Great Circle Associates Firewalls
(February 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Certifiying Security Auditors
From: Mark Teicher <mht @ clark . net>
Date: Fri, 20 Feb 1998 18:42:22 -0500 (EST)
To: Peter da Silva <peter @ baileynm . com>
Cc: books @ mail . state . fl . us, firewalls @ GreatCircle . COM
In-reply-to: <9802191609 . AA12826 @ baileynm . com>

Peter et al,

If that was true, why is there such a flurry of NT Security books being
pushed out by the publishers..Understanding the internals of NT, how to
create efficient or 'anal retentive' security policies , stripping out
the overhead and such is similiar to tuning a UNIX box <insert UNIX O/S of
choice here>  ..

Just composing a security policy takes some skill in filtering out from a
particular environment what mass of knowledge dictates how the
particular's company network is laid out, what O/S are used, what hardware
is used, who has access to what, what type of access, etc, etc. The list
can go on and on.  

Any system be it as simple as you state or as complex in some cases.  Ever
try conducting an audit on NT and interviewing the person at the
particular customer's site you are at to even document how he/she set it
up and why they choose a particular configuration over another..  Hmm..

The same disciplines that this thread has been ranting and raving about
for almost a week now..

Just admitting that this industry is in CHAOS is the first step to
salvation..

/mht

On Thu, 19 Feb 1998, Peter da Silva wrote:

> > Can you say "Unix"?  Since when does a programmer need to know how to load
> > windows NT?  Does an author need to be able to make a pencil?
> 
> I can't conceive of how anyone could manage to get a degree without learning
> the minimal technical knowledge involved in installing NT. You boot off the
> floppy and follow instructions. The only technical material is the IP
> addressing and maybe setting or reading jumpers, and that's not NT specific.
> 

##########################################################
'Turn on, Boot Up, Jack in'
#########################################################    



Follow-Ups:
References:
Indexed By Date Previous: Re: Cisco & WheelGroup -reply
From: Mark Teicher <mht @ clark . net>
Next: Re: What kind of list do you people run?
From: Jamie Lawrence <jal @ 42is . com>
Indexed By Thread Previous: Re: Certifiying Security Auditors
From: Peter da Silva <peter @ baileynm . com>
Next: Re: Certifiying Security Auditors
From: Peter da Silva <peter @ baileynm . com>

Google
 
Search Internet Search www.greatcircle.com