pen-test
[Top] [All Lists]

Paper - Audit Taxonomy

To: pen-test@securityfocus.com
Subject: Paper - Audit Taxonomy
From: cwright@bdosyd.com.au
Date: 20 Jun 2007 20:45:54 -0000
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Wed, 20 Jun 2007 15:03:31 -0600 (MDT)
Resent-from: pen-test-return-1078484420@securityfocus.com
Resent-message-id: <20070620210331.2BAB6236F5D@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Hello,
A while back now I mentioned that I was going to write a definative paper on 
audit terminology. A few people asked me to forward this and I know a people 
had been looking to pick it apart ;).

The paper is now released (a little latter than anticipated, but such is life). 
It is titled:
"A Taxonomy of Information Systems Audits, Assessments and Reviews"

It is available directly from:
http://www.sans.org/reading_room/whitepapers/auditing/1801.php

Or via the SANS reading room at:
http://www.sans.org/reading_room/last.php     and
http://www.sans.org/reading_room/whitepapers/auditing/

The assertions made in the paper are validated experimentally in the second 
half of the paper for those who enjoy a little math.

Regards,
Craig S Wright

Abstract:
Common misconceptions plague information systems audit as to the nature of 
security,
audit and assessment types and definitions. The dissertation aims at being a 
definitive
guide to define the terminology and detail the related methodologies across the 
range of
information assurance services. The idea is to not only detail and define the 
types of
audit, assessment inspections [etc], but to compare and evaluate the various 
strengths and
benefits of each in a simple and referential critique that may remove an 
abstraction of
error and confusion surrounding these services. The paper will cover the types, 
history
and basis for each type of service. The paper statistically compares the 
strengths and
weaknesses of each and sets out a scientifically repeatable foundation for the
deterministic nomenclature used in the industry.

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Are you using SPI, Watchfire or WhiteHat?
Consider getting clear vision with Cenzic
See HOW Now with our 20/20 program!

http://www.cenzic.com/c/2020
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>
  • Paper - Audit Taxonomy, cwright <=