.
The location hasn&amp;#8217;t been verified yet but I am looking at hosting the
event in &lt;st1:City w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;Alameda&lt;/st1:place&gt;&lt;/st1:City&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;The meetings will not be used for solicitation purposes from
any vendors. Although, some speakers may be from specific vendors, the emphasis
will be on the concepts and solutions and not specific products or services.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Contact me if you are interested in becoming a member and everything
is still open for discussions therefore feel free to email me suggestions. Remember:
the plan is to establish the possibility to exchange of knowledge and skills
among a wide variety of information security experts.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Steven Salaets&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Bay-Area-Security-User-Group-tp591824p591824.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-574788</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-08-04T09:09:40Z</published>
	<updated>2005-08-04T09:09:40Z</updated>
	<author>
		<name>Richard Sullivan-2</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;quot;Measuring IT security&amp;quot; is
a broad concept, but a comprehensive risk assessment is the best way to
gage overall security posture. Vulnerability assessment is just one piece
of that. Standards for best practice, like ISO17799, force you to consider
every part of your organization as it relates to infosec. There are many
risk assessment frameworks, guidelines and tools available from sites like
sans.org, nist.gov, issa.org, etc., as well as commercial offerings.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Unfortunately, there's no cut &amp;amp;
dried scoring system, nor a universally adopted measurement standard, so
keep your expectations (and management's expectations) realistic. Involve
EVERYONE in your assessment and in your security program. I've seen companies
ignore outside contractors, cleaning services and maintenance workers because
they weren't permanent, full-time employees. That's like ignoring the key
under the door mat.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;- Rich&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
&lt;/font&gt;
&lt;p&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;table width=100%&gt;
&lt;tr valign=top&gt;
&lt;td width=40%&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;&lt;b&gt;&amp;quot;Toto A Atmojo&amp;quot;
&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574788&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;&amp;gt;&lt;/b&gt; &lt;/font&gt;
&lt;p&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;07/28/2005 06:02 AM&lt;/font&gt;
&lt;td width=59%&gt;
&lt;table width=100%&gt;
&lt;tr valign=top&gt;
&lt;td&gt;
&lt;div align=right&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;To&lt;/font&gt;&lt;/div&gt;
&lt;td&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574788&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;&amp;gt;,
&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574788&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574788&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;&amp;gt;,
&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574788&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574788&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;&amp;gt;,
&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574788&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574788&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&amp;gt;&lt;/font&gt;
&lt;tr valign=top&gt;
&lt;td&gt;
&lt;div align=right&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;cc&lt;/font&gt;&lt;/div&gt;
&lt;td&gt;
&lt;tr valign=top&gt;
&lt;td&gt;
&lt;div align=right&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;Subject&lt;/font&gt;&lt;/div&gt;
&lt;td&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;Is there any way to measure IT Security??&lt;/font&gt;&lt;/table&gt;
&lt;br&gt;
&lt;table&gt;
&lt;tr valign=top&gt;
&lt;td&gt;
&lt;td&gt;&lt;/table&gt;
&lt;br&gt;&lt;/table&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Dear all,&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Currently I&amp;#8217;m looking for a tool, or a technique
to measure IT security?&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;The baseline for security is CIA (Confidentiality,
Integrity and Availability), that is every organization which want to called
secure must be guarantee that their system comply this matter.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;But the problem is, we need a tool/technique
to measure how secure are we. Therefore, wee need a tool/technique to measure
how close that our system status now to CIA.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Please share your experience about this matter.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;If there any link about this issue, I really
appreciate if you share to us (You may contact me privately) .&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Best Regs,&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Toto&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505323p574788.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-548927</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-08-03T09:34:56Z</published>
	<updated>2005-08-03T09:34:56Z</updated>
	<author>
		<name>Alberto Cardona II</name>
	</author>
	<content type="html">Larry,
&lt;br&gt;&lt;br&gt;I have worked for major fortune 100 and 500 companies. &amp;nbsp;Some of these 
&lt;br&gt;companies use a product called Enterprise Security Management and is made by 
&lt;br&gt;Archer (www.archer-tech.com). &amp;nbsp;It is highly customizable and you are able to 
&lt;br&gt;setup different metrics to monitor. &amp;nbsp;It ties in and correlates the different 
&lt;br&gt;facets of an InfoSec program:
&lt;br&gt;&lt;br&gt;- Threat Management
&lt;br&gt;- Incident Management
&lt;br&gt;- Asset Management
&lt;br&gt;- Risk Management
&lt;br&gt;- Policy Management
&lt;br&gt;&lt;br&gt;&lt;br&gt;You can set up different gauges, metrics and report on your company security 
&lt;br&gt;posture.
