<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Shades of Gray Security &#187; assessment</title>
	<atom:link href="http://shadesofgraysecurity.com/tag/assessment/feed/" rel="self" type="application/rss+xml" />
	<link>http://shadesofgraysecurity.com</link>
	<description>Because security isn't always black &#38; white</description>
	<lastBuildDate>Thu, 17 Mar 2011 07:20:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Penetration Testing Primer</title>
		<link>http://shadesofgraysecurity.com/penetration-testing-primer/</link>
		<comments>http://shadesofgraysecurity.com/penetration-testing-primer/#comments</comments>
		<pubDate>Wed, 28 Apr 2010 01:27:26 +0000</pubDate>
		<dc:creator>Chad Olivier</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[assessment]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[vulnerabilties]]></category>

		<guid isPermaLink="false">http://shadesofgraysecurity.com/?p=204</guid>
		<description><![CDATA[This is the slide deck from a talk I did for the Greater New Orleans ISACA group in October 2009 (Yes, I know that was 7 months ago). It&#8217;s very high level, and is full of holes, but my target audience was not a bunch of 1337 haxx0rs so keep that in mind. It&#8217;s an [...]]]></description>
			<content:encoded><![CDATA[<p>This is the slide deck from a talk I did for the Greater New Orleans ISACA group in October 2009 (Yes, I know that was 7 months ago). It&#8217;s very high level, and is full of holes, but my target audience was not a bunch of 1337 haxx0rs so keep that in mind. It&#8217;s an introduction to hacking concepts and should be treated as such. Feel free to leave some feedback. <a href="http://shadesofgraysecurity.com/wp-content/uploads/2010/04/Pen-test-primer.pptx">Download Penetration Testing Primer here.</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fshadesofgraysecurity.com%2Fpenetration-testing-primer%2F&amp;title=Penetration%20Testing%20Primer" id="wpa2a_2"><img src="http://shadesofgraysecurity.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Penetration Testing Primer"  title="Penetration Testing Primer photo" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://shadesofgraysecurity.com/penetration-testing-primer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security from Obscurity: Building a Security Program, Define the Domain</title>
		<link>http://shadesofgraysecurity.com/building-security-program-part2/</link>
		<comments>http://shadesofgraysecurity.com/building-security-program-part2/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 00:00:23 +0000</pubDate>
		<dc:creator>Chad Olivier</dc:creator>
				<category><![CDATA[security governance]]></category>
		<category><![CDATA[assessment]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security program]]></category>

		<guid isPermaLink="false">http://shadesofgraysecurity.com/?p=160</guid>
		<description><![CDATA[In our first installment, we decided who needs to be involved in the program and an idea of how it is structured and to whom it reports. That&#8217;s a great start! If you haven&#8217;t had a chance to read that article, check here. Now we need to start looking at what we are securing? What [...]]]></description>
			<content:encoded><![CDATA[<p>In our <a title="Building a Security Program, Part 1" href="http://shadesofgraysecurity.com/building-security-program-part1/">first installment</a>, we decided who needs to be involved in the program and an idea of how it is structured and to whom it reports. That&#8217;s a great start! If you haven&#8217;t had a chance to read that article, <a title="Building a Security Program, Part 1" href="http://shadesofgraysecurity.com/building-security-program-part1/">check here</a>. Now we need to start looking at <em>what</em> we are securing? What is it we are governing? What is the scope? If we don&#8217;t have that defined, we can&#8217;t really protect it can we?</p>
<p>It&#8217;s probably easier to define what isn&#8217;t in a <a href="http://shadesofgraysecurity.com/tag/security-program/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security program">security program</a>, than what is in it! That&#8217;s right, security is going to touch almost every aspect of your organization. Every organization is different, they all have their own threats, compliance issues, business lines, risks, etc. Even in the same industry, the <a href="http://shadesofgraysecurity.com/tag/security-program/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security program">security program</a> requirements can vary greatly. However, they all typically have the same basic elements.</p>
<p>Every organization has assets. This is what we are defending and we&#8217;ll call this tier 1. Assets can be systems, knowledge, data, people, etc. It just depends on the organization, and if applicable, it&#8217;s business lines. Tier 2 are the elements influencing tier 1. Assets are protected by network security, physical security, system/software lifecycle security, and communication security. Factors effecting the assets and security of the assets include threats and threat management, compliance with <a href="http://shadesofgraysecurity.com/tag/policy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with policy">policy</a> (note, we are not talking regulations, that comes at a higher tier), metrics for evaluating our security (defined in a higher tier), vulnerability management, and incident response. Elements that drive tier 2 and therefore will be called tier 3 include personnel security, <a href="http://shadesofgraysecurity.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> <a href="http://shadesofgraysecurity.com/tag/assessment/" class="st_tag internal_tag" rel="tag" title="Posts tagged with assessment">assessment</a>, audits, business continuity planning (BCP), metrics development, process management, threats and vulnerabilities (yes they appear here as well as this level is also being protected), data classification, and  process management. Tier 4 is the final tier we will cover. This however can be expanded to additional tiers depending on complexity of organizational structure and regulations/laws, but we are talking basics here. Tier 4 includes, regulations, laws, <a href="http://shadesofgraysecurity.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> analysis, the overarching security program, <a href="http://shadesofgraysecurity.com/tag/policy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with policy">policy</a> development, process development and monitoring, <a href="http://shadesofgraysecurity.com/tag/governance/" class="st_tag internal_tag" rel="tag" title="Posts tagged with governance">governance</a> model, and organizational security.</p>
<p>In some capacity, your organization MUST have each of these components to have an effective security program. I know, that seems like a daunting task. It is no small undertaking to establish all that, and if the company has grown for years without it, it will be extremely difficult to change the culture of the organization to be accepting of such a wide sweeping change. Remember though, if you followed<a title="Building a Security Program, Part 1" href="http://shadesofgraysecurity.com/building-security-program-part1/"> part 1</a>, you have the authority of the board and CEO. This is a mandate. If not, you&#8217;re wasting your time. That isn&#8217;t to say, be ugly about it. In fact, just the opposite. The people that need to be involved in this process (which is pretty much everyone in the organization in some aspect) MUST want to participate or they won&#8217;t live up to their end. A great way to start is training your employees on how to protect themselves from predators. This will get them engaged and thinking about security in new ways.</p>
<p>Most companies have no idea where to begin trying to get a handle on all those elements. Fortunately, you are reading this article to help you on your way. There are plenty of great resources out there for best practices guidelines. ISO 17799 and it&#8217;s successor is a fantastic resource. It is an internationally recognized standard for information security governance and provides high level recommendations for enterprise security programs. Divided into two main parts, the first is an implementation guideline and the second is an auditing guide.</p>
<p>As suggested in <a title="Building a Security Program, Part 1" href="http://shadesofgraysecurity.com/building-security-program-part1/">part 1</a>, security should be top down. Meaning the board down to upper management, middle management, and finally the staff. A bottom up approach in which the IT department tries to initiate a security program is less effective, won&#8217;t get full buy in from other departments/business lines, and is doomed to fail. Other than the obvious lack of buy in from others, it is generally focused on technology and leaves all other vectors of attack untouched. The people actually responsible for protecting the assets must be driving the program.</p>
<p><a title="Contact Shades of Gray Security" href="http://shadesofgraysecurity.com/about/contact">Contact Shades of Gray Security</a> to find out how we can help you setup and manage your security program today!</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fshadesofgraysecurity.com%2Fbuilding-security-program-part2%2F&amp;title=Security%20from%20Obscurity%3A%20Building%20a%20Security%20Program%2C%20Define%20the%20Domain" id="wpa2a_4"><img src="http://shadesofgraysecurity.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Security from Obscurity: Building a Security Program, Define the Domain"  title="Security from Obscurity: Building a Security Program, Define the Domain photo" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://shadesofgraysecurity.com/building-security-program-part2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security from Obscurity: Building a Security Program, Intro</title>
		<link>http://shadesofgraysecurity.com/building-security-program-part1/</link>
		<comments>http://shadesofgraysecurity.com/building-security-program-part1/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 20:07:47 +0000</pubDate>
		<dc:creator>Chad Olivier</dc:creator>
				<category><![CDATA[security governance]]></category>
		<category><![CDATA[assessment]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security program]]></category>

		<guid isPermaLink="false">http://shadesofgraysecurity.com/?p=106</guid>
		<description><![CDATA[After reflecting on much of my career, and more specifically, my last job, I have decided to write a series of articles about starting a security program. I have set foot in pretty much every industry type and every organization size and from small banks, to law firms, to large Fortune 500 energy companies, across [...]]]></description>
			<content:encoded><![CDATA[<p>After reflecting on much of my career, and more specifically, my last job, I have decided to write a series of articles about starting a <a href="http://shadesofgraysecurity.com/tag/security-program/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security program">security program</a>. I have set foot in pretty much every industry type and every organization size and from small banks, to law firms, to large Fortune 500 energy companies, across the board, there are always companies who turn a blind eye to security. Why? Some, like law firms, think they are not targets. I have all too often heard the same thing from law firms. &#8220;Everything we have here is on the public record, so it doesn&#8217;t matter if someone steals our data.&#8221; Trouble is, not ALL of your stuff is on the public record, things like medical records of clients, credit reports, payment info, the evidence you have on a case that, while you will ultimately have to turn over to the opposition before trial, you may not want to show your hand now, etc. Some are just young naive companies who grew into a Fortune 500 overnight and have no idea how they got there or what they need to do to ensure their survivability. These types seem to be intimidated by the idea of security and prefer to stick their heads in the sand and pretend there is nothing to worry about. Trouble is, when you stick your head in the sand, guess which part of your body is sticking up in the air!</p>
<p>But I digress, this series of articles is about the hows of starting a security program, not the whys. Keeping the various sizes and roles of companies I have either worked for or with in mind, I am going to give some pointers on how to get the ball rolling on this daunting task.</p>
<p>First, let&#8217;s talk about what security is, and isn&#8217;t. It isn&#8217;t just having a <a href="http://shadesofgraysecurity.com/tag/policy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with policy">policy</a> and then turning to network defense appliances and washing your hands of the idea, mission accomplished. If your security program isn&#8217;t mandated by the board, mapped to all business lines, legal and regulatory requirements, and threat agents, it isn&#8217;t complete. It also isn&#8217;t enough to guard the perimeter while leaving the internal network in shambles. Likewise, if you don&#8217;t have data classification, you can&#8217;t move forward in a security program. After all, what is it you&#8217;re protecting and why? How can you have a <a href="http://shadesofgraysecurity.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a> <a href="http://shadesofgraysecurity.com/tag/assessment/" class="st_tag internal_tag" rel="tag" title="Posts tagged with assessment">assessment</a> if there isn&#8217;t a metric for what is at <a href="http://shadesofgraysecurity.com/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a>?&#8221;If you don&#8217;t eat your meat, you can&#8217;t have any pudding! HOW can you have any pudding if you don&#8217;t eat your meat?!&#8221; Wait, I&#8217;ve gone off topic again. Anyway&#8230;</p>
<p>Let&#8217;s agree we need security and doing the above things simply isn&#8217;t cutting it. What are the first steps to getting your business security focused? Dive in and start applying patches? Install that much needed <a href="http://shadesofgraysecurity.com/tag/ips/" class="st_tag internal_tag" rel="tag" title="Posts tagged with ips">IPS</a>? Write policies? No. Our first steps are crucial and should happen in rapid succession.</p>
<p>The board, CEO, and so forth, all must be on board with this. If there is no mandate coming down from the top, hang it up, go home, forget about it, game over man&#8230; game over.</p>
<p>First and foremost, let&#8217;s agree we need qualified people architecting it. I know most people may laugh, but I have tragically seen unqualified people put in the position of managing security. This is NOT a job to be given to someone because they have seniority. You will FAIL. This director must report directly to the CEO and board. It is not in the best interest of security to report to the CIO, CTO, network director, etc. It is not in their best interest to have anything negative reported by the security department and it will therefore not be. A security team is not a political football to be used to give the board and CEO false hopes of a safe network by the network director all the while not letting them do their job because he may look bad. You will FAIL. It is not a department that needs to be a clapping monkey doing cheap tricks to impress upper management with &#8220;quick wins.&#8221; If anyone ever thinks about uttering the words &#8220;quick win&#8221; toss them out ASAP. You will FAIL. That&#8217;s another thing, if someone says you won&#8217;t fail, toss them out. You WILL FAIL. The difference is, how graceful you fail. Did you fail and know within seconds? Hours? Days? Years? Did you ever find out?</p>
<p>So for our first step, and end to this first installment, we need sign on from the board and CEO. We need qualified people in place to architect this program, we need the team to report directly to the board and CEO. If this is going to be a political football and for some reason, no one can put on the big boy pants and enforce the program, I would venture to say your best bet is to outsource the entire program.</p>
<p><a title="Contact Shades of Gray Security" href="http://shadesofgraysecurity.com/about/contact">Contact Shades of Gray Security</a> to find out how we can help grow your security department.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fshadesofgraysecurity.com%2Fbuilding-security-program-part1%2F&amp;title=Security%20from%20Obscurity%3A%20Building%20a%20Security%20Program%2C%20Intro" id="wpa2a_6"><img src="http://shadesofgraysecurity.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Security from Obscurity: Building a Security Program, Intro"  title="Security from Obscurity: Building a Security Program, Intro photo" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://shadesofgraysecurity.com/building-security-program-part1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Information Security Services</title>
		<link>http://shadesofgraysecurity.com/information-security-services/</link>
		<comments>http://shadesofgraysecurity.com/information-security-services/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 03:51:26 +0000</pubDate>
		<dc:creator>Chad Olivier</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[assessment]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security program]]></category>
		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://shadesofgraysecurity.com/?page_id=94</guid>
		<description><![CDATA[Security Assessments An assessment is critical to establish a baseline of your security posture. All future endeavors in security are based off this first, crucial step. Security Assessments from Shades of Gray Security are not your standard canned scan and report assessments you get from other companies. We take the time to learn your organization [...]]]></description>
			<content:encoded><![CDATA[<h2>Security Assessments</h2>
<p>An <a href="http://shadesofgraysecurity.com/tag/assessment/" class="st_tag internal_tag" rel="tag" title="Posts tagged with assessment">assessment</a> is critical to establish a baseline of your security posture. All future endeavors in security are based off this first, crucial step. Security Assessments from Shades of Gray Security are not your standard canned scan and report assessments you get from other companies. We take the time to learn your organization and present a more accurate picture of your security posture based on our matrix which analyzes your data based on several factors including threat agents, issue severity, and criticality of systems.<a title="Contact Shades of Gray Security" href="http://shadesofgraysecurity.com/about/contact"> Contact us</a> today to get more information and schedule an assessment today!</p>
<h2>Network/System Tuning</h2>
<p>Tired of companies handing you an assessment report, then washing their hands of you leaving you stuck trying to figure out just what to do with it? Don&#8217;t know where to begin improving your test scores? Shades of Gray Security can help! From server hardening to firewall rules, to installing and monitoring an Intrusion Detection System (IDS) or even an Intrusion Prevention System (<a href="http://shadesofgraysecurity.com/tag/ips/" class="st_tag internal_tag" rel="tag" title="Posts tagged with ips">IPS</a>), let us evaluate your needs and offer a great solution to increase your overall security posture today! <a title="Contact Shades of Gray Security" href="http://shadesofgraysecurity.com/about/contact">Contact us</a> now to learn more about what we can do to help keep your data safe!</p>
