ExamNotes.net  -  IT certification portal

ForumsCertResearchTop sitesNewslettersFree email
HomeRegister
Exams Notes
Practice exams
Exam games
Questions by email
Online training
Training videos
College degrees
Boot camps
Book store
Links directory
Tell a friend
For webmasters

CompTIA Exam Vouchers
Save money on CompTIA exams
Question of the day
Sign up to receive
interactive practice questions
for MCSE, CompTIA
Cisco and other exams
TestKing
Get MCSE, MCSD, CCNA, CCNP,A+, N+ and many more

* ExamSheets *
Guide for Success!
Actual Questions & Answers
MCSE, MCSD, A+ ,CCNA, CCNP
Oracle 8i, Oracle 9i

Online practice tests

Certification sites

Online university

Online college

Online education

Distance learning

Software forum

Server administration forum

Programming resources






This is interesting: Free IT Magazines | Databases help forum



CompTIA > Security+ > Third party security infrastructure analysis

Show a Printable Version
Email This Page to Someone!
Receive updates to this thread


www.ExamVouchers.com - Get Instant $60 OFF Security+ exam and a free practice test!

Featured site: Online Security+ practice exams from Cert21.com



Author Third party security infrastructure analysis
chodan
Senior Member
M




Registered: Mar 2000
Location: Kentucky
Country: United States
State:
Certifications: CCNA/CCNP CCDA /CCDP MCSE NT4/Win2000 MCP+I Network+ Security+
Working on: CCIE Routing & Switching

Total Posts: 1582
Third party security infrastructure analysis

How do you guys feel about hiring a 3rd party company to come in to do a IS security assesment on your network systems.
I am somewhat torn between reluctance at having people poking around "my" network and having a good knowledge of the network as a reference point.
The company I am looking at has an excellent reputation in this field and being an IS manager with a small staff and alot of responsibility to go around doesn't leave alot of time to keep up with security measures.
I think they might help in a number of areas.
1. To see how I am doing so far.
2. To see what areas need to be addressed
3. Help to develope a security policy which I may not have the clout to do without a 3rd party to back me up.
4. To see a risk assesment based on our objectives and uptime requirements.

What do you guys think?

__________________
Check out my music at
www.chodan.com
Rural Development in Eastern Ky.
www.centertech.com
"It is our decisions that show us what we truly are in life, not our abilities."

Report this post to a moderator

Old Post 03-18-03 12:32 AM
chodan is offline Click Here to See the Profile for chodan Click here to Send chodan a Private Message Visit chodan's homepage! Add chodan to your buddy list Find more posts by chodan Reply w/Quote Edit/Delete Message IP: Logged
RussS
radical dood
M




Registered: Sep 2002
Location: Hamilton
Country: New Zealand (Aotearoa)
State:
Certifications: MCP W2K Pro & Server, A+, Net+, NZQA L3 Computing
Working on: Security+, MCSA, Linux+

Total Posts: 955

Sometimes an outsider can see glaring holes in ones defenses so I guess they can be a good idea. However as a longtime manager in various different industries I am always loathe having 'consultants' come in to my area as past experiences have shown that an awful lot of very expensive consultants are people who are great salespersons, but really know squat about the overall picture - and in fact some I would even consider unemployable in their chosen fields.
With my VERY limited experience in the IT security field I am however shocked to see some of the things I have come across lately in the way of systems and personnel management. It is a wonder that some places even have a working network

__________________
Go hard or go home!

Report this post to a moderator

Old Post 03-18-03 02:07 AM
RussS is offline Click Here to See the Profile for RussS Click here to Send RussS a Private Message Add RussS to your buddy list Find more posts by RussS Send a message to RussS Reply w/Quote Edit/Delete Message IP: Logged
Tcat
Moderator
M




Registered: May 2002
Location: Digital Nomad
Country: United States
State:
Certifications: Security+, MCSE, MCT, CIW, A+, Net+, Inet+, Server+, Other
Working on: Linux+

Total Posts: 187

I have to strongly agree with RussS.

It is a double edged sword. One one side, the bean counter will never see his own entry error (which is why most use double entry to catch mistakes).

And in my years of observation, the truely inept at anything but the give of gab run from one new thing to another looking for a quick buck before they are caught.

Security is the current place to run to.

It is good the firm you are looking at has good background check. And the expenses can be very painful. As an alternative, is their someone you know where you can team up to check each others network? Double teaming would made sure you don't have obvious holes while insureing no one is poking where they shouldn't be.

I don't you're industry, so I cannot say what is enough... Generally speaking however, I am blown away at the gaping holes most have. By picking off the Low Hanging Fruit, if you're not in say, banking, oil, or health care, you have tipped the scales in your favor without too much time/expense.

One of the cheapest things you can do is print the first chapter from the beta pdf I did and pass out copies to every employee. Just getting them to be aware of changing passwords and being alert to social engineering really puts a few stiches in the flap on the back side of the pajamas.

Report this post to a moderator

Old Post 03-19-03 03:16 PM
Tcat is offline Click Here to See the Profile for Tcat Click here to Send Tcat a Private Message Add Tcat to your buddy list Find more posts by Tcat Reply w/Quote Edit/Delete Message IP: Logged
rlrouns
Member




Registered: Aug 2000
Location: Coral Springs
Country: US
State:
Certifications: SANS GSEC, IBM Server Expert, CCNA, SANS Win2k Gold Standard, MCSE, Linux+, Security+
Working on: GCWN, CISSP

Total Posts: 235

Another thing, do not hire a company that sells software or hardware. Use the company that just does threat assessments, etc. Also check out your local ISSA (www.issa.org) and talk to some of the security people there as there are some usually some pretty senior level people who can help guide you as well. If you do hire out a company that sells hardware and/or software you might get an assessment that you need a certain security product, and they just so happen to carry it... Remember: Vendors are evil! (and I work for one even though it is not security specific). Also check out CISecurity.org and look at the top 20 threats, free security guidelines, and some of the baseline tools out there. That should help you get a good start. Good luck and let us know what you decide to do!

Report this post to a moderator

Old Post 03-19-03 08:22 PM
rlrouns is offline Click Here to See the Profile for rlrouns Click here to Send rlrouns a Private Message Add rlrouns to your buddy list Find more posts by rlrouns Send a message to rlrouns Reply w/Quote Edit/Delete Message IP: Logged
chodan
Senior Member
M




Registered: Mar 2000
Location: Kentucky
Country: United States
State:
Certifications: CCNA/CCNP CCDA /CCDP MCSE NT4/Win2000 MCP+I Network+ Security+
Working on: CCIE Routing & Switching

Total Posts: 1582
Tcat

I work here http://www.centertech.com
We deal with alot of federally funded grant projects.
I have gotten upper management onboard with the notion of increasing security and have taken many steps toward securing our network systems.
The biggest hurdle is the human factor, most are careless or lazy about security and a few are so paranoid that they send false alarms out every few days.
In both cases education will be the key.

I have done OK with the recources I have but I feel I have much room for improvement.
I'll keep everyone posted on my progress.

__________________
Check out my music at
www.chodan.com
Rural Development in Eastern Ky.
www.centertech.com
"It is our decisions that show us what we truly are in life, not our abilities."

Report this post to a moderator

Old Post 03-20-03 01:15 AM
chodan is offline Click Here to See the Profile for chodan Click here to Send chodan a Private Message Visit chodan's homepage! Add chodan to your buddy list Find more posts by chodan Reply w/Quote Edit/Delete Message IP: Logged
Tcat
Moderator
M




Registered: May 2002
Location: Digital Nomad
Country: United States
State:
Certifications: Security+, MCSE, MCT, CIW, A+, Net+, Inet+, Server+, Other
Working on: Linux+

Total Posts: 187

I have family in your general area of the SE. I wish I could report from my experience that you are dealing with either side of the coin that is unusual. If I did, I would be lying. :-(

The hardest job for any of us it 'selling' reasonable precautions, on an ongoing basis.

If you can get top brass to buy off on the concept, then come basic CTT+ skills come into play. Selling is the game, as much as it isn't our primary job.

Maybe I can see you in a road tour. I have some airline "bump" money to burn or lose.

Tcat

Report this post to a moderator

Old Post 03-20-03 01:26 AM
Tcat is offline Click Here to See the Profile for Tcat Click here to Send Tcat a Private Message Add Tcat to your buddy list Find more posts by Tcat Reply w/Quote Edit/Delete Message IP: Logged
rlrouns
Member




Registered: Aug 2000
Location: Coral Springs
Country: US
State:
Certifications: SANS GSEC, IBM Server Expert, CCNA, SANS Win2k Gold Standard, MCSE, Linux+, Security+
Working on: GCWN, CISSP

Total Posts: 235

When I said, "Vendors are evil" I didn't really mean that they are bad people, or evil, or mal-intentioned. Sometimes it is just difficult to get an accurate assessment from someone who is selling a hardware or software solutions. Money permitting, it is nice to have a person come in who is an unbiased 3rd party who can look at the network.... Another thing you can do, depending on your time/money situation is go take the SANS training. If you want to be truly paranoid, and get effective hands on in how to lock down your network, that is a great investment. I took the security essentials course, and on day one, I wanted to call my boss, and tell him to just unplug the network. it will get you nice and paranoid. I would highly recommend the security essentials course, but if you are in an all windows environment or all unix environment, take those individual tracks. I hope that helps!

Rob

Report this post to a moderator

Old Post 03-20-03 02:27 PM
rlrouns is offline Click Here to See the Profile for rlrouns Click here to Send rlrouns a Private Message Add rlrouns to your buddy list Find more posts by rlrouns Send a message to rlrouns Reply w/Quote Edit/Delete Message IP: Logged
All times are GMT.
Post new thread   Post reply

Click here for list of Security+ study guides and order yours now!

CompTIA exam notes

Security+ exam details



Forum Jump:
Rate This Thread:
Forum Rules:
Who Can Read The Forum? Any registered user or guest.
Who Can Post New Topics? Any registered user.
Who Can Post Replies? Any registered user.
Changes: Messages can be edited by their author.
Posts: HTML code is OFF. Smilies are ON. vB code is ON. [IMG] code is OFF.
 

ExamNotes forum archive


Powered by: vBulletin 2.2.8
Copyright ©2000, Jelsoft Enterprises Limited.

  Free Braindumps | mcse braindumps