Penetration Testing mailing list archives

[PEN-TEST] Help defining job scope


From: "Steven W. Smith" <SYSSWS () GC MARICOPA EDU>
Date: Tue, 22 Aug 2000 09:12:59 -0700

  I'm transitioning from systems management and programming into a "site
security person" role.  We don't even have an appropriate job title, yet.

  I've read horror stories about security people prosecuted for performing
their jobs and I don't want to follow in their footsteps.  I'd like to write a
document alluding to job duties that I'm authorized to perform: port scans,
probing for vulnerabilities, etc. and get a hardcopy signed by my boss and
his boss.

  I'm not looking for a laundry list of what I can do, rather, a "this guy is
*supposed* to be doing scary stuff" doc.  I'd really appreciate any
suggestions toward this goal and/or pointers to net resources.  Thanks much!
If this is off-topic for the list I trust it won't make it past the moderator.

Steve

Steven W. Smith, Systems Programmer
Glendale Community College. Glendale Az.
syssws () gc maricopa edu


Current thread: