Security Basics mailing list archives
Re: Why Security testing is required
From: "steve" <securityfocus () delahunty com>
Date: Tue, 24 Feb 2004 12:59:13 -0500
One more "point of view" to add would be that of auditors. Another reason to test security is to see if you have implemented systems that enforce your policies. So reverse engineer your written policies and test. For instance, are you blocking EXE attachments if that is your policy, are you blocking PORN websites if that is your policy, does your firewall prohit incoming SQL port 1433 if that is your policy, and so forth. ----- Original Message ----- On Feb 19, 2004, at 9:07 PM, Matt Lyon wrote:
Hi List,As a non technical person I want to know why security testing is required when all security systems like Firewall, IDS and content management are in place. This is a very basic question but I want to know answers from different users point of view like:- 1. system Administrator 2. system Manager 3. User 4. CEO of the company Thanks in advance. NKPBecause you can't assume the infalibility of those systems. An employee could introduce a hole and not know it thus leaving your whole system vulnerable. IMHO the hardest part of keeping a network secure is limiting the human factor.
--------------------------------------------------------------------------- ----------------------------------------------------------------------------
Current thread:
- RE: Why Security testing is required Matt Lyon (Feb 20)
- Re: Why Security testing is required Meritt James (Feb 24)
- Re: Why Security testing is required Rishi Pande (Feb 24)
- Re: Why Security testing is required steve (Feb 24)
- most that can happan (was Re: Why Security testing is required Meritt James (Feb 25)
- RE: Why Security testing is required David Gillett (Feb 24)
- Re: Why Security testing is required Byron Sonne (Feb 24)
- Re: Why Security testing is required captgoodnight (Feb 24)
- RE: Why Security testing is required Navaneetharangan (Feb 26)
- Re: Why Security testing is required Meritt James (Feb 26)
- RE: Why Security testing is required Navaneetharangan (Feb 26)
- RE: Why Security testing is required Raoul Armfield (Feb 24)
- RE: Why Security testing is required Steve (Feb 24)
- <Possible follow-ups>
- Re: Why Security testing is required Fralick, Alan (Feb 25)
- RE: Why Security testing is required Ryan Cornelsen (Feb 27)
