cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
722
Views
0
Helpful
4
Replies

Security Audit

j-allison
Level 1
Level 1

What would someone need to do a complete security audit on a network from the inside and the outside? What kind of legal documents would I need and where can I find samples? Any good web sites?

Thanks for the reply.

Jacques

4 Replies 4

k.poplitz
Level 3
Level 3

I actually looked into that and couldn’t find too much information. It’s worthwhile using a third party on this to have someone from the outside do the audit. What legalities concern you?

3tgrigsby
Level 1
Level 1

Hello Jacques, This sounds a lot like a system Certification and Accreditation that gov't organizations have to do on all of the sensitive systems.

There's a lot of "how to" type stuff at NIST:

http://csrc.nist.gov/

Good luck!!! Tom

jjwwilson
Level 1
Level 1

I've worked on several security audits (inside and outsite). I use what is called a "Get out of Jail" document that eliminates the liability that you might occure if in your audit you damage something. I also carry 1,000,000 insurance just in case. James Wilson jwilson@nmtg.com

sakeoseyan
Level 1
Level 1

Start with the Site Security Handbook... RFC-2196

http://www.cis.ohio-state.edu/Services/rfc/rfc-text/rfc2196.txt