【24h】

Security audit: a case study information systems

机译:安全审核:案例研究信息系统

获取原文

摘要

This paper presents the basics of an information systems security audit, through a real security audit carried out on a medium-sized organization. The audit was the 1/sup st/ security audit done on the company and would serve as a security baseline for future audits. An effective security audit should not be a one-time event but rather an ongoing process. Security is a delicate balance between protection, availability and user acceptance. We start the security audit at the outside of the network and gradually work our way inward. We performed a vulnerability check on the exposed IP addresses and ports. Each of the vulnerabilities found was carefully assessed to see if it violated the security policies of the organization. An analysis of firewalls and various remote access methods of the organization were also evaluated. Using a wireless network sniffer, we found the footprints of the wireless LAN and some interesting results were obtained. Finally, some sensitive managerial issues and findings of an awareness survey of information security were presented.
机译:本文通过对中型组织进行的真实安全审核,介绍了信息系统安全审核的基础。审核是对公司进行的1 /后/安全审核,并将用作将来审核的安全基准。有效的安全审核不应是一次性事件,而应该是一个持续的过程。安全性是保护,可用性和用户接受度之间的微妙平衡。我们从网络外部开始进行安全审核,然后逐步向内进行。我们对公开的IP地址和端口进行了漏洞检查。对发现的每个漏洞均进行了仔细评估,以查看其是否违反了组织的安全策略。还评估了防火墙和组织的各种远程访问方法的分析。使用无线网络嗅探器,我们发现了无线局域网的占用空间,并获得了一些有趣的结果。最后,介绍了一些敏感的管理问题和信息安全意识调查的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号