<h2>Penetration Tests</h2>
<p>What could a hacker find if they went after your systems? Let us find it before they do! A penetration test performed by Shades of Gray Security is a cut above the average test. We don&#8217;t give you a couple days of scanning and a cursory attempt at low hanging fruit. Shades of Gray Security gives a rigorous testing of your organization by a GIAC certified Penetration Tester. Chad Olivier is one of a handful of people in the world to have the GPEN certification from GIAC. We can customize the rules of engagement to suit your needs. Internal, external, blackbox, greybox, etc. Shades of Gray Security is ready to fit your <a href="http://shadesofgraysecurity.com/tag/penetration-testing/" class="st_tag internal_tag" rel="tag" title="Posts tagged with penetration testing">penetration testing</a> needs. Are you ready to pick up your pencil, open your workbook, and begin your test? <a title="Contact Shades of Gray Security" href="http://shadesofgraysecurity.com/about/contact">Contact us</a> today!</p>
<h2>Application Testing</h2>
<p>Have you developed a custom application? Do you have an interactive web site? Are you accidentally exposing sensitive data? Do you want to test it before it goes live? Has it already gone live and you&#8217;re wondering what may happen? Get some peace of mind and order an application test. We can handle source code reviews, or penetration tests. Have your application tested by a GIAC certified penetration tester today! <a title="Contact Shades of Gray Security" href="http://shadesofgraysecurity.com/about/contact">Contact us</a> now to get a good night&#8217;s sleep!</p>
<h2><a href="http://shadesofgraysecurity.com/tag/social-engineering/" class="st_tag internal_tag" rel="tag" title="Posts tagged with social engineering">Social Engineering</a></h2>
<p>A great many of the big &#8220;hacker&#8221; attacks were really social engineering. Social engineering is the new term for con artist. It could come in the form of a phishing scheme or the bad guy may just show up and talk his way in. Think it can&#8217;t happen? Think again! Chad Olivier has been performing social engineering tests for six years with a 100% success rate. These engagements are great when accompanied by training. We can first test your employees with social engineering efforts, then come back for training and point out good efforts of the staff, as well as areas that need improvements. This is much more effective than a standard training session, or a <a href="http://shadesofgraysecurity.com/tag/policy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with policy">policy</a> your employees have to read. This is the most effective way to grab their attention and get them thinking about security. The benefits don&#8217;t stop at the office, your staff will be able to incorporate the security tips learned during this engagement and subsequent training in their personal lives as well. Let us walk into your vault, before a criminal does! <a title="Contact Shades of Gray Security" href="http://shadesofgraysecurity.com/about/contact">Contact us</a> today!</p>
<h2>Incident Response</h2>
<p>The first steps in response to an attack are critical. Do you know what to do and when to do it? Let us help you design and plan your response. We offer services to be on call ready to respond with you. Have you ever had a virus spread throughout your organization? What did you do? Attempt to stop it while it continued spreading ultimately resulting in extensive damage both to data and loss of productivity? Did you perform forensics, or merely wipe the systems? Are you sure your data didn&#8217;t leak out during the attack? A virus is often times a side effect of having a trojan horse on a system It also makes a great method for covering your tracks after completing an attack. After all, what do people do? They wipe the system and destroy all evidence of the attack. Don&#8217;t let this happen to you! Let Shades of Gray Security prepare you for the worse. We will stand by you during your darkest hour and help you through the crisis. <a title="Contact Shades of Gray Security" href="http://shadesofgraysecurity.com/about/contact">Contact us</a> today to find out more about our incident response programs.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fshadesofgraysecurity.com%2Finformation-security-services%2F&amp;title=Information%20Security%20Services" id="wpa2a_8"><img src="http://shadesofgraysecurity.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Information Security Services"  title="Information Security Services photo" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://shadesofgraysecurity.com/information-security-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

