Posts

Showing posts with the label security audits

GFI LANguard 9 Review

Image
As a consultant, I used GFI LANguard (7?...it was at least 2 years ago) as a tool, in conjunction with nmap and some others, to perform security audits for our clients. Now I've an opportunity to use it again, and agreed to give it a review. Environment Dell Dimension 5150 P4 3ghz, 2gb Ram SLED 10.1, running VMWare Server 1.x 768mb allocated for XP SP2 Instance LAN, 2003 Domain in mixed mode The download from GFI's website was surprisingly small; only 50mb. The installation was straight forward, with only two questions; installation location, and initial credentials to use for scanning your domain. The UI is no different, very intuitive. I'd expect nothing else from GFI, since most of their products are the same way. The product is broken up into four components: Management Console - the central location for launching scans, view saved scans, configure options, and use specialized network security tools. Attendant Service - runs scheduled scans and patch deploymen...

Security Audits

Late 2005 I was working for a consulting company in the Milwaukee area. In an attempt to continue to move from a break-fix environment to a more proactive, managed IT approach, I was asked to develop a security audit methodology, which we would use in conjunction with our "taste-test" approach to new customers. A taste-test was really nothing more than an engineer and a salesman showing a potential client how smart we were, how messed up their environment was, and how we could help them. We decided to use the Security Audit as another layer to enhance what we had to offer. Here is an outline of the methodology I used, which was borrowed in large part from the SANS institute, along with a sample statement of work that was presented to my now employer. Read this doc on Scribd: Security Audit Methodology Security Audits A security audit will use best practice methods to discover, assess, test, and finally, suggest modifications to existing security infrastruc...