&lt;br&gt;Below are the different modules:
&lt;br&gt;&lt;br&gt;Incident Management:
&lt;br&gt;Report incidents, manage their escalation, track investigations and analyze 
&lt;br&gt;resolutions.
&lt;br&gt;Key features:
&lt;br&gt;- Based on the CERT Security Incident Response Handbook
&lt;br&gt;- Easily open, prioritize and track security incidents with built-in 
&lt;br&gt;workflow.
&lt;br&gt;- Perform impact analyses of incidents on critical assets and business 
&lt;br&gt;processes.
&lt;br&gt;- Manage incident escalation, investigations and forensic activities.
&lt;br&gt;- Track remediation efforts and document incident postmortem.
&lt;br&gt;- Manage response team contact information, processes and procedures.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Threat Management:
&lt;br&gt;Track threats through a comprehensive early warning system to help prevent 
&lt;br&gt;system compromise.
&lt;br&gt;Key features:
&lt;br&gt;- Receive real-time intelligence feeds from iDEFENSE, Symantec or TruSecure.
&lt;br&gt;- Filter alert notifications based on your environment.
&lt;br&gt;- Prioritize remediation plans and corrective actions.
&lt;br&gt;- Utilize a CVE-compliant threat and vulnerability database.
&lt;br&gt;- Integrate with your existing vulnerability scanning tools.
&lt;br&gt;- Search for data using a powerful reporting engine with built-in and custom 
&lt;br&gt;reports.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Asset Management:
&lt;br&gt;Manage enterprise assets and their relationships to secure them according to 
&lt;br&gt;management expectations.
&lt;br&gt;Key features:
&lt;br&gt;- Build the asset database
&lt;br&gt;- Define groups of assets and assign individual responsibilities.
&lt;br&gt;- Tie policies, baselines and procedures to specific assets
&lt;br&gt;- Filter real-time alerts based on the assets under your control
&lt;br&gt;- Manage the activities required to secure those assets.
&lt;br&gt;- Document business criticality for an asset in terms of confidentiality, 
&lt;br&gt;integrity and availability.
&lt;br&gt;- Link critical assets to the business processes they support.
&lt;br&gt;- Fully integrate with Archer Policy, Threat, Risk and Incident Management 
&lt;br&gt;solutions.
&lt;br&gt;- Import data from third-party discovery, scanning and asset management 
&lt;br&gt;tools.
&lt;br&gt;- Track vulnerabilities, remediation efforts and configuration changes.
&lt;br&gt;- Tie in to Change Managment System
&lt;br&gt;- Filter real-time alerts and other security content.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Utilize advanced reporting and analysis tools.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Risk Management:
&lt;br&gt;&lt;a href=&quot;http://www.archer-tech.com/solutions/riskmgmt.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.archer-tech.com/solutions/riskmgmt.html&lt;/a&gt;&lt;br&gt;Perform online risk assessments to determine the proper controls to 
&lt;br&gt;implement based on use and risk.
&lt;br&gt;Key features:
&lt;br&gt;- Utilize integrated risk management methodology based on industry 
&lt;br&gt;standards.
&lt;br&gt;- Generate Online risk assessment questionnaires
&lt;br&gt;- Generate Asset risk scorecards and actionable plans for managing your 
&lt;br&gt;enterprise information risk.
&lt;br&gt;- Automate the risk assessment process.
&lt;br&gt;- Employ predefined and customizable assessment templates.
&lt;br&gt;- Build online risk assessment questionnaires.
&lt;br&gt;- Create risk scorecards and profiles.
&lt;br&gt;- Search for data using advanced management reporting tools.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Policy Management:
&lt;br&gt;&lt;a href=&quot;http://www.archer-tech.com/solutions/policymgmt.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.archer-tech.com/solutions/policymgmt.html&lt;/a&gt;&lt;br&gt;Create policies, distribute them online, educate and train employees and 
&lt;br&gt;track compliance.
&lt;br&gt;Key features:
&lt;br&gt;- Creation and Administration:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Link policies to the industry, regulatory or corporate standards they 
&lt;br&gt;support.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Attach relevant files to policies (procedures, flowcharts, examples, 
&lt;br&gt;images, etc.).
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Utilize content workflow features for version control and management 
&lt;br&gt;approval.
&lt;br&gt;- Communication and Distribution
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Display policies to users in an easy-to-understand tree format.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Filter and view policies by job function.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Alert users of changes to existing policies or new policies via email.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Allow users to perform keyword searches to quickly find specific 
&lt;br&gt;information among policies.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Enable users to export policy content directly into Word, Excel, HTML, 
&lt;br&gt;CSV or XML formats.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Set up, maintain and moderate discussion forums for specific users and 
&lt;br&gt;groups.
&lt;br&gt;- Tracking and Reporting
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Receive online acknowledgement that users have read and accepted 
&lt;br&gt;specific policies.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Monitor and report on user access to specific policies.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Track exceptions that have been granted for specific policies and the 
&lt;br&gt;dates exceptions will expire.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Allow users to report policy violations.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Track policy violations by date of occurrence and date of remediation 
&lt;br&gt;for compliance.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Utilize the full policy compliance reporting capability.
&lt;br&gt;- Policy Library
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Access a library of policies and standards that have been developed by 
&lt;br&gt;leading information &amp;nbsp; security subject matter experts for managing 
&lt;br&gt;compliance with industry regulations and industry-specific legislation.
&lt;br&gt;- All standards in the Policy Library have been mapped to the following 
&lt;br&gt;leading industry standards:
&lt;br&gt;&amp;nbsp; ISO/IEC 17799 (Code of Practice for Information Security Management)
&lt;br&gt;&amp;nbsp; Information Security Forum (The Forum?s Standard of Good Practice)
&lt;br&gt;&amp;nbsp; FFIEC Security Handbook
&lt;br&gt;&amp;nbsp; Health Insurance Portability Accountability Act (HIPAA) Final Ruling
&lt;br&gt;&amp;nbsp; European Union Directive on Data Protection
&lt;br&gt;&amp;nbsp; Basel II
&lt;br&gt;&amp;nbsp; CobIT
&lt;br&gt;&amp;nbsp; COSO
&lt;br&gt;&amp;nbsp; Monetary Authority of Singapore?s ?Technology Risk Management Guidelines
&lt;br&gt;&lt;br&gt;&lt;br&gt;Kind regards,
&lt;br&gt;&lt;br&gt;&lt;br&gt;Alberto Cardona II, CCSE, MCP, CNA
&lt;br&gt;VP of Information Security - Professional Services
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;From: &amp;quot;Larry Marin (Irony Account)&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548927&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;To: Toto A Atmojo &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548927&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;CC: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548927&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;,&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548927&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;, 
&lt;br&gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548927&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;,&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548927&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;, 
&lt;br&gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548927&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;,&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548927&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;, 
&lt;br&gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548927&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt;Subject: Re: Is there any way to measure IT Security??
&lt;br&gt;&amp;gt;Date: Thu, 28 Jul 2005 12:29:57 -0400
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;You should check out NSA IAM/IEM Methodology...it works well for me.
&lt;br&gt;&amp;gt;&lt;a href=&quot;http://www.iatrp.com/iam.cfm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Toto A Atmojo wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Dear all,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Currently I?m looking for a tool, or a technique to measure IT security?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;The baseline for security is CIA (Confidentiality, Integrity and 
&lt;br&gt;&amp;gt;&amp;gt;Availability), that is every organization which want to called secure must 
&lt;br&gt;&amp;gt;&amp;gt;be guarantee that their system comply this matter.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;But the problem is, we need a tool/technique to measure how secure are we. 
&lt;br&gt;&amp;gt;&amp;gt;Therefore, wee need a tool/technique to measure how close that our system 
&lt;br&gt;&amp;gt;&amp;gt;status now to CIA.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Please share your experience about this matter.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;If there any link about this issue, I really appreciate if you share to us 
&lt;br&gt;&amp;gt;&amp;gt;(You may contact me privately) .
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Best Regs,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Toto
&lt;br&gt;&amp;gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't
&lt;br&gt;&lt;br&gt;Learn the hacker's secrets that compromise wireless LANs. Secure your
&lt;br&gt;WLAN by understanding these threats, available hacking tools and proven
&lt;br&gt;countermeasures. Defend your WLAN against man-in-the-Middle attacks and
&lt;br&gt;session hijacking, denial-of-service, rogue access points, identity
&lt;br&gt;thefts and MAC spoofing. Request your complimentary white paper at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&lt;/a&gt;&lt;br&gt;-------------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505323p548927.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-548608</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-08-03T03:21:02Z</published>
	<updated>2005-08-03T03:21:02Z</updated>
	<author>
		<name>aj-4</name>
	</author>
	<content type="html">Basically IT Security covers a gamut of areas, i am just listing some , on the fly
&lt;br&gt;&lt;br&gt;* Antivirus Solutions
&lt;br&gt;* Intrusion Prevention
&lt;br&gt;* Intrusion Detection
&lt;br&gt;* Patch Management
&lt;br&gt;* Firewall
&lt;br&gt;* VPN Gateway
&lt;br&gt;* Vulnerability Assessment &amp; Reporting
&lt;br&gt;* Identity Access Management (single-sign-on, SOX/HIPAA/GLB compliance....)
&lt;br&gt;* Network Security
&lt;br&gt;* Security Policy Compliance Management
&lt;br&gt;* AntiSpam (mail protection software)
&lt;br&gt;* Web Content Filtering
&lt;br&gt;&lt;br&gt;I'm not sure whether we have one-size-fits-all solution which can help us in measuring your enterprise IT Security posture.
&lt;br&gt;&lt;br&gt;I can list some good tools i have come across personally like NMap, ScanFi, Nessus, IdentityAccess Manager,GFI ....but the list is endless, so give them a try in google :-)
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message -----
&lt;br&gt;From: &amp;quot;Gary Everekyan&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548608&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;karo.onnik@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548608&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548608&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Is there any way to measure IT Security??
&lt;br&gt;Date: Tue, 02 Aug 2005 14:32:30 -0400
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Google Risk reporting and you will get whole list of research links.
&lt;br&gt;&amp;gt; It would also be helpful to look at owasp www.owasp.org
&lt;br&gt;&amp;gt; HTH
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Gary Everekyan
&lt;br&gt;&amp;gt; CISSP, CISM, ISSAP, ISSPCS, MCSE, MCT
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548608&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;garyeve@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;quot;High achievement always takes place in the framework of high 
&lt;br&gt;&amp;gt; expectation&amp;quot; -Jack Kinder
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &amp;quot;Larry Marin (Irony Account)&amp;quot; [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548608&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Date: 08/02/2005 01:09 PM
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; You should check out NSA IAM/IEM Methodology...it works well for me.
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.iatrp.com/iam.cfm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Toto A Atmojo wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Dear all,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Currently Im looking for a tool, or a technique to measure IT security?
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; The baseline for security is CIA (Confidentiality, Integrity and 
&lt;br&gt;&amp;gt; &amp;gt; Availability), that is every organization which want to called 
&lt;br&gt;&amp;gt; &amp;gt; secure must be guarantee that their system comply this matter.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; But the problem is, we need a tool/technique to measure how 
&lt;br&gt;&amp;gt; &amp;gt; secure are we. Therefore, wee need a tool/technique to measure 
&lt;br&gt;&amp;gt; &amp;gt; how close that our system status now to CIA.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Please share your experience about this matter.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; If there any link about this issue, I really appreciate if you 
&lt;br&gt;&amp;gt; &amp;gt; share to us (You may contact me privately) .
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Best Regs,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Toto
&lt;br&gt;&amp;gt; &amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;___________________________________________________________
&lt;br&gt;Sign-up for Ads Free at Mail.com
&lt;br&gt;&lt;a href=&quot;http://promo.mail.com/adsfreejump.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://promo.mail.com/adsfreejump.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't
&lt;br&gt;&lt;br&gt;Learn the hacker's secrets that compromise wireless LANs. Secure your
&lt;br&gt;WLAN by understanding these threats, available hacking tools and proven
&lt;br&gt;countermeasures. Defend your WLAN against man-in-the-Middle attacks and
&lt;br&gt;session hijacking, denial-of-service, rogue access points, identity
&lt;br&gt;thefts and MAC spoofing. Request your complimentary white paper at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&lt;/a&gt;&lt;br&gt;-------------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505323p548608.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-542736</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-08-02T12:32:30Z</published>
	<updated>2005-08-02T12:32:30Z</updated>
	<author>
		<name>Gary Everekyan-2</name>
	</author>
	<content type="html">&lt;font style='{font-family: Arial,Verdana, Sans-Serif;font-size: 10pt;}'&gt;
&lt;FONT size=2&gt;
&lt;P&gt;Google Risk reporting and you will get whole list of research links.&lt;/P&gt;
&lt;P&gt;It would also be helpful to look at owasp &lt;/FONT&gt;&lt;A href=&quot;https://www.bluetie.com/cgi-bin/www.owasp.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff size=2&gt;www.owasp.org&lt;/U&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;FONT size=2&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;&lt;/FONT&gt;&lt;FONT size=2&gt;
&lt;P&gt;&lt;br&gt;
&lt;/FONT&gt;&lt;FONT size=2&gt;&lt;FONT face=&quot;Times New Roman&quot;&gt;Gary Everekyan&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;CISSP, CISM, ISSAP, ISSPCS, MCSE, MCT&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=542736&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;garyeve@...&lt;/a&gt;&lt;br&gt;
&quot;High achievement always takes place in the framework of high expectation&quot; -Jack Kinder&lt;/P&gt;&lt;/FONT&gt;&lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
&lt;B&gt;From:&lt;/B&gt; &quot;Larry Marin (Irony Account)&quot; [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=542736&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;]&lt;br&gt;
&lt;B&gt;Date:&lt;/B&gt; 08/02/2005 01:09 PM&lt;br&gt;
&lt;br&gt;
You should check out NSA IAM/IEM Methodology...it works well for me.&lt;br&gt;
&lt;A href=&quot;http://www.iatrp.com/iam.cfm&quot; target=_blank rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/A&gt;&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Toto A Atmojo wrote:&lt;br&gt;
&lt;br&gt;
&amp;gt; Dear all,&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; Currently Im looking for a tool, or a technique to measure IT security?&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; The baseline for security is CIA (Confidentiality, Integrity and &lt;br&gt;
&amp;gt; Availability), that is every organization which want to called secure &lt;br&gt;
&amp;gt; must be guarantee that their system comply this matter.&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; But the problem is, we need a tool/technique to measure how secure are &lt;br&gt;
&amp;gt; we. Therefore, wee need a tool/technique to measure how close that our &lt;br&gt;
&amp;gt; system status now to CIA.&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; Please share your experience about this matter.&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; If there any link about this issue, I really appreciate if you share &lt;br&gt;
&amp;gt; to us (You may contact me privately) .&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; Best Regs,&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; Toto&lt;br&gt;
&amp;gt;&lt;br&gt;
&lt;br&gt;
&lt;/font&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505323p542736.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-538660</id>
	<title>RE: Is there any way to measure IT Security??</title>
	<published>2005-07-29T00:27:56Z</published>
	<updated>2005-07-29T00:27:56Z</updated>
	<author>
		<name>Bohoudi, S. - Salah -</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;
&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;Toto,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;I am afraid that no tool can fulfill your
requirement. I think in order to be able to measure the effectiveness of your
IT security controls; you should first start with defining security policies
fitting your organizational requirements. Based on these policies and your corporate
security strategy you can define security metrics to measure conformance with
the security policies. As an example the number/percentage of audited/security accredited
systems (against the system security policy) is a metric you can use in order
to measure the effectiveness of your system security policy (preventive control).
&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;I wouldn&amp;#8217;t rather think in tools,
but processes within your IT security department to help you out drive
performance, and achieve policy compliance.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;Hope this helps&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;Salah&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:12.0pt'&gt;

&lt;hr size=2 width=&quot;100%&quot; align=center tabindex=-1&gt;

&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;
font-family:Tahoma;font-weight:bold'&gt;From:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;font-family:Tahoma'&gt; Toto A Atmojo
[mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538660&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;] &lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Sent:&lt;/span&gt;&lt;/b&gt; Thursday, July 28, 2005
12:02 PM&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;To:&lt;/span&gt;&lt;/b&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538660&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538660&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538660&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538660&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538660&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538660&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538660&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Subject:&lt;/span&gt;&lt;/b&gt; Is there any way to
measure IT Security??&lt;/span&gt;&lt;/font&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Dear all,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Currently I&amp;#8217;m looking for a tool, or a technique to
measure IT security?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;The baseline for security is CIA (Confidentiality, Integrity
and Availability), that is every organization which want to called secure must
be guarantee that their system comply this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;But the problem is, we need a tool/technique to measure how
secure are we. Therefore, wee need a tool/technique to measure how close that
our system status now to CIA.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Please share your experience about this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;If there any link about this issue, I really appreciate if
you share to us (You may contact me privately) .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Best Regs,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Toto&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505323p538660.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-538488</id>
	<title>RE: Is there any way to measure IT Security??</title>
	<published>2005-07-28T19:38:16Z</published>
	<updated>2005-07-28T19:38:16Z</updated>
	<author>
		<name>Balachendran, Thamilarasu SITI-ITIBHW</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.0 Transitional//EN&quot;&gt;
&lt;HTML xmlns=&quot;http://www.w3.org/TR/REC-html40&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot;&gt;&lt;HEAD&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=iso-8859-1&quot;&gt;


&lt;META content=&quot;MSHTML 6.00.2800.1505&quot; name=GENERATOR&gt;

&lt;/HEAD&gt;
&lt;BODY lang=EN-US vLink=purple link=blue&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;Hi 
Guys,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;Have 
you try out with MBSA Tool that provided by Microsoft.This tool can used for 
measure what are the patches install on your machine.Nevertheless , this tool 
used to measure password strength and account information.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;Regards,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;Arasu&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
  &lt;DIV class=OutlookMessageHeader dir=ltr align=left&gt;&lt;FONT face=Tahoma size=2&gt;-----Original Message-----&lt;BR&gt;&lt;B&gt;From:&lt;/B&gt; Toto A Atmojo 
  [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538488&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;]&lt;BR&gt;&lt;B&gt;Sent:&lt;/B&gt; Thursday, July 28, 2005 6:02 
  PM&lt;BR&gt;&lt;B&gt;To:&lt;/B&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538488&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;; 
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538488&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538488&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;; 
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538488&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538488&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;; 
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538488&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;; 
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538488&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&lt;BR&gt;&lt;B&gt;Subject:&lt;/B&gt; Is there any way to 
  measure IT Security??&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;
  &lt;DIV class=Section1&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Dear 
  all,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Currently I&amp;#8217;m looking for a tool, 
  or a technique to measure IT security?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;The baseline for security is CIA 
  (Confidentiality, Integrity and Availability), that is every organization 
  which want to called secure must be guarantee that their system comply this 
  matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;But the problem is, we need a 
  tool/technique to measure how secure are we. Therefore, wee need a 
  tool/technique to measure how close that our system status now to 
  CIA.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Please share your experience about 
  this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;If there any link about this 
  issue, I really appreciate if you share to us (You may contact me privately) 
  .&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Best 
  Regs,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Toto&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505323p538488.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-510061</id>
	<title>RE: Is there any way to measure IT Security??</title>
	<published>2005-07-28T17:17:16Z</published>
	<updated>2005-07-28T17:17:16Z</updated>
	<author>
		<name>cwright-2</name>
	</author>
	<content type="html">17799 - part2
&lt;br&gt;SANS have a few measures
&lt;br&gt;The NSA and NIST methodologies are good
&lt;br&gt;ITOL
&lt;br&gt;COSO
&lt;br&gt;COBIT
&lt;br&gt;&lt;br&gt;Lots and the list goes on....
&lt;br&gt;&lt;br&gt;Craig 
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Larry Marin (Irony Account) [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510061&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;] 
&lt;br&gt;Sent: 29 July 2005 2:30
&lt;br&gt;To: Toto A Atmojo
&lt;br&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510061&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510061&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510061&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510061&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510061&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510061&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510061&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Is there any way to measure IT Security??
&lt;br&gt;&lt;br&gt;You should check out NSA IAM/IEM Methodology...it works well for me.
&lt;br&gt;&lt;a href=&quot;http://www.iatrp.com/iam.cfm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Toto A Atmojo wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Dear all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Currently I'm looking for a tool, or a technique to measure IT
&lt;br&gt;security?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The baseline for security is CIA (Confidentiality, Integrity and 
&lt;br&gt;&amp;gt; Availability), that is every organization which want to called secure 
&lt;br&gt;&amp;gt; must be guarantee that their system comply this matter.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; But the problem is, we need a tool/technique to measure how secure are
&lt;br&gt;&lt;br&gt;&amp;gt; we. Therefore, wee need a tool/technique to measure how close that our
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; system status now to CIA.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please share your experience about this matter.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If there any link about this issue, I really appreciate if you share 
&lt;br&gt;&amp;gt; to us (You may contact me privately) .
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Best Regs,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Toto
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505323p510061.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-509084</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-07-28T10:29:57Z</published>
	<updated>2005-07-28T10:29:57Z</updated>
	<author>
		<name>Larry Marin (Irony Account)</name>
	</author>
	<content type="html">You should check out NSA IAM/IEM Methodology...it works well for me.
&lt;br&gt;&lt;a href=&quot;http://www.iatrp.com/iam.cfm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Toto A Atmojo wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Dear all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Currently I’m looking for a tool, or a technique to measure IT security?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The baseline for security is CIA (Confidentiality, Integrity and 
&lt;br&gt;&amp;gt; Availability), that is every organization which want to called secure 
&lt;br&gt;&amp;gt; must be guarantee that their system comply this matter.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; But the problem is, we need a tool/technique to measure how secure are 
&lt;br&gt;&amp;gt; we. Therefore, wee need a tool/technique to measure how close that our 
&lt;br&gt;&amp;gt; system status now to CIA.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please share your experience about this matter.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If there any link about this issue, I really appreciate if you share 
&lt;br&gt;&amp;gt; to us (You may contact me privately) .
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Best Regs,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Toto
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505323p509084.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-505323</id>
	<title>Is there any way to measure IT Security??</title>
	<published>2005-07-28T04:02:09Z</published>
	<updated>2005-07-28T04:02:09Z</updated>
	<author>
		<name>Toto A Atmojo</name>
	</author>
	<content type="html">&lt;html xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;


&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Dear all,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Currently I&amp;#8217;m looking for a tool, or a technique to measure
IT security?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;The baseline for security is CIA (Confidentiality, Integrity
and Availability), that is every organization which want to called secure must
be guarantee that their system comply this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;But the problem is, we need a tool/technique to measure how
secure are we. Therefore, wee need a tool/technique to measure how close that
our system status now to CIA.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Please share your experience about this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;If there any link about this issue, I really appreciate if
you share to us (You may contact me privately) .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Best Regs,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Toto&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505323p505323.html" />
</entry>

</feed>
