<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-425</id>
	<title>Nabble - Security - Papers</title>
	<updated>2007-09-29T22:10:31Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Security---Papers-f425.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Security---Papers-f425.html" />
	<subtitle type="html">Announcement of computer security papers, articles, and books</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-12962604</id>
	<title>Re: Vulnerability Assessment Help Needed.</title>
	<published>2007-09-29T22:10:31Z</published>
	<updated>2007-09-29T22:10:31Z</updated>
	<author>
		<name>belinda</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp;If you are frustrated &amp;nbsp;about the virus infection,nothing serious ,Select AyRecovery that can prevent your PC from virus infection, Trojan effectively.
&lt;br&gt;&amp;nbsp; &amp;nbsp; A very quick recovery software--ayrecovery,it can not only provide PC ROLLBACK, but INSTANT RECOVERY and eliminate the system downtime and PC maintenance cost.
&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Emmanuel Baffo wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Hello everyone, 
&lt;br&gt;&lt;br&gt;I am trying to gather the following information for a management report and would really appreciate any information that anyone can provide...sources of such info will be greatly appreciated as well. &amp;nbsp; 
&lt;br&gt;&lt;br&gt;1) What are other companies doing when they detect or uncover security vulnerabilities on exposures such as unsecure server services? 
&lt;br&gt;&lt;br&gt;2) Can you&amp;nbsp; provide statistics or metrics.&amp;nbsp; 
&lt;br&gt;&lt;br&gt;3 ) What happens when nothing is done?... What are the company's risks and exposures? 
&lt;br&gt;&lt;br&gt;&amp;nbsp; 
&lt;br&gt;&lt;br&gt;Thank you in advance, 
&lt;br&gt;&lt;br&gt;&lt;br&gt;Emmanuel Baffo, CISSP 
&lt;br&gt;&lt;br&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Vulnerability-Assessment-Help-Needed.-tp866694p12962604.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-866694</id>
	<title>Vulnerability Assessment Help Needed.</title>
	<published>2005-09-14T10:23:37Z</published>
	<updated>2005-09-14T10:23:37Z</updated>
	<author>
		<name>Emmanuel Baffo</name>
	</author>
	<content type="html">&lt;html&gt;
&lt;FONT face=Helv size=2&gt;
&lt;P&gt;Hello everyone, &lt;/P&gt;
&lt;P&gt;I am trying to gather the following information for a management report and would really appreciate any information that anyone can provide...sources of such info will be greatly appreciated as well. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) What are other companies doing when they detect or uncover security vulnerabilities on exposures such as unsecure server services?&lt;/P&gt;
&lt;P&gt;2) Can you&amp;nbsp; provide statistics or metrics.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3 ) What happens when nothing is done?... What are the company's risks and exposures?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance, &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;
Emmanuel Baffo, CISSP&lt;/P&gt;
&lt;/html&gt;&lt;BR&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Vulnerability-Assessment-Help-Needed.-tp866694p866694.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-819292</id>
	<title>RE: Incident Regarding to CIA</title>
	<published>2005-09-08T08:46:31Z</published>
	<updated>2005-09-08T08:46:31Z</updated>
	<author>
		<name>Alberto Cardona II</name>
	</author>
	<content type="html">Toto,
&lt;br&gt;&lt;br&gt;Here is a sample list that might be able to help you out and build upon.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Kind regards,
&lt;br&gt;&lt;br&gt;Alberto Cardona II, CCSE, MCP, CNA
&lt;br&gt;VP of Information Security - Professional Services
&lt;br&gt;&lt;br&gt;=====================================
&lt;br&gt;&lt;br&gt;1. Unauthorized Access
&lt;br&gt;&amp;nbsp; - Digital
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;An unauthorized user has infiltrated or compromised a system or 
&lt;br&gt;network
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Ex-employee/Contractor/Business Partner
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Ex-employee/contractor/business partner accessing or trying to access 
&lt;br&gt;networks / systems.
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Physical
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;An unauthorized user has infiltrated the physical premises
&lt;br&gt;&lt;br&gt;&lt;br&gt;2. Denial of Service
&lt;br&gt;&amp;nbsp; - Denial of Service (DoS)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;A &amp;quot;denial-of-service&amp;quot; attack is characterized by an explicit attempt 
&lt;br&gt;by attackers to prevent legitimate users of a service from using that 
&lt;br&gt;service
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Distributed Denial of Service (DDoS)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;An attack initiated from many individual hosts (acting as drones) 
&lt;br&gt;controlled from another central host in order to prevent legitimate users of 
&lt;br&gt;a service from using that service
&lt;br&gt;&lt;br&gt;&lt;br&gt;3. Malware
&lt;br&gt;&amp;nbsp; - Virus
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;A program or software code that is loaded onto a system without 
&lt;br&gt;user?s knowledge and runs without authorization. &amp;nbsp;Also capable replicate 
&lt;br&gt;themselves or destroying data
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Worm
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;A program or algorithm designed to replicate itself over a computer 
&lt;br&gt;network and usually performs malicious actions
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Trojan
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Designed to cause damage or do something malicious to a system, but 
&lt;br&gt;disguised as something useful.
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Spyware
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;A program or software code that covertly gathers user information 
&lt;br&gt;through the user's Internet connection without his or her knowledge, usually 
&lt;br&gt;for advertising purposes
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;4. Inappropriate Usage
&lt;br&gt;&amp;nbsp; - Policy Non-compliance
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All employees and other person when they act on behalf of the company 
&lt;br&gt;(consultants, business partners) are to abide by the Company Corporate 
&lt;br&gt;Policies. &amp;nbsp;Any violations of corporate policies are considered as 
&lt;br&gt;?non-compliance? incident. For a list of detailed policies and procedures 
&lt;br&gt;please refer to ?IS Policies, Standards &amp; Procedures? .
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Dictionary \ Password Cracking, Brute Force
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;A dictionary attack is in essence a password-guessing attack. &amp;nbsp;
&lt;br&gt;Brute-force attack looks at all possible keys
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Data Replay
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Capture network traffic (usually authentication credentials) to play 
&lt;br&gt;back at a later time and assume identity
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Passive Network Traffic Capture (sniffing), Eavesdropping
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Reconnaissance method to determine user credentials, traffic 
&lt;br&gt;patterns, and available services
&lt;br&gt;&lt;br&gt;&amp;nbsp; - DNS Zone Transfer Requests or poisoning (Internal Network)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Unauthorized requests to obtain website?s DNS registration 
&lt;br&gt;information
&lt;br&gt;&lt;br&gt;&amp;nbsp; - DNS Zone Transfer poisoning (Internal Network)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Unauthorized requests to corrupt website?s DNS registration 
&lt;br&gt;information
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Port Sweeping (TCP \ UDP \ ICMP) (Internal Network)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Reconnaissance method to determine system vulnerabilities and 
&lt;br&gt;?listening? ports. &amp;nbsp;Used to build more focused attacks
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Spoofing
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Creation of TCP/IP packets using somebody else's IP address
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Inappropriate browsing
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Browsing non-business related offensive web sites using Internet 
&lt;br&gt;infrastructure
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Inappropriate email
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Sending / Receiving / Forwarding non-business related emails using &amp;nbsp;
&lt;br&gt;Email infrastructure
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Inappropriate Hosting
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Hosting non-business related FTP servers, Web servers, Shares, Email 
&lt;br&gt;systems, News groups using infrastructure
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Hoax
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Sending / Receiving / Forwarding false messages / deceiving intent 
&lt;br&gt;messages using email or other communicating methods
&lt;br&gt;&lt;br&gt;&lt;br&gt;5. External Attacks
&lt;br&gt;&amp;nbsp; - Spoofing
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Creation of TCP/IP packets using somebody else's IP address
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Network Traffic Redirection, Man-In-The-Middle, Data Manipulation, 
&lt;br&gt;Malformation (URL or URI)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Interception of network traffic with intent to hijack the session 
&lt;br&gt;and modify the data payload or data stream.
&lt;br&gt;&lt;br&gt;&amp;nbsp; - DNS Zone Transfer Requests or poisoning (External Public Network)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Unauthorized requests to obtain website?s DNS registration 
&lt;br&gt;information
&lt;br&gt;&lt;br&gt;&amp;nbsp; - DNS Zone Transfer poisoning (External Public Network)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Unauthorized requests to corrupt website?s DNS registration 
&lt;br&gt;information
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Port Sweeping (TCP \ UDP \ ICMP) (External Public Network)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Reconnaissance method to determine system vulnerabilities and 
&lt;br&gt;?listening? ports. &amp;nbsp;Used to build more focused attacks
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Data
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Definition:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;A unauthorized or valid user gains circuitous or direct access to 
&lt;br&gt;proprietary company information retained on data storage or processing 
&lt;br&gt;systems and compromises that data with malicious, illicit intent
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;From: &amp;quot;Toto A Atmojo&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=819292&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;To: 
&lt;br&gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=819292&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&amp;gt;,&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=819292&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;&amp;gt;,&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=819292&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;&amp;gt;,&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=819292&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;&amp;gt;, 
&lt;br&gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=819292&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;Subject: Incident Regarding to CIA
&lt;br&gt;&amp;gt;Date: Wed, 7 Sep 2005 00:36:36 +0700
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Dear all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Right now I'm collecting any Incident regarding to CIA (Confidentiality,
&lt;br&gt;&amp;gt;Integrity and Avaibility).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;But I'm afraid that the list is not completed. Is there any documentation
&lt;br&gt;&amp;gt;regarding this issue?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Example of list:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Incident regarding to Availability:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;1.	DOS
&lt;br&gt;&amp;gt;2.	Disaster
&lt;br&gt;&amp;gt;3.	etc
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Can anyone send me the complete incident?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Incident not only causes by cracker, but outside human touch are acceptable
&lt;br&gt;&amp;gt;also.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Thanks.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Incident-Regarding-to-CIA-tp809571p819292.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-809571</id>
	<title>Incident Regarding to CIA</title>
	<published>2005-09-06T11:36:36Z</published>
	<updated>2005-09-06T11:36:36Z</updated>
	<author>
		<name>Toto A Atmojo</name>
	</author>
	<content type="html">&lt;html xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;


&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Dear all,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Right now I&amp;#8217;m collecting any Incident regarding to CIA
(Confidentiality, Integrity and Avaibility).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;But I&amp;#8217;m afraid that the list is not completed. Is there
any documentation regarding this issue?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Example of list:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Incident regarding to Availability:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;ol style='margin-top:0in' start=1 type=1&gt;
 &lt;li class=MsoNormal style='mso-list:l0 level1 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;DOS&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
 &lt;li class=MsoNormal style='mso-list:l0 level1 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;Disaster&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
 &lt;li class=MsoNormal style='mso-list:l0 level1 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;etc&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Can anyone send me the complete incident?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Incident not only causes by cracker, but outside human touch
are acceptable also.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Thanks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Incident-Regarding-to-CIA-tp809571p809571.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-743306</id>
	<title>CIA checklist</title>
	<published>2005-08-29T17:56:54Z</published>
	<updated>2005-08-29T17:56:54Z</updated>
	<author>
		<name>Toto A Atmojo</name>
	</author>
	<content type="html">&lt;html xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;


&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Dear all,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;I&amp;#8217;m looking for the checklist regarding CIA
(Confidentiality, Integrity and Availability) rules.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;The format may look like this:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;ol style='margin-top:0in' start=1 type=1&gt;
 &lt;li class=MsoNormal style='mso-list:l0 level1 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;If a system want to be classified
     comply Confidentiality, it must be able to prevent this kind of attack:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
 &lt;ul style='margin-top:0in' type=disc&gt;
  &lt;li class=MsoNormal style='mso-list:l0 level2 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;A&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
  &lt;li class=MsoNormal style='mso-list:l0 level2 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;B&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
  &lt;li class=MsoNormal style='mso-list:l0 level2 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;C&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
  &lt;li class=MsoNormal style='mso-list:l0 level2 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;D&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
 &lt;/ul&gt;
 &lt;li class=MsoNormal style='mso-list:l0 level1 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;If a system want to be classified
     comply Integrity, it must be able to prevent this kind of attack:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
 &lt;ul style='margin-top:0in' type=disc&gt;
  &lt;li class=MsoNormal style='mso-list:l0 level2 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;A&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
  &lt;li class=MsoNormal style='mso-list:l0 level2 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;B&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
  &lt;li class=MsoNormal style='mso-list:l0 level2 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;C&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
  &lt;li class=MsoNormal style='mso-list:l0 level2 lfo1'&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial'&gt;D&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/li&gt;
 &lt;/ul&gt;
&lt;/ol&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;I think this checklist will be very useful for system
administrator that really concern on security. This list also give us guidance
on part that need to be secure, or need more attention regarding security.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Any paper or documentation about this issue will be very
appreciated.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Thanks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/CIA-checklist-tp743306p743306.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-736172</id>
	<title>Xcon2005 papers released</title>
	<published>2005-08-28T21:36:11Z</published>
	<updated>2005-08-28T21:36:11Z</updated>
	<author>
		<name>alert7-2</name>
	</author>
	<content type="html">hi all:
&lt;br&gt;&lt;br&gt;Xcon2005 closed successful on Aug 20th, 2005 
&lt;br&gt;&lt;br&gt;Those papers released in &lt;a href=&quot;http://xcon.xfocus.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://xcon.xfocus.org/&lt;/a&gt;&amp;nbsp;
&lt;br&gt;Chinese version papers in &lt;a href=&quot;http://xcon.xfocus.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://xcon.xfocus.net/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Hacking Windows CE..............................................-- by San
&lt;br&gt;Windows Kernel Pool Overflow Exploitation ......................-- by SoBeIt &amp;nbsp;
&lt;br&gt;Advanced trojan in Grub ........................................-- by CoolQ
&lt;br&gt;Structural Signature and Signature's Structure..................-- by Funnywei
&lt;br&gt;New thoughts in ring3 nt rootkit ...............................-- by Baiyuanfan
&lt;br&gt;Anti-Virus Heuristics...........................................-- by Drew 
&lt;br&gt;Reconfigurable Synchronization Technique........................-- by Cawan &amp;nbsp;
&lt;br&gt;Java &amp; Secure Programming.......................................-- by Marc Schoenefeld &amp;nbsp;
&lt;br&gt;Security in development environment &amp;nbsp;...........................-- by ICBM
&lt;br&gt;Research on Same Source Feature Measuring Technology of Software-- by Liu,Xin
&lt;br&gt;Profiling Malware and Rootkits from Kernel-Mode ................-- by Matt Conover( Shok) &amp;nbsp; &amp;nbsp;
&lt;br&gt;I want to see farther ..........................................-- by TombKeeper
&lt;br&gt;New architecture and approach in Network Virus Detction ........-- by Seak 
&lt;br&gt;Talking About 0day .............................................-- by Sowhat &amp;nbsp;
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Best Regards
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=736172&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;alert7@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Xfocus TEAM
&lt;br&gt;&lt;a href=&quot;http://www.xfocus.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.xfocus.org&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Xcon2005-papers-released-tp736172p736172.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-591822</id>
	<title>Bay Area Security User Group</title>
	<published>2005-08-08T05:29:15Z</published>
	<updated>2005-08-08T05:29:15Z</updated>
	<author>
		<name>Salaets, Steven</name>
	</author>
	<content type="html">&lt;html xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:st1=&quot;urn:schemas-microsoft-com:office:smarttags&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;
&lt;o:SmartTagType namespaceuri=&quot;urn:schemas-microsoft-com:office:smarttags&quot; name=&quot;City&quot; /&gt;
&lt;o:SmartTagType namespaceuri=&quot;urn:schemas-microsoft-com:office:smarttags&quot; name=&quot;place&quot; /&gt;
&lt;!--[if !mso]&gt;
&lt;style&gt;
st1\:*{behavior:url(#default#ieooui) }
&lt;/style&gt;
&lt;![endif]--&gt;


&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;All,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;I recently moved from &lt;st1:City w:st=&quot;on&quot;&gt;Paris&lt;/st1:City&gt;
to the Bay Area, working for a company named &lt;st1:place w:st=&quot;on&quot;&gt;Wind River&lt;/st1:place&gt;
where I am responsible for Information Security and currently I try to
establish a security group in the bay area. The goal is to provide a forum for
experts to encourage discussion and share expertise in understanding the latest
trends and security threats facing computer networks, systems and data. &lt;br&gt;
&lt;br&gt;
Members should be Information Security practitioners, managers, network administrators,
etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;The meetings are intended to be performed on a monthly basis.
The location hasn&amp;#8217;t been verified yet but I am looking at hosting the
event in &lt;st1:City w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;Alameda&lt;/st1:place&gt;&lt;/st1:City&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;The meetings will not be used for solicitation purposes from
any vendors. Although, some speakers may be from specific vendors, the emphasis
will be on the concepts and solutions and not specific products or services.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Contact me if you are interested in becoming a member and everything
is still open for discussions therefore feel free to email me suggestions. Remember:
the plan is to establish the possibility to exchange of knowledge and skills
among a wide variety of information security experts.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Steven Salaets&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Bay-Area-Security-User-Group-tp591822p591822.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-574786</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-08-04T09:09:40Z</published>
	<updated>2005-08-04T09:09:40Z</updated>
	<author>
		<name>Richard Sullivan-2</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;quot;Measuring IT security&amp;quot; is
a broad concept, but a comprehensive risk assessment is the best way to
gage overall security posture. Vulnerability assessment is just one piece
of that. Standards for best practice, like ISO17799, force you to consider
every part of your organization as it relates to infosec. There are many
risk assessment frameworks, guidelines and tools available from sites like
sans.org, nist.gov, issa.org, etc., as well as commercial offerings.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Unfortunately, there's no cut &amp;amp;
dried scoring system, nor a universally adopted measurement standard, so
keep your expectations (and management's expectations) realistic. Involve
EVERYONE in your assessment and in your security program. I've seen companies
ignore outside contractors, cleaning services and maintenance workers because
they weren't permanent, full-time employees. That's like ignoring the key
under the door mat.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;- Rich&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
&lt;/font&gt;
&lt;p&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;table width=100%&gt;
&lt;tr valign=top&gt;
&lt;td width=40%&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;&lt;b&gt;&amp;quot;Toto A Atmojo&amp;quot;
&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574786&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;&amp;gt;&lt;/b&gt; &lt;/font&gt;
&lt;p&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;07/28/2005 06:02 AM&lt;/font&gt;
&lt;td width=59%&gt;
&lt;table width=100%&gt;
&lt;tr valign=top&gt;
&lt;td&gt;
&lt;div align=right&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;To&lt;/font&gt;&lt;/div&gt;
&lt;td&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574786&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;&amp;gt;,
&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574786&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574786&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;&amp;gt;,
&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574786&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574786&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;&amp;gt;,
&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574786&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;&amp;gt;, &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574786&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&amp;gt;&lt;/font&gt;
&lt;tr valign=top&gt;
&lt;td&gt;
&lt;div align=right&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;cc&lt;/font&gt;&lt;/div&gt;
&lt;td&gt;
&lt;tr valign=top&gt;
&lt;td&gt;
&lt;div align=right&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;Subject&lt;/font&gt;&lt;/div&gt;
&lt;td&gt;&lt;font size=1 face=&quot;sans-serif&quot;&gt;Is there any way to measure IT Security??&lt;/font&gt;&lt;/table&gt;
&lt;br&gt;
&lt;table&gt;
&lt;tr valign=top&gt;
&lt;td&gt;
&lt;td&gt;&lt;/table&gt;
&lt;br&gt;&lt;/table&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Dear all,&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Currently I&amp;#8217;m looking for a tool, or a technique
to measure IT security?&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;The baseline for security is CIA (Confidentiality,
Integrity and Availability), that is every organization which want to called
secure must be guarantee that their system comply this matter.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;But the problem is, we need a tool/technique
to measure how secure are we. Therefore, wee need a tool/technique to measure
how close that our system status now to CIA.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Please share your experience about this matter.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;If there any link about this issue, I really
appreciate if you share to us (You may contact me privately) .&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Best Regs,&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;Toto&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Arial&quot;&gt;&amp;nbsp;&lt;/font&gt;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p574786.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-574782</id>
	<title>RE: Is there any way to measure IT Security??</title>
	<published>2005-08-03T23:17:16Z</published>
	<updated>2005-08-03T23:17:16Z</updated>
	<author>
		<name>shankarnarayan.d</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 3.2//EN&quot;&gt;
&lt;HTML&gt;
&lt;HEAD&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;META NAME=&quot;Generator&quot; CONTENT=&quot;MS Exchange Server version 5.5.2657.73&quot;&gt;
&lt;TITLE&gt;RE: Is there any way to measure IT Security??&lt;/TITLE&gt;
&lt;/HEAD&gt;
&lt;BODY&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;SSE CMM might be a good approach for &amp;quot;measuring security&amp;quot;. The library in &lt;A HREF=&quot;http://www.sse-cmm.org/lib/lib.asp&quot; TARGET=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.sse-cmm.org/lib/lib.asp&lt;/A&gt; may be of help. One of the reasons for development of SSE - CMM is &amp;quot;advance security engineering as a defined, mature and measurable discipline&amp;quot;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Most personnel forget that defining, using and implementing security processes are very critical to the Organization. How effectively these have been implemented measures effectiveness of the security. While Technology and the tools can provide that much security, unless people are aware of processes that are involved in keeping, using, maintaining, updating and upgrading these devices, there is no use of the devices. Additionally, one should also look at effectively training people to ensure that they follow the process and use the tools correctly. &lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;While a VA and a PT can effectively provide a measure of security from the technical angle, process-wise BS7799 and IOS17799 provide a really good benchmark. SSE - CMM adds to provide a measurable value to the BS and ISO.&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;More important do a good risk analysis - this is the foundation. Understand what affects, you how, why, when........ The risk would be completely different for the same device in multiple topologies and the best tool I guess is the human brain for this&lt;/FONT&gt;&lt;/P&gt;
&lt;BR&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Rgds,&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Shankar&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;-----Original Message-----&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;From: Marriott, Bill (US - Dallas) [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bmarriott@...&lt;/a&gt;] &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Sent: Thursday, August 04, 2005 1:25 AM&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;To: John Alexander; Gary Everekyan; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Subject: RE: Is there any way to measure IT Security??&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;This is a good list, but somewhat incomplete.&amp;nbsp; I think you should&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;consider that security is not a destination, it is a process.&amp;nbsp; There are&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;plenty of sources out there that you can measure yourself against, from&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;a process point of view.&amp;nbsp; Check out the ISO17799 standard or the BS7799&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;standard, they outline the processes which go into a well developed&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;security program.&amp;nbsp; Or look at the Generally Accepted Information&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Security Principles (under development -&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&lt;A HREF=&quot;http://www.issa.org/gaisp/gaisp.html&quot; TARGET=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.issa.org/gaisp/gaisp.html&lt;/A&gt;).&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;The NSA IAM/IEM is a methodology for managing controlled&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;penetration/vulnerability for a particular system/app.&amp;nbsp; The OWASP is for&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;web application testing.&amp;nbsp; These might give you an idea of security&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;posture of one server or application, but not overall for your company.&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;This kind of testing makes up a small amount of managing a secure&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;organization. &lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Take a look at the new ISO version, 2005.&amp;nbsp; This fall, there will be a&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;different ISO standard, 27001, which will allow a company to be&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;certified against the standard.&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&lt;A HREF=&quot;http://www.iso.org/iso/en/commcentre/pressreleases/2005/Ref963.html&quot; TARGET=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.iso.org/iso/en/commcentre/pressreleases/2005/Ref963.html&lt;/A&gt;&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Hope that helps.&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;/bpm &lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;-----Original Message-----&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;From: John Alexander [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aj@...&lt;/a&gt;] &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Sent: Wednesday, August 03, 2005 4:21 AM&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;To: Gary Everekyan; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=12&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=13&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=14&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=15&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=16&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Subject: Re: Is there any way to measure IT Security??&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Basically IT Security covers a gamut of areas, i am just listing some ,&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;on the fly&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;* Antivirus Solutions&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* Intrusion Prevention&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* Intrusion Detection&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* Patch Management&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* Firewall&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* VPN Gateway&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* Vulnerability Assessment &amp;amp; Reporting&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* Identity Access Management (single-sign-on, SOX/HIPAA/GLB&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;compliance....)&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* Network Security&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* Security Policy Compliance Management&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* AntiSpam (mail protection software)&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;* Web Content Filtering&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;I'm not sure whether we have one-size-fits-all solution which can help&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;us in measuring your enterprise IT Security posture.&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;I can list some good tools i have come across personally like NMap,&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;ScanFi, Nessus, IdentityAccess Manager,GFI ....but the list is endless,&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;so give them a try in google :-)&lt;/FONT&gt;
&lt;/P&gt;
&lt;BR&gt;
&lt;BR&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;----- Original Message -----&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;From: &amp;quot;Gary Everekyan&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=17&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;karo.onnik@...&lt;/a&gt;&amp;gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=18&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=19&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Subject: Re: Is there any way to measure IT Security??&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Date: Tue, 02 Aug 2005 14:32:30 -0400&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; Google Risk reporting and you will get whole list of research links.&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; It would also be helpful to look at owasp www.owasp.org&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; HTH&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; Regards,&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; Gary Everekyan&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; CISSP, CISM, ISSAP, ISSPCS, MCSE, MCT&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=20&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;garyeve@...&lt;/a&gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;quot;High achievement always takes place in the framework of high &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; expectation&amp;quot; -Jack Kinder&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; -----Original Message-----&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; From: &amp;quot;Larry Marin (Irony Account)&amp;quot; [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=574782&amp;i=21&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;]&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; Date: 08/02/2005 01:09 PM&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; You should check out NSA IAM/IEM Methodology...it works well for me.&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;A HREF=&quot;http://www.iatrp.com/iam.cfm&quot; TARGET=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/A&gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; Toto A Atmojo wrote:&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; Dear all,&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; Currently I'm looking for a tool, or a technique to measure IT&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;security?&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; The baseline for security is CIA (Confidentiality, Integrity and &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; Availability), that is every organization which want to called &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; secure must be guarantee that their system comply this matter.&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; But the problem is, we need a tool/technique to measure how &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; secure are we. Therefore, wee need a tool/technique to measure &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; how close that our system status now to CIA.&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; Please share your experience about this matter.&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; If there any link about this issue, I really appreciate if you &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; share to us (You may contact me privately) .&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; Best Regs,&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt; Toto&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&amp;gt; &amp;gt;&lt;/FONT&gt;
&lt;/P&gt;
&lt;BR&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;-- &lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;___________________________________________________________&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Sign-up for Ads Free at Mail.com&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;&lt;A HREF=&quot;http://promo.mail.com/adsfreejump.htm&quot; TARGET=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://promo.mail.com/adsfreejump.htm&lt;/A&gt;&lt;/FONT&gt;
&lt;/P&gt;
&lt;BR&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;------------------------------------------------------------------------&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;------&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;Don't&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Learn the hacker's secrets that compromise wireless LANs. Secure your&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;WLAN by understanding these threats, available hacking tools and proven&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;countermeasures. Defend your WLAN against man-in-the-Middle attacks and&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;session hijacking, denial-of-service, rogue access points, identity&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;thefts and MAC spoofing. Request your complimentary white paper at:&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;&lt;A HREF=&quot;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&quot; TARGET=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&lt;/A&gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;------------------------------------------------------------------------&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;------- &lt;/FONT&gt;
&lt;/P&gt;
&lt;BR&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law.&amp;nbsp; If you are not the intended recipient, you should delete this message. Any disclosure, copying, or distribution of this message, or the taking of any action based on it, is strictly prohibited. [v.E.1]&lt;/FONT&gt;&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;------------------------------------------------------------------------------&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Learn the hacker's secrets that compromise wireless LANs. Secure your&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;WLAN by understanding these threats, available hacking tools and proven&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;countermeasures. Defend your WLAN against man-in-the-Middle attacks and&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;session hijacking, denial-of-service, rogue access points, identity&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;thefts and MAC spoofing. Request your complimentary white paper at:&lt;/FONT&gt;
&lt;/P&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;&lt;A HREF=&quot;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&quot; TARGET=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&lt;/A&gt;&lt;/FONT&gt;
&lt;BR&gt;&lt;FONT SIZE=2&gt;-------------------------------------------------------------------------------&lt;/FONT&gt;
&lt;/P&gt;

&lt;/BODY&gt;
&lt;/HTML&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p574782.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-550499</id>
	<title>RE: Is there any way to measure IT Security??</title>
	<published>2005-08-03T13:55:22Z</published>
	<updated>2005-08-03T13:55:22Z</updated>
	<author>
		<name>Marriott, Bill (US - Dallas)</name>
	</author>
	<content type="html">This is a good list, but somewhat incomplete. &amp;nbsp;I think you should
&lt;br&gt;consider that security is not a destination, it is a process. &amp;nbsp;There are
&lt;br&gt;plenty of sources out there that you can measure yourself against, from
&lt;br&gt;a process point of view. &amp;nbsp;Check out the ISO17799 standard or the BS7799
&lt;br&gt;standard, they outline the processes which go into a well developed
&lt;br&gt;security program. &amp;nbsp;Or look at the Generally Accepted Information
&lt;br&gt;Security Principles (under development -
&lt;br&gt;&lt;a href=&quot;http://www.issa.org/gaisp/gaisp.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.issa.org/gaisp/gaisp.html&lt;/a&gt;).
&lt;br&gt;&lt;br&gt;The NSA IAM/IEM is a methodology for managing controlled
&lt;br&gt;penetration/vulnerability for a particular system/app. &amp;nbsp;The OWASP is for
&lt;br&gt;web application testing. &amp;nbsp;These might give you an idea of security
&lt;br&gt;posture of one server or application, but not overall for your company.
&lt;br&gt;This kind of testing makes up a small amount of managing a secure
&lt;br&gt;organization. 
&lt;br&gt;&lt;br&gt;Take a look at the new ISO version, 2005. &amp;nbsp;This fall, there will be a
&lt;br&gt;different ISO standard, 27001, which will allow a company to be
&lt;br&gt;certified against the standard.
&lt;br&gt;&lt;a href=&quot;http://www.iso.org/iso/en/commcentre/pressreleases/2005/Ref963.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iso.org/iso/en/commcentre/pressreleases/2005/Ref963.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Hope that helps.
&lt;br&gt;/bpm 
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: John Alexander [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aj@...&lt;/a&gt;] 
&lt;br&gt;Sent: Wednesday, August 03, 2005 4:21 AM
&lt;br&gt;To: Gary Everekyan; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;
&lt;br&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Is there any way to measure IT Security??
&lt;br&gt;&lt;br&gt;Basically IT Security covers a gamut of areas, i am just listing some ,
&lt;br&gt;on the fly
&lt;br&gt;&lt;br&gt;* Antivirus Solutions
&lt;br&gt;* Intrusion Prevention
&lt;br&gt;* Intrusion Detection
&lt;br&gt;* Patch Management
&lt;br&gt;* Firewall
&lt;br&gt;* VPN Gateway
&lt;br&gt;* Vulnerability Assessment &amp; Reporting
&lt;br&gt;* Identity Access Management (single-sign-on, SOX/HIPAA/GLB
&lt;br&gt;compliance....)
&lt;br&gt;* Network Security
&lt;br&gt;* Security Policy Compliance Management
&lt;br&gt;* AntiSpam (mail protection software)
&lt;br&gt;* Web Content Filtering
&lt;br&gt;&lt;br&gt;I'm not sure whether we have one-size-fits-all solution which can help
&lt;br&gt;us in measuring your enterprise IT Security posture.
&lt;br&gt;&lt;br&gt;I can list some good tools i have come across personally like NMap,
&lt;br&gt;ScanFi, Nessus, IdentityAccess Manager,GFI ....but the list is endless,
&lt;br&gt;so give them a try in google :-)
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message -----
&lt;br&gt;From: &amp;quot;Gary Everekyan&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;karo.onnik@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=12&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Is there any way to measure IT Security??
&lt;br&gt;Date: Tue, 02 Aug 2005 14:32:30 -0400
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Google Risk reporting and you will get whole list of research links.
&lt;br&gt;&amp;gt; It would also be helpful to look at owasp www.owasp.org
&lt;br&gt;&amp;gt; HTH
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Gary Everekyan
&lt;br&gt;&amp;gt; CISSP, CISM, ISSAP, ISSPCS, MCSE, MCT
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=13&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;garyeve@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;quot;High achievement always takes place in the framework of high 
&lt;br&gt;&amp;gt; expectation&amp;quot; -Jack Kinder
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &amp;quot;Larry Marin (Irony Account)&amp;quot; [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=550499&amp;i=14&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Date: 08/02/2005 01:09 PM
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; You should check out NSA IAM/IEM Methodology...it works well for me.
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.iatrp.com/iam.cfm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Toto A Atmojo wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Dear all,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Currently I'm looking for a tool, or a technique to measure IT
&lt;/div&gt;security?
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; The baseline for security is CIA (Confidentiality, Integrity and 
&lt;br&gt;&amp;gt; &amp;gt; Availability), that is every organization which want to called 
&lt;br&gt;&amp;gt; &amp;gt; secure must be guarantee that their system comply this matter.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; But the problem is, we need a tool/technique to measure how 
&lt;br&gt;&amp;gt; &amp;gt; secure are we. Therefore, wee need a tool/technique to measure 
&lt;br&gt;&amp;gt; &amp;gt; how close that our system status now to CIA.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Please share your experience about this matter.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; If there any link about this issue, I really appreciate if you 
&lt;br&gt;&amp;gt; &amp;gt; share to us (You may contact me privately) .
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Best Regs,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Toto
&lt;br&gt;&amp;gt; &amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;___________________________________________________________
&lt;br&gt;Sign-up for Ads Free at Mail.com
&lt;br&gt;&lt;a href=&quot;http://promo.mail.com/adsfreejump.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://promo.mail.com/adsfreejump.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;------
&lt;br&gt;FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You
&lt;br&gt;Don't
&lt;br&gt;&lt;br&gt;Learn the hacker's secrets that compromise wireless LANs. Secure your
&lt;br&gt;WLAN by understanding these threats, available hacking tools and proven
&lt;br&gt;countermeasures. Defend your WLAN against man-in-the-Middle attacks and
&lt;br&gt;session hijacking, denial-of-service, rogue access points, identity
&lt;br&gt;thefts and MAC spoofing. Request your complimentary white paper at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&lt;/a&gt;&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;------- 
&lt;br&gt;&lt;br&gt;&lt;br&gt;This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law. &amp;nbsp;If you are not the intended recipient, you should delete this message. Any disclosure, copying, or distribution of this message, or the taking of any action based on it, is strictly prohibited. [v.E.1]
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p550499.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-548925</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-08-03T09:34:56Z</published>
	<updated>2005-08-03T09:34:56Z</updated>
	<author>
		<name>Alberto Cardona II</name>
	</author>
	<content type="html">Larry,
&lt;br&gt;&lt;br&gt;I have worked for major fortune 100 and 500 companies. &amp;nbsp;Some of these 
&lt;br&gt;companies use a product called Enterprise Security Management and is made by 
&lt;br&gt;Archer (www.archer-tech.com). &amp;nbsp;It is highly customizable and you are able to 
&lt;br&gt;setup different metrics to monitor. &amp;nbsp;It ties in and correlates the different 
&lt;br&gt;facets of an InfoSec program:
&lt;br&gt;&lt;br&gt;- Threat Management
&lt;br&gt;- Incident Management
&lt;br&gt;- Asset Management
&lt;br&gt;- Risk Management
&lt;br&gt;- Policy Management
&lt;br&gt;&lt;br&gt;&lt;br&gt;You can set up different gauges, metrics and report on your company security 
&lt;br&gt;posture.
&lt;br&gt;Below are the different modules:
&lt;br&gt;&lt;br&gt;Incident Management:
&lt;br&gt;Report incidents, manage their escalation, track investigations and analyze 
&lt;br&gt;resolutions.
&lt;br&gt;Key features:
&lt;br&gt;- Based on the CERT Security Incident Response Handbook
&lt;br&gt;- Easily open, prioritize and track security incidents with built-in 
&lt;br&gt;workflow.
&lt;br&gt;- Perform impact analyses of incidents on critical assets and business 
&lt;br&gt;processes.
&lt;br&gt;- Manage incident escalation, investigations and forensic activities.
&lt;br&gt;- Track remediation efforts and document incident postmortem.
&lt;br&gt;- Manage response team contact information, processes and procedures.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Threat Management:
&lt;br&gt;Track threats through a comprehensive early warning system to help prevent 
&lt;br&gt;system compromise.
&lt;br&gt;Key features:
&lt;br&gt;- Receive real-time intelligence feeds from iDEFENSE, Symantec or TruSecure.
&lt;br&gt;- Filter alert notifications based on your environment.
&lt;br&gt;- Prioritize remediation plans and corrective actions.
&lt;br&gt;- Utilize a CVE-compliant threat and vulnerability database.
&lt;br&gt;- Integrate with your existing vulnerability scanning tools.
&lt;br&gt;- Search for data using a powerful reporting engine with built-in and custom 
&lt;br&gt;reports.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Asset Management:
&lt;br&gt;Manage enterprise assets and their relationships to secure them according to 
&lt;br&gt;management expectations.
&lt;br&gt;Key features:
&lt;br&gt;- Build the asset database
&lt;br&gt;- Define groups of assets and assign individual responsibilities.
&lt;br&gt;- Tie policies, baselines and procedures to specific assets
&lt;br&gt;- Filter real-time alerts based on the assets under your control
&lt;br&gt;- Manage the activities required to secure those assets.
&lt;br&gt;- Document business criticality for an asset in terms of confidentiality, 
&lt;br&gt;integrity and availability.
&lt;br&gt;- Link critical assets to the business processes they support.
&lt;br&gt;- Fully integrate with Archer Policy, Threat, Risk and Incident Management 
&lt;br&gt;solutions.
&lt;br&gt;- Import data from third-party discovery, scanning and asset management 
&lt;br&gt;tools.
&lt;br&gt;- Track vulnerabilities, remediation efforts and configuration changes.
&lt;br&gt;- Tie in to Change Managment System
&lt;br&gt;- Filter real-time alerts and other security content.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - Utilize advanced reporting and analysis tools.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Risk Management:
&lt;br&gt;&lt;a href=&quot;http://www.archer-tech.com/solutions/riskmgmt.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.archer-tech.com/solutions/riskmgmt.html&lt;/a&gt;&lt;br&gt;Perform online risk assessments to determine the proper controls to 
&lt;br&gt;implement based on use and risk.
&lt;br&gt;Key features:
&lt;br&gt;- Utilize integrated risk management methodology based on industry 
&lt;br&gt;standards.
&lt;br&gt;- Generate Online risk assessment questionnaires
&lt;br&gt;- Generate Asset risk scorecards and actionable plans for managing your 
&lt;br&gt;enterprise information risk.
&lt;br&gt;- Automate the risk assessment process.
&lt;br&gt;- Employ predefined and customizable assessment templates.
&lt;br&gt;- Build online risk assessment questionnaires.
&lt;br&gt;- Create risk scorecards and profiles.
&lt;br&gt;- Search for data using advanced management reporting tools.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Policy Management:
&lt;br&gt;&lt;a href=&quot;http://www.archer-tech.com/solutions/policymgmt.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.archer-tech.com/solutions/policymgmt.html&lt;/a&gt;&lt;br&gt;Create policies, distribute them online, educate and train employees and 
&lt;br&gt;track compliance.
&lt;br&gt;Key features:
&lt;br&gt;- Creation and Administration:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Link policies to the industry, regulatory or corporate standards they 
&lt;br&gt;support.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Attach relevant files to policies (procedures, flowcharts, examples, 
&lt;br&gt;images, etc.).
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Utilize content workflow features for version control and management 
&lt;br&gt;approval.
&lt;br&gt;- Communication and Distribution
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Display policies to users in an easy-to-understand tree format.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Filter and view policies by job function.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Alert users of changes to existing policies or new policies via email.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Allow users to perform keyword searches to quickly find specific 
&lt;br&gt;information among policies.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Enable users to export policy content directly into Word, Excel, HTML, 
&lt;br&gt;CSV or XML formats.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Set up, maintain and moderate discussion forums for specific users and 
&lt;br&gt;groups.
&lt;br&gt;- Tracking and Reporting
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Receive online acknowledgement that users have read and accepted 
&lt;br&gt;specific policies.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Monitor and report on user access to specific policies.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Track exceptions that have been granted for specific policies and the 
&lt;br&gt;dates exceptions will expire.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Allow users to report policy violations.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Track policy violations by date of occurrence and date of remediation 
&lt;br&gt;for compliance.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Utilize the full policy compliance reporting capability.
&lt;br&gt;- Policy Library
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Access a library of policies and standards that have been developed by 
&lt;br&gt;leading information &amp;nbsp; security subject matter experts for managing 
&lt;br&gt;compliance with industry regulations and industry-specific legislation.
&lt;br&gt;- All standards in the Policy Library have been mapped to the following 
&lt;br&gt;leading industry standards:
&lt;br&gt;&amp;nbsp; ISO/IEC 17799 (Code of Practice for Information Security Management)
&lt;br&gt;&amp;nbsp; Information Security Forum (The Forum?s Standard of Good Practice)
&lt;br&gt;&amp;nbsp; FFIEC Security Handbook
&lt;br&gt;&amp;nbsp; Health Insurance Portability Accountability Act (HIPAA) Final Ruling
&lt;br&gt;&amp;nbsp; European Union Directive on Data Protection
&lt;br&gt;&amp;nbsp; Basel II
&lt;br&gt;&amp;nbsp; CobIT
&lt;br&gt;&amp;nbsp; COSO
&lt;br&gt;&amp;nbsp; Monetary Authority of Singapore?s ?Technology Risk Management Guidelines
&lt;br&gt;&lt;br&gt;&lt;br&gt;Kind regards,
&lt;br&gt;&lt;br&gt;&lt;br&gt;Alberto Cardona II, CCSE, MCP, CNA
&lt;br&gt;VP of Information Security - Professional Services
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;From: &amp;quot;Larry Marin (Irony Account)&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548925&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;To: Toto A Atmojo &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548925&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;CC: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548925&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;,&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548925&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;, 
&lt;br&gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548925&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;,&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548925&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;, 
&lt;br&gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548925&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;,&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548925&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;, 
&lt;br&gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548925&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;&amp;gt;Subject: Re: Is there any way to measure IT Security??
&lt;br&gt;&amp;gt;Date: Thu, 28 Jul 2005 12:29:57 -0400
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;You should check out NSA IAM/IEM Methodology...it works well for me.
&lt;br&gt;&amp;gt;&lt;a href=&quot;http://www.iatrp.com/iam.cfm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;Toto A Atmojo wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Dear all,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Currently I?m looking for a tool, or a technique to measure IT security?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;The baseline for security is CIA (Confidentiality, Integrity and 
&lt;br&gt;&amp;gt;&amp;gt;Availability), that is every organization which want to called secure must 
&lt;br&gt;&amp;gt;&amp;gt;be guarantee that their system comply this matter.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;But the problem is, we need a tool/technique to measure how secure are we. 
&lt;br&gt;&amp;gt;&amp;gt;Therefore, wee need a tool/technique to measure how close that our system 
&lt;br&gt;&amp;gt;&amp;gt;status now to CIA.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Please share your experience about this matter.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;If there any link about this issue, I really appreciate if you share to us 
&lt;br&gt;&amp;gt;&amp;gt;(You may contact me privately) .
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Best Regs,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;Toto
&lt;br&gt;&amp;gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't
&lt;br&gt;&lt;br&gt;Learn the hacker's secrets that compromise wireless LANs. Secure your
&lt;br&gt;WLAN by understanding these threats, available hacking tools and proven
&lt;br&gt;countermeasures. Defend your WLAN against man-in-the-Middle attacks and
&lt;br&gt;session hijacking, denial-of-service, rogue access points, identity
&lt;br&gt;thefts and MAC spoofing. Request your complimentary white paper at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&lt;/a&gt;&lt;br&gt;-------------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p548925.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-548606</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-08-03T03:21:02Z</published>
	<updated>2005-08-03T03:21:02Z</updated>
	<author>
		<name>aj-4</name>
	</author>
	<content type="html">Basically IT Security covers a gamut of areas, i am just listing some , on the fly
&lt;br&gt;&lt;br&gt;* Antivirus Solutions
&lt;br&gt;* Intrusion Prevention
&lt;br&gt;* Intrusion Detection
&lt;br&gt;* Patch Management
&lt;br&gt;* Firewall
&lt;br&gt;* VPN Gateway
&lt;br&gt;* Vulnerability Assessment &amp; Reporting
&lt;br&gt;* Identity Access Management (single-sign-on, SOX/HIPAA/GLB compliance....)
&lt;br&gt;* Network Security
&lt;br&gt;* Security Policy Compliance Management
&lt;br&gt;* AntiSpam (mail protection software)
&lt;br&gt;* Web Content Filtering
&lt;br&gt;&lt;br&gt;I'm not sure whether we have one-size-fits-all solution which can help us in measuring your enterprise IT Security posture.
&lt;br&gt;&lt;br&gt;I can list some good tools i have come across personally like NMap, ScanFi, Nessus, IdentityAccess Manager,GFI ....but the list is endless, so give them a try in google :-)
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message -----
&lt;br&gt;From: &amp;quot;Gary Everekyan&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548606&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;karo.onnik@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548606&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548606&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Is there any way to measure IT Security??
&lt;br&gt;Date: Tue, 02 Aug 2005 14:32:30 -0400
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Google Risk reporting and you will get whole list of research links.
&lt;br&gt;&amp;gt; It would also be helpful to look at owasp www.owasp.org
&lt;br&gt;&amp;gt; HTH
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Gary Everekyan
&lt;br&gt;&amp;gt; CISSP, CISM, ISSAP, ISSPCS, MCSE, MCT
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548606&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;garyeve@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;quot;High achievement always takes place in the framework of high 
&lt;br&gt;&amp;gt; expectation&amp;quot; -Jack Kinder
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &amp;quot;Larry Marin (Irony Account)&amp;quot; [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=548606&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Date: 08/02/2005 01:09 PM
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; You should check out NSA IAM/IEM Methodology...it works well for me.
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.iatrp.com/iam.cfm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Toto A Atmojo wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Dear all,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Currently Im looking for a tool, or a technique to measure IT security?
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; The baseline for security is CIA (Confidentiality, Integrity and 
&lt;br&gt;&amp;gt; &amp;gt; Availability), that is every organization which want to called 
&lt;br&gt;&amp;gt; &amp;gt; secure must be guarantee that their system comply this matter.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; But the problem is, we need a tool/technique to measure how 
&lt;br&gt;&amp;gt; &amp;gt; secure are we. Therefore, wee need a tool/technique to measure 
&lt;br&gt;&amp;gt; &amp;gt; how close that our system status now to CIA.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Please share your experience about this matter.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; If there any link about this issue, I really appreciate if you 
&lt;br&gt;&amp;gt; &amp;gt; share to us (You may contact me privately) .
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Best Regs,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Toto
&lt;br&gt;&amp;gt; &amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;___________________________________________________________
&lt;br&gt;Sign-up for Ads Free at Mail.com
&lt;br&gt;&lt;a href=&quot;http://promo.mail.com/adsfreejump.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://promo.mail.com/adsfreejump.htm&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't
&lt;br&gt;&lt;br&gt;Learn the hacker's secrets that compromise wireless LANs. Secure your
&lt;br&gt;WLAN by understanding these threats, available hacking tools and proven
&lt;br&gt;countermeasures. Defend your WLAN against man-in-the-Middle attacks and
&lt;br&gt;session hijacking, denial-of-service, rogue access points, identity
&lt;br&gt;thefts and MAC spoofing. Request your complimentary white paper at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801&lt;/a&gt;&lt;br&gt;-------------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p548606.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-542734</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-08-02T12:32:30Z</published>
	<updated>2005-08-02T12:32:30Z</updated>
	<author>
		<name>Gary Everekyan-2</name>
	</author>
	<content type="html">&lt;font style='{font-family: Arial,Verdana, Sans-Serif;font-size: 10pt;}'&gt;
&lt;FONT size=2&gt;
&lt;P&gt;Google Risk reporting and you will get whole list of research links.&lt;/P&gt;
&lt;P&gt;It would also be helpful to look at owasp &lt;/FONT&gt;&lt;A href=&quot;https://www.bluetie.com/cgi-bin/www.owasp.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff size=2&gt;www.owasp.org&lt;/U&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;FONT size=2&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;&lt;/FONT&gt;&lt;FONT size=2&gt;
&lt;P&gt;&lt;br&gt;
&lt;/FONT&gt;&lt;FONT size=2&gt;&lt;FONT face=&quot;Times New Roman&quot;&gt;Gary Everekyan&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;CISSP, CISM, ISSAP, ISSPCS, MCSE, MCT&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=542734&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;garyeve@...&lt;/a&gt;&lt;br&gt;
&quot;High achievement always takes place in the framework of high expectation&quot; -Jack Kinder&lt;/P&gt;&lt;/FONT&gt;&lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
&lt;B&gt;From:&lt;/B&gt; &quot;Larry Marin (Irony Account)&quot; [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=542734&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;]&lt;br&gt;
&lt;B&gt;Date:&lt;/B&gt; 08/02/2005 01:09 PM&lt;br&gt;
&lt;br&gt;
You should check out NSA IAM/IEM Methodology...it works well for me.&lt;br&gt;
&lt;A href=&quot;http://www.iatrp.com/iam.cfm&quot; target=_blank rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/A&gt;&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Toto A Atmojo wrote:&lt;br&gt;
&lt;br&gt;
&amp;gt; Dear all,&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; Currently Im looking for a tool, or a technique to measure IT security?&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; The baseline for security is CIA (Confidentiality, Integrity and &lt;br&gt;
&amp;gt; Availability), that is every organization which want to called secure &lt;br&gt;
&amp;gt; must be guarantee that their system comply this matter.&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; But the problem is, we need a tool/technique to measure how secure are &lt;br&gt;
&amp;gt; we. Therefore, wee need a tool/technique to measure how close that our &lt;br&gt;
&amp;gt; system status now to CIA.&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; Please share your experience about this matter.&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; If there any link about this issue, I really appreciate if you share &lt;br&gt;
&amp;gt; to us (You may contact me privately) .&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; Best Regs,&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; Toto&lt;br&gt;
&amp;gt;&lt;br&gt;
&lt;br&gt;
&lt;/font&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p542734.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-538658</id>
	<title>RE: Is there any way to measure IT Security??</title>
	<published>2005-07-29T00:27:56Z</published>
	<updated>2005-07-29T00:27:56Z</updated>
	<author>
		<name>Bohoudi, S. - Salah -</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;
&lt;!--[if !mso]&gt;
&lt;style&gt;
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;Toto,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;I am afraid that no tool can fulfill your
requirement. I think in order to be able to measure the effectiveness of your
IT security controls; you should first start with defining security policies
fitting your organizational requirements. Based on these policies and your corporate
security strategy you can define security metrics to measure conformance with
the security policies. As an example the number/percentage of audited/security accredited
systems (against the system security policy) is a metric you can use in order
to measure the effectiveness of your system security policy (preventive control).
&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;I wouldn&amp;#8217;t rather think in tools,
but processes within your IT security department to help you out drive
performance, and achieve policy compliance.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;Hope this helps&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;Salah&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=navy face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:navy'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:12.0pt'&gt;

&lt;hr size=2 width=&quot;100%&quot; align=center tabindex=-1&gt;

&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;
font-family:Tahoma;font-weight:bold'&gt;From:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 face=Tahoma&gt;&lt;span style='font-size:10.0pt;font-family:Tahoma'&gt; Toto A Atmojo
[mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538658&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;] &lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Sent:&lt;/span&gt;&lt;/b&gt; Thursday, July 28, 2005
12:02 PM&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;To:&lt;/span&gt;&lt;/b&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538658&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538658&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538658&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538658&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538658&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538658&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538658&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&lt;br&gt;
&lt;b&gt;&lt;span style='font-weight:bold'&gt;Subject:&lt;/span&gt;&lt;/b&gt; Is there any way to
measure IT Security??&lt;/span&gt;&lt;/font&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Dear all,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Currently I&amp;#8217;m looking for a tool, or a technique to
measure IT security?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;The baseline for security is CIA (Confidentiality, Integrity
and Availability), that is every organization which want to called secure must
be guarantee that their system comply this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;But the problem is, we need a tool/technique to measure how
secure are we. Therefore, wee need a tool/technique to measure how close that
our system status now to CIA.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Please share your experience about this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;If there any link about this issue, I really appreciate if
you share to us (You may contact me privately) .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Best Regs,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Toto&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p538658.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-538486</id>
	<title>RE: Is there any way to measure IT Security??</title>
	<published>2005-07-28T19:38:16Z</published>
	<updated>2005-07-28T19:38:16Z</updated>
	<author>
		<name>Balachendran, Thamilarasu SITI-ITIBHW</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.0 Transitional//EN&quot;&gt;
&lt;HTML xmlns=&quot;http://www.w3.org/TR/REC-html40&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot;&gt;&lt;HEAD&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=iso-8859-1&quot;&gt;


&lt;META content=&quot;MSHTML 6.00.2800.1505&quot; name=GENERATOR&gt;

&lt;/HEAD&gt;
&lt;BODY lang=EN-US vLink=purple link=blue&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;Hi 
Guys,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;Have 
you try out with MBSA Tool that provided by Microsoft.This tool can used for 
measure what are the patches install on your machine.Nevertheless , this tool 
used to measure password strength and account information.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;Regards,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;SPAN class=587493501-29072005&gt;Arasu&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
  &lt;DIV class=OutlookMessageHeader dir=ltr align=left&gt;&lt;FONT face=Tahoma size=2&gt;-----Original Message-----&lt;BR&gt;&lt;B&gt;From:&lt;/B&gt; Toto A Atmojo 
  [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538486&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;toto@...&lt;/a&gt;]&lt;BR&gt;&lt;B&gt;Sent:&lt;/B&gt; Thursday, July 28, 2005 6:02 
  PM&lt;BR&gt;&lt;B&gt;To:&lt;/B&gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538486&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;; 
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538486&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538486&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;; 
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538486&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538486&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;; 
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538486&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;; 
  &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=538486&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;&lt;BR&gt;&lt;B&gt;Subject:&lt;/B&gt; Is there any way to 
  measure IT Security??&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;/DIV&gt;
  &lt;DIV class=Section1&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Dear 
  all,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Currently I&amp;#8217;m looking for a tool, 
  or a technique to measure IT security?&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;The baseline for security is CIA 
  (Confidentiality, Integrity and Availability), that is every organization 
  which want to called secure must be guarantee that their system comply this 
  matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;But the problem is, we need a 
  tool/technique to measure how secure are we. Therefore, wee need a 
  tool/technique to measure how close that our system status now to 
  CIA.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Please share your experience about 
  this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;If there any link about this 
  issue, I really appreciate if you share to us (You may contact me privately) 
  .&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Best 
  Regs,&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;Toto&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
  &lt;P class=MsoNormal&gt;&lt;FONT face=Arial size=2&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: Arial&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p538486.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-510059</id>
	<title>RE: Is there any way to measure IT Security??</title>
	<published>2005-07-28T17:17:16Z</published>
	<updated>2005-07-28T17:17:16Z</updated>
	<author>
		<name>cwright-2</name>
	</author>
	<content type="html">17799 - part2
&lt;br&gt;SANS have a few measures
&lt;br&gt;The NSA and NIST methodologies are good
&lt;br&gt;ITOL
&lt;br&gt;COSO
&lt;br&gt;COBIT
&lt;br&gt;&lt;br&gt;Lots and the list goes on....
&lt;br&gt;&lt;br&gt;Craig 
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Larry Marin (Irony Account) [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510059&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;irony@...&lt;/a&gt;] 
&lt;br&gt;Sent: 29 July 2005 2:30
&lt;br&gt;To: Toto A Atmojo
&lt;br&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510059&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pen-test@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510059&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-management@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510059&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;secpapers@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510059&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;focus-linux@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510059&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;libnet@...&lt;/a&gt;; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510059&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;firewalls@...&lt;/a&gt;;
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=510059&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-basics@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Is there any way to measure IT Security??
&lt;br&gt;&lt;br&gt;You should check out NSA IAM/IEM Methodology...it works well for me.
&lt;br&gt;&lt;a href=&quot;http://www.iatrp.com/iam.cfm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Toto A Atmojo wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Dear all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Currently I'm looking for a tool, or a technique to measure IT
&lt;br&gt;security?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The baseline for security is CIA (Confidentiality, Integrity and 
&lt;br&gt;&amp;gt; Availability), that is every organization which want to called secure 
&lt;br&gt;&amp;gt; must be guarantee that their system comply this matter.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; But the problem is, we need a tool/technique to measure how secure are
&lt;br&gt;&lt;br&gt;&amp;gt; we. Therefore, wee need a tool/technique to measure how close that our
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; system status now to CIA.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please share your experience about this matter.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If there any link about this issue, I really appreciate if you share 
&lt;br&gt;&amp;gt; to us (You may contact me privately) .
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Best Regs,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Toto
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p510059.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-509082</id>
	<title>Re: Is there any way to measure IT Security??</title>
	<published>2005-07-28T10:29:57Z</published>
	<updated>2005-07-28T10:29:57Z</updated>
	<author>
		<name>Larry Marin (Irony Account)</name>
	</author>
	<content type="html">You should check out NSA IAM/IEM Methodology...it works well for me.
&lt;br&gt;&lt;a href=&quot;http://www.iatrp.com/iam.cfm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.iatrp.com/iam.cfm&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Toto A Atmojo wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Dear all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Currently I’m looking for a tool, or a technique to measure IT security?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The baseline for security is CIA (Confidentiality, Integrity and 
&lt;br&gt;&amp;gt; Availability), that is every organization which want to called secure 
&lt;br&gt;&amp;gt; must be guarantee that their system comply this matter.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; But the problem is, we need a tool/technique to measure how secure are 
&lt;br&gt;&amp;gt; we. Therefore, wee need a tool/technique to measure how close that our 
&lt;br&gt;&amp;gt; system status now to CIA.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please share your experience about this matter.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If there any link about this issue, I really appreciate if you share 
&lt;br&gt;&amp;gt; to us (You may contact me privately) .
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Best Regs,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Toto
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p509082.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-505321</id>
	<title>Is there any way to measure IT Security??</title>
	<published>2005-07-28T04:02:09Z</published>
	<updated>2005-07-28T04:02:09Z</updated>
	<author>
		<name>Toto A Atmojo</name>
	</author>
	<content type="html">&lt;html xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;


&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Dear all,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Currently I&amp;#8217;m looking for a tool, or a technique to measure
IT security?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;The baseline for security is CIA (Confidentiality, Integrity
and Availability), that is every organization which want to called secure must
be guarantee that their system comply this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;But the problem is, we need a tool/technique to measure how
secure are we. Therefore, wee need a tool/technique to measure how close that
our system status now to CIA.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Please share your experience about this matter.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;If there any link about this issue, I really appreciate if
you share to us (You may contact me privately) .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Best Regs,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;Toto&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt;
font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Is-there-any-way-to-measure-IT-Security---tp505321p505321.html" />
</entry>

</feed>
