Newsletters Welcome, Guest Log In | Register


Join the Community

Exchange

Get full access to our community's expertise and resources.

Register Now >

Currently Being Moderated

Technical Guide to Information Security Testing and Assessment

0

Created on: Nov 4, 2009 2:29 PM by NIST - Last Modified:  Nov 4, 2009 2:29 PM by NIST

An information security assessment is the process of determining how effectively an entity being assessed (e.g., host, system, network, procedure, person—known as the assessment object) meets specific security objectives. Three types of assessment methods can be used to accomplish this—testing, examination, and interviewing. Testing is the process of exercising one or more assessment objects under specified conditions to compare actual and expected behaviors. Examination is the process of checking, inspecting, reviewing, observing, studying, or analyzing one or more assessment objects to facilitate understanding, achieve clarification, or obtain evidence. Interviewing is the process of conducting discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or identify the location of evidence. Assessment results are used to support the determination of security control effectiveness over time.

This document, provided by the National Institute of Standards and Technology, is a guide to the basic technical aspects of conducting information security assessments. It presents technical testing and examination methods and techniques that an organization might use as part of an assessment, and offers insights to assessors on their execution and the potential impact they may have on systems and networks. For an assessment to be successful and have a positive impact on the security posture of a system (and ultimately the entire organization), elements beyond the execution of testing and examination must support the technical process. Suggestions for these activities—including a robust planning process, root cause analysis, and tailored reporting—are also presented in this guide.

The attached Zip file includes:

• Intro Page.doc

• Cover Sheet and Terms.pdf

• Technical Guide to Information Security Testing and Assessment.pdf

Related Knowledge Network Content

Average User Rating
(0 ratings)




Add a comment Leave some feedback about this document.

There are no comments on this document

All About Reducing Your IT Costs

Looking to cut costs? Use this research-driven Excel tool to pinpoint which IT cost reduction measures best fit your needs.

Learn more >

Windows 7 Upgrade Project Kit

Moving to Windows 7? The Windows 7 Upgrade Project Kit is the ideal support tool for managing all phases of an organizational upgrade to Windows 7. The tools and templates in this kit will help you develop a strategy and map out the implementation tactics which link your Windows 7 deployment to your company's bottom line.

Learn more >

Smart Phones for Smart Business

Cutting-edge business applications and productivity uses, along with expert commentary, for today's smart phones.

Database Management

Data management tips and techniques that insure ease of access, comprehensive security and absolute privacy for your invaluable company information.

Compliance and Risk Mitigation

Compliance and risk mitigation solutions that strengthen data security, automate compliance measures, and reduce TCO for a more viable business future.

Greening IT with Server Consolidation

Learn how virtualization reduces the TCO of managing your date, while contributing towards your sustainability efforts.

How Real Are Cloud Security Concerns?

This technology briefing addresses some of the sources of confusion as they apply to IaaS implementations and then outlines the practices and technologies available to keep clouds safe in the areas where they do have unique vulnerabilities.

HP SiteScope Software Security Essentials

This white paper outlines how an agentless monitoring solution can securely transmit data and restrict access to satisfy even the most demanding security officer.