RE: Penetration Test Vendors

2010-06-24 Thread Chris Gravell
Pen-testing for what?

-Original Message-
From: Scott Berkman [mailto:sc...@sberkman.net] 
Sent: Wednesday, June 23, 2010 1:28 AM
To: 'Ken Gilmour'; 'George Bonser'
Cc: nanog@nanog.org
Subject: RE: Penetration Test Vendors

If I wanted someone to do this, I'd probably look at a security vendor
instead of a general purpose consulting firm.

Some examples off the top of my head might include IBM's ISS and
SecureWorks.

-Scott

-Original Message-
From: Ken Gilmour [mailto:ken.gilm...@gmail.com] 
Sent: Tuesday, June 22, 2010 4:58 PM
To: George Bonser
Cc: nanog@nanog.org
Subject: Re: Penetration Test Vendors

Depends on where you are... I've used Sysnet in Europe (www.sysnet.ie) and
they are excellent. We used Deloitte (
http://www.deloitte.com/view/en_GX/global/services/enterprise-risk-services/
security-privacy-resiliency/pcidss/index.htm)
in non-european countries, with not such a good result (but other people may
have different experiences).

Regards,

Ken

On 22 June 2010 14:48, George Bonser  wrote:

> Anyone have any suggestions for a decent vendor that provides network
> penetration testing? We have a customer requirement for a third party
> test for a certain facility. Have you used anyone that you thought did a
> great job?  Anyone you would suggest avoiding?
>
> Replies can be sent off list and I will summarize any feedback I might
> get from the community if anyone is interested.
>
> George
>
>
>






RE: Sources of network security templates or designs

2010-06-24 Thread Chris Gravell
You start with all of them once you have a good understanding of the underlying 
protocols.

There is no cheat-sheet.

-Original Message-
From: Sean Donelan [mailto:s...@donelan.com] 
Sent: Thursday, June 24, 2010 2:45 AM
To: nanog@nanog.org
Subject: Sources of network security templates or designs

While every network designer/architect with an emphasis on security has 
his or her favorite design templates, I'm wondering what public sources 
do people start with?

Cisco SAFE and other published designs
IBM Redbooks
DOD Security Technical Implementation Guides (STIGs)
NIST Special Publications
O'Reilly series (specific books?)

Of course, every designer customizes things based on the project and
preferences.  So I'm not asking for what's best, or even what's wrong
with particular sources.  Just where do you start?