-
19
pages
-
English
-
Documents
Description
LINUX Operating System Audit & AssessmentAugust 9, 2006www. lsat.sourceforg net (LSAT).www .bastille- linux.org (Jay Beale)(today’ s script 8.4)N o longer completely free: www.cisecurity.orgStandard disclaimer, “‘I never said TH AT, and if you did THA T, and something broke, it’ s your own durn fault. Al so, the views expressed here are mine, not my past, present or future employer’ s, and not the conference sponsor, nor any quail hunting partners. When using any tool, do no harm.”M ichael T H oesing C ISA, C ISSP, C IA, C C P, C M A, C PA AU4 11/14/20 0 5 m-hoesing@ cox.net (40 2) 981-7747Learning O bjectives• Define an Audit Approach/M ethodology• Determine Audit G oals, O bjectives, Scope• Individual Tests to Achieve the G oals (7) • O ther R esources• Auditing Example – an independent assessment process (take home scripts)Audit Approach• Determine K ey Success C riteria (objectives)• Define System Under R eview (scope, LIN UX, file server, web server, both)• Assess R isk (focus test resources where appropriate)• G ather Standards (policy, procedures, regulation, contracts)• Inventory the C urrent State (the scripts)• C ompare the C urrent State to Standards (analysis)• Investigate Differences (reporting, correction)Audit O bjectives and R isks• Authorized User Access H igh• Authorized Services, Daemons, M odules H igh• Authorized N etworking/C onnections H igh +• Authorized File Access H igh• Appropriate R ecording/Logging H ...
-
Publié par
-
Langue
English