Firewall Wizards mailing list archives

Re: Re: Firewall Audit Programme/checklist


From: "Wei Li" <networkman () mailexcite com>
Date: Tue, 17 Mar 1998 05:11:04 -0700

Hi,

I'm a newbe on this list but here is my 2 cents.  When I provide security for any
site I start with a set of policies and procedure for the site, of course this is
a living document.  Then the security is built from it, so based on that you can
start your audit from there.  The site must have a minimum of a security document
where the firewall is built from.  If they don't have any document but a firewall
then you should tell them to start over with a set of policies and procedure.  

This is only my opinion.

---
Wei Li
networkamn () mailexcite com
wei () networkman com
www.networkman.com

Has anyone found or got an Audit Program for firewalls? or an audit
checklist for firewalls?

I do a lot of training for a "big six" firm and an audit checklist
is a fairly common request. I haven't ever given one to anyone,
because I don't have one. If you know what you're doing when you
audit a firewall, you don't need a checklist. If you don't know
what you're doing, you do -- but then you shouldn't be taking
someone's money to audit their firewall.

snip snip :-)
mjr.
--
Marcus J. Ranum, CEO, Network Flight Recorder, Inc.
work - http://www.nfr.net
home - http://www.clark.net/pub/mjr







Free web-based email, Forever, From anywhere!
http://www.mailexcite.com



Current thread: