 |
 |
 |
| FAQs:
Security site assessment services:
|
|
 |
|
|
 |
 |
Security site assessment FAQ: Questions for the client


Pre-assessment questions
|
 |
 |
What is the scope of the assessment? |
 |
| 19 May 2008 | SearchSecurityChannel.com |
 |


|
 |
| About the author |
| Joel Scambray has held diverse roles in information security over a dozen years, including co-author of Hacking Exposed: Windows and Hacking Exposed: Web Applications, senior director of security at Microsoft, co-founder of security technology and service company Foundstone, senior security consultant for Ernst & Young and internationally recognized speaker in both public and private forums. Listen to the supplemental podcast with Joel for more information on security site assessments. |
|
|
 |
 |
As with most consultative engagements, the scope of the assessment is all-important. Value-added resellers should clarify the parameters of the assessment, including the nature of specific environments/components to be assessed. For example, will the assessment cover physical, network, application, database, personnel, policy and/or wireless assets? This will help the reseller determine the types of tools and skills necessary to deliver. The scale of work (i.e., number of iterations) is also important, e.g., number of IP addresses to be scanned/assessed. The reseller should also ensure it has permission to assess all in-scope assets, especially if third-party assets are to be targeted.
Return to the security site assessment FAQ guide and read the rest of Joel's expert answers.
');
// -->

|
 |
|
 |
 |
 |
| TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of . |
|
| |
All Rights Reserved, , TechTarget |
|
|
|
|
|