Auditing Security Controls: Policy Compliance, Vulnerability Assessment, and Pen Testing

Determining security policy and implementing the technical controls that support it is not a trivial task. Keeping controls in place is harder. There are many reasons for this:

  • Security policy can change. Although this is not usually a rapid process, when a change is made, it can mean that a lot of configuration changes or procedural changes are needed. Security policy changes can result from legislative changes, internal or external audits, a better understanding of the technology or the risks inherent in its use for a specific purpose, or even management's acceptance of a proposed change from you.

  • Required changes to operating systems and applications (patches ...

Get Windows Server 2003 Security: A Technical Reference now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.