Network Security Evaluation Using the NSA IEM

If you have been involved in conducting any type of technical assessment or evaluation in the past, you know that such processes can often produce a large amount of data that can take a significant amount of time to organize, analyze, and correlate. You must be able to analyze the data in an efficient amount of time but still be able to provide an accurate and high-quality final report to the customer. Organizing the data collected during the evaluation is a critical component of the post-evaluation phase of the IEM.
The variety of tools used during the evaluation produce raw data in diverse formats. You must be able to organize the evaluation data in ways that make sense to you or are meaningful to the person who will analyze the data so that it can be turned into usable information. The final deliverable is dependent on how you break down the complex raw data collected during the onsite activities into its most basic elements and relationships, then how you are able analyze the data, through the process of categorizing, consolidating, correlating, and consulting, to develop practical and effective solutions for the customer. This chapter walks you through this process.
At this point, we need to discuss what to do with the data that has been collected. Throughout the onsite evaluation process, the...