pen-test
[Top] [All Lists]

RE: Skype use obligation - Security x Productivity

To: <jreyna@onlinet.com.mx>, <marcio.barbado@gmail.com>
Subject: RE: Skype use obligation - Security x Productivity
From: Pradeep-Kumar.Karavadi@ubs.com
Date: Wed, 18 Jul 2007 07:01:04 +0100
Cc: <pen-test@securityfocus.com>
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
In-reply-to: <469CC8B3.4060602@onlinet.com.mx>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Tue, 17 Jul 2007 23:17:47 -0600 (MDT)
Resent-from: pen-test-return-1078484618@securityfocus.com
Resent-message-id: <20070718051747.7291C143E77@outgoing2.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Thread-index: AcfJAKnspls8rMEKQbGpnykwVOWrAAAAEXdA
Thread-topic: Skype use obligation - Security x Productivity
How about getting MindAlign installed. It's a security compliant IM. Many big 
organizations use it. Just give it a thought 

-----Original Message-----
From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com] On 
Behalf Of Javier Reyna Padilla
Sent: 17 July 2007 19:19
To: M.B.Jr.
Cc: pen-test list
Subject: Re: Skype use obligation - Security x Productivity

I think Skype is nt a professional service to send business oportunity, I am 
sure that this partner can implement an internal messaging service, like a 
jabber server, with acces just for the partners, one that can be audited and 
secured where theres a need to be secured. Or maybe an IM is not the solution.

M.B.Jr. wrote:
> Gentlemen,
> Iam part of a Brazilian Information Security consultancy focused on 
> the SMB market segment and we're facing sth new.
>
> We're used to see some companies offering partnership transactions 
> through web apps but this time we're dealing with the obligation of 
> sheltering a new service.
>
> Some backgound:
> one of our customers has its network pretty restricted, following ISO
> 27001 and ISO 17799 that is to say, all of the services within their 
> network were carefully chosen and deployed.
> Their network itself was meticulously designed.
>
> Now,
> one big partner they have is forcing them to install Skype in order to 
> keep'em up to receive new business opportunities.
>
> Well,
> Skype is against their policies.
> I was asked about how hazardous this could be to their network and I
> said:
> "no, Skype is not ok because it lacks transparency concerning your 
> firewalls, bridges, proxies and etc."
>
> Not to mention its port agile features.
>
> But,
> did not give one final word yet...
>
> The network's stability is my team's responsibility.
>
> What to do? Risk their efforts in obtaining ISO certification?
> Guess we need to hear some other professionals.
>
> Thank you,
> any comment will be extremmely useful.
>
>
>


--
¡Saludos!

________________

Javier Reyna
CCSA CCSE WCSE NSA NSP
Consultor en Seguridad
jreyna@onlinet.com.mx
www.onlinet.com.mx


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/c/wf-spi
------------------------------------------------------------------------

Visit our website at http://www.ubs.com

This message contains confidential information and is intended only
for the individual named.  If you are not the named addressee you
should not disseminate, distribute or copy this e-mail.  Please
notify the sender immediately by e-mail if you have received this
e-mail by mistake and delete this e-mail from your system.

E-mails are not encrypted and cannot be guaranteed to be secure or
error-free as information could be intercepted, corrupted, lost,
destroyed, arrive late or incomplete, or contain viruses.  The sender
therefore does not accept liability for any errors or omissions in the
contents of this message which arise as a result of e-mail transmission.
If verification is required please request a hard-copy version.  This
message is provided for informational purposes and should not be
construed as a solicitation or offer to buy or sell any securities
or related financial instruments.


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/c/wf-spi
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>