Security Basics mailing list archives

Re: Initial Security assesment for a large university - what to ask?


From: Lorenzo Nicolodi <lorenzo.nicolodi () gmail com>
Date: Thu, 1 Apr 2010 08:08:50 +0200

Hello Camilo

other things I would ask to them would be:

- emergency response plans
- network schemas & Co (these are not related to security per se, but
they would be great for understanding the design and to evaluate
possible errors(e.g.: a server whit a network interface connected in
the private LAN and another interface connected in the DMZ))
- backup&restore procedures (if not included in the emergencies response plans)
- a list of all the people and the contacts which are related to the
"security slice" of the infrastructure (firewall producers, IDS / IPS
technicians, etc...)
- a list of the maintenance agreements (for example for the firewall /
IPS / IDS management, etc...)

Of course this is not an comprehensive list, but hope it helps :)

L.

On Wed, Mar 31, 2010 at 7:40 PM, Camilo Olea <colea () sunset com mx> wrote:
Dear friends,

I've been asked to be part of a large project. A local college (in
Cancun,MX) is changing administration, and as a part of it, seems like they
are changing the whole IT team. My orders were clear "Make a list of all
that they need to give to you, security-related".

I'm thinking:

- root logins and passwords for all servers/routers/etc


... and I stopped there. Any other ideas on what I should demand from them?

Thanks,
Camilo Olea

-Por favor piense en el medio ambiente antes de imprimir este mensaje-
-Please think of the environment before printing this message-

La informacion  de  este correo es de caracter CONFIDENCIAL y PRIVADO y es
propiedad de GRUPO SUNSET. La privacidad  de esta comunicacion goza de
proteccion legal. Cualquier revision, retransmision, difusion o cualquier
otro uso de este correo, por personas o entidades distintas a las del
destinatario legitimo, queda expresamente prohibida. Si usted ha recibido
este mensaje por error, por favor avise inmediatamente al remitente
contestando y eliminando este correo. Las opiniones incluidas son del
remitente, y no necesariamente reflejan  la opinion de GRUPO SUNSET. Este
correo electronico no pretende ni debe ser considerado como constitutivo de
ninguna relacion legal, contractual o de otra indole similar.  No puede
garantizarse que las comunicaciones de Internet sean seguras, libres de
error o virus. Por lo tanto GRUPO SUNSET, no acepta responsabilidad alguna.
The contents of this email are CONFIDENTIAL and PRIVATE in nature, and
remain the property of SUNSET GROUP. The privacy of this email is protected
by law. Any revision, forwarding, distribution or any other use of this
email, for persons or entities other than the legitimate addressee, is
forbidden. If you have received this message by mistake, please alert the
sender immediately by responding to and then eliminating this email. The
opinions expressed in this email are those of the sender, and may not
necessarily reflect the opinions of SUNSET GROUP. This email does not
constitute, nor should it be considered as confirmation of any legal,
contractual, or any other relationship. Internet communications cannot be
guaranteed to be secure or error-free, as information could be intercepted,
corrupted, lost, arrive late or contain viruses. SUNSET GROUP does not
accept liability for any errors or omissions in the context of this message
which could arise as a result of Internet
transmission.

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL
certificate.  We look at how SSL works, how it benefits your company and how
your customers can tell if a site is secure. You will find out how to test,
purchase, install and use a thawte Digital Certificate on your Apache web
server. Throughout, best practices for set-up are highlighted to help you
ensure efficient ongoing management of your encryption keys and digital
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: