Home > Security Channel FAQs > Security site assessment services > Security site assessment FAQ: Questions for the consultant > Assessment questions > Have access credentials, documentation and training been provided?
FAQs: Security site assessment services:
EMAIL THIS
 START   SECURITY SITE ASSESSMENT PODCAST   SECURITY SITE ASSESSMENT: QUESTIONS FOR THE CLIENT   SECURITY SITE ASSESSMENT: CONSULTANT QUESTIONS   
Security site assessment FAQ: Questions for the consultant


Assessment questions
<< PREVIOUS | NEXT >>: What is the proper methodology for security site...

Have access credentials, documentation and training been provided?

19 May 2008 | SearchSecurityChannel.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

About the author
Joel Scambray has held diverse roles in information security over a dozen years, including co-author of Hacking Exposed: Windows and Hacking Exposed: Web Applications, senior director of security at Microsoft, co-founder of security technology and service company Foundstone, senior security consultant for Ernst & Young and internationally recognized speaker in both public and private forums. Listen to the supplemental podcast with Joel for more information on security site assessments.

A lack of access/credentials is often a major showstopper -- it's hard to assess something that you can't get to! Allow appropriate padding to the schedule to ensure that customer credential/account provisioning systems/processes work. If the assessment is full-knowledge, make sure the consultants have access to any documentation, personnel and/or training that may be required. For example, a white-box line-of-business application assessment should begin with a review of software design and specification documentation, plus any necessary training on accessing software source code and bug-tracking repositories. Without these items, the assessment team can sit idle while the customer gets little value -- all due to a simple lack of preparation.

Another necessity of preparation is to ensure that permissions have been granted to assess all of the elements within scope. It never hurts to re-clarify with the customer if there are any doubts, particularly around partner/third-party systems that may be of unclear ownership. This issue commonly arises in outsourced data center hosting arrangements, where many organizations are hosted near each other by a common provider(s), and access to the customer potentially crosses third-party-owned infrastructure. Be sure that the assessment techniques being employed are well-understood by all parties, so as to avoid unnecessary risks of downtime or policy violations to unrelated systems.

Return to the security site assessment FAQ guide and read the rest of Joel's expert answers.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: What is the proper methodology for security site...
VIEW ALL IN THIS CATEGORY

RELATED CONTENT
Security Risk Analysis and Risk Management
How to perform a network security audit for customers
How to generate revenue from unified threat management
Unified threat management: Migration and management techniques
Unified threat management: An intro for solution providers
Podcast with Dr. Paul Rohmeyer on choosing a remote management platform
Have you created a map of the to-be architecture?
How will you leverage the remote management platform architecture to demonstrate controls effectiveness?
How does the remote management platform complement your existing architecture?
What is your business and what are the data risks?
How will you monitor for unknown threats with the remote management system?

Assessment questions
Has a kick-off meeting been held for the security site assessment?
What is the proper methodology for security site assessments?
Are required tools and people available to complete work on schedule?
How to guarantee customer satisfaction after a security assessment?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts