Chapter 1. Network Security Assessment
This chapter discusses the rationale behind Internet-based network security assessment and penetration testing at a high level. To retain complete control over your networks and data, you must take a proactive approach to security, an approach that starts with assessment to identify and categorize your risks. Network security assessment is an integral part of any security life cycle.
The Business Benefits
From a commercial standpoint, information assurance is a business enabler. As a security consultant, I have helped a number of clients in the retail sector secure their 802.11 wireless networks used in stores. By designing and implementing secure networks, these retailers can lower their costs and increase efficacy, by implementing queue-busting technologies, for example.
Shortcomings in network security and user adherence to security policy often allow Internet-based attackers to locate and compromise networks. High-profile examples of companies that have fallen victim to such determined attackers in recent times include:
| RSA Security (http://www.2600.com/hacked_pages/2000/02/www.rsa.com/) |
| OpenBSD (http://lists.jammed.com/incidents/2002/08/0000.html) |
| NASDAQ (http://www.wired.com/news/politics/0,1283,21762,00.html) |
| Playboy Enterprises (http://www.vnunet.com/news/1127004) |
| Cryptologic (http://lists.jammed.com/isn/2001/09/0042.html) |
These compromises came about in similar ways, involving large losses in some cases. Cryptologic is an online casino gaming ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access