RE: Is there any way to measure IT Security??

"Craig Wright" <[email protected]> Fri, 29 Jul 2005 09:17:16 +1000
Newsgroups gmane.comp.security.penetration,gmane.comp.security.linux,gmane.comp.security.libnet,gmane.comp.security.basics
Message-ID <2FE3228499A87F47ADF0B903A063D7450496AFB1@bdo-syd-nt-02.bdonsw.local>
17799 - part2
SANS have a few measures
The NSA and NIST methodologies are good
ITOL
COSO
COBIT

Lots and the list goes on....

Craig=20

-----Original Message-----
From: Larry Marin (Irony Account) [mailto:[email protected]]=20
Sent: 29 July 2005 2:30
To: Toto A Atmojo
Cc: [email protected]; [email protected];
[email protected]; [email protected];
[email protected]; [email protected];
[email protected]
Subject: Re: Is there any way to measure IT Security??

You should check out NSA IAM/IEM Methodology...it works well for me.
http://www.iatrp.com/iam.cfm


Toto A Atmojo wrote:

> Dear all,
>
> Currently I'm looking for a tool, or a technique to measure IT
security?
>
> The baseline for security is CIA (Confidentiality, Integrity and=20
> Availability), that is every organization which want to called secure=20
> must be guarantee that their system comply this matter.
>
> But the problem is, we need a tool/technique to measure how secure are

> we. Therefore, wee need a tool/technique to measure how close that our

> system status now to CIA.
>
> Please share your experience about this matter.
>
> If there any link about this issue, I really appreciate if you share=20
> to us (You may contact me privately) .
>
> Best Regs,
>
> Toto
>