Re: [Full-disclosure] Security Incident Response Testing To Meet Audit

2010-12-13 Thread Line Noise
On Sun, Dec 12, 2010 at 2:47 PM, Jeffrey Walton wrote: > On Sun, Dec 12, 2010 at 12:02 PM, Jeffrey Walton wrote: >> The company was started by a fellow named Al Huger. I believe he also >> started Bugtraq. When Bugtraq was commercialized by Symantec, Huger >> moved on to Immunet. > >From Kurt S

Re: [Full-disclosure] Security Incident Response Testing To Meet Audit

2010-12-12 Thread Jeffrey Walton
On Sun, Dec 12, 2010 at 12:02 PM, Jeffrey Walton wrote: > On Fri, Dec 10, 2010 at 11:52 PM, Charles Polisher wrote: >> Adam Behnke wrote: >>> Hi everyone, InfoSec Institute author Russ McRee has written up an overview >>> on tools to ensure maximum readiness for incident response teams, including

Re: [Full-disclosure] Security Incident Response Testing To Meet Audit

2010-12-12 Thread cpolish
Christian Sciberras wrote: > Just to satisfy my curiosity, but, when was the last AV update performed? > One could assume some anti-virus would be up-to-date even if the last update > was performed a month or so ago. > On the other hand, an anti-virus update usually is done sometimes even > several

Re: [Full-disclosure] Security Incident Response Testing To Meet Audit

2010-12-12 Thread Jeffrey Walton
On Fri, Dec 10, 2010 at 11:52 