Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Security Metrics -- Measuring a firm's security

Status
Not open for further replies.

odinfire

MIS
Jan 20, 2003
76
US
Greetings all!

I am looking for someone out there who may have some ideas, or a template, on some measurables that can be quantified for the security audit of an organization. Some examples of the metrics I had in mind include:
1) Patch Level - How many users are patched?
2) Password Compliance - Are users adhering to policy?
3) User Installed software - Inapproriate rights for users?
If anyone can provide, or point me in the right direction, information on this topic I would be much obliged.

Regards,

Odin
 
Were I work we use a product from Internet Security Systems called ISS7, their site is at
Pretty good tool, it will do everything you are asking for and tons more. But do check the price, I have no idea what this thing costs but I'm sure it is a bundle.

SF18C
CCNP, MCSE, A+, N+ & HPCC

"Tis better to die on your feet than live on your knees!"
 
I use Nessus Security Scanner to verify that systems are patched against known vulnerabilities.

Available at , but it requires a linux system to use it.

For Microsoft Systems, You can use Microsoft baseline security Analyzer. It will give you a starting place on Microsoft Systems

available here
Craig

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top