LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-17-2006, 12:47 PM   #1
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Rep: Reputation: 60
Vulnerabilty Assestments


I have several questions regarding security. I have formed a business and I would like to focus on network security and what services I can provide:

1 - What is performed in an application security assestment. What does it consist of?

2 - When performing a a true penetration test of a business what is involved? What does it consist of?

3 - What is the difference between a Penetration Test and a Wireless security assestment?

4 - What does ensuring data entegrity consist of? How would one achieve this ?

5 - Can anyone point me in the right direction of find an IT guideline for Health Insurance Portability & Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI DSS) and Sarbanes-Oxley (SOX) compliancy ?

Last edited by metallica1973; 03-17-2006 at 12:56 PM.
 
Old 03-17-2006, 03:24 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by metallica1973
I have several questions regarding security. I have formed a business and I would like to focus on network security and what services I can provide:

1 - What is performed in an application security assestment. What does it consist of?

2 - When performing a a true penetration test of a business what is involved? What does it consist of?

3 - What is the difference between a Penetration Test and a Wireless security assestment?

4 - What does ensuring data entegrity consist of? How would one achieve this ?

5 - Can anyone point me in the right direction of find an IT guideline for Health Insurance Portability & Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI DSS) and Sarbanes-Oxley (SOX) compliancy ?
i find it hard to believe that someone would start a security business and THEN start asking/learning about these things... are you sure this isn't homework??? hehe...

anyways, here's some links i googled for you, it's not much but it's my ... i'm sure others will provide more and better stuff...

http://en.wikipedia.org/wiki/HIPAA

http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act

http://www.technicalinfo.net/papers/...Questions.html

http://www.penetration-testing.com/

good luck with your paper...

Last edited by win32sux; 03-17-2006 at 03:31 PM.
 
Old 03-17-2006, 03:46 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,417
Blog Entries: 55

Rep: Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627
i find it hard to believe that someone would start a security business and THEN start asking/learning about these things...
Hmm, starting a business w/o getting basics right first isn't the best thing to do IMHO.


i'm sure others will provide more and better stuff...
Don't be too sure, because:

@metallica1973: now you do know where to find the list with sites that contain security news and backgrounds. You might even have read some of those sites for no particular reason just to build up knowledge. If you didn't I would suggest you do so. To get a grip on what's being done in the field: simply check your "competitors". Wrt to definitions, methodology and cases check out the SANS reading room, owasp.org and securityfocus.com. In closing HIPAA, PCI DSS and SOX are all perfect search terms. Don't get me wrong here, if you have specific questions I'd love to answer them, but asking such broad questions to me means you gotta read up first.
 
Old 03-17-2006, 04:45 PM   #4
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
All I am trying to do is to determine if I am on the right track not some idiot trying to maliciously cause destruction. I was under the impression that I could ask a professional question and get a professional anwser in this forum. I have noticed that everytime I ask a question in this arena everyone is very hestitant on give out some information in fear of creating a monster. That may be the case with some of these teenage cyborgs that dont even know what a girls is but not in my case. At least anwser this question if you are not going to awnsering the other. It is true that one needs to know how to hack in order to defend against a hacker. At least give me that. A point I would like to make for the people who do not know the meaning of running a business is and what is involved (I wont mention any names). If I dont have a skill that I need to run my business there is something called smarts in hiring someone who does.

Last edited by metallica1973; 03-19-2006 at 12:15 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration