Network Security: A Practical Approach

The best security policy in the world isn t worth much unless it is implemented effectively. A security audit is a process that determines how well your network is protected against a variety of threats. Security audits usually include
Risk assessment: A risk assessment is a high-level analysis of the security risks faced by the organization.
Vulnerability testing: Vulnerability testing involves attempts to crack the network, looking for weak points in the security implementation.
Examination of known vulnerabilities: This differs from vulnerability testing in that, rather than attempting to crack security, it checks the network for software and hardware vulnerabilities that have been reported to vendors. For example, this activity determines whether vendor patches have been applied to vulnerable software.
Policy verification: policy verification involves the comparison of procedures with what is specified in an organization s security policy.
Just as you must consider security from both the inside and outside of an organization, a security audit must also examine external security (protection from attacks) and internal security (adherence to internal security policy by employees and any others with data access).
Who should perform an audit? Generally, the term audit implies an outside firm. Considering that it s quite difficult to perform an unbiased assessment of compliance to policies that you ve developed yourself, you will probably want to hire an outside firm to perform the audit. This also will give the audit more credibility than if you had performed it yourself.
Assuming that you hire...