thepete
0 pts. | Nov 18 2004 8:57AM GMT
In security products, you often will find they are offering you solutions to problems you don’t know you have (or had). It is no different here. First find out what you really need, such as through a thorough security test, and then apply the right solution where appropriate. A security test will also act as a quarterly reporting tool. Finally, don’t confuse a security test with a penetration test or IT audit. Look at the OSSTMM at <a href="http://www.osstmm.org/" title="http://www.osstmm.org/" target="_blank">http://www.osstmm.org/</a> and the security metrics used in SOX quarterly reporting at <a href="http://www.isecom.org/securitymetrics.shtml" title="http://www.isecom.org/securitymetrics.shtml" target="_blank">http://www.isecom.org/securitymetrics.sh…</a>. You will find even a very useful security metrics reporting tool called SecurityNOW! from CIOview there which is really worth looking at.
Once you’ve done that, then go back and match the things that are missing from your security to the appropriate product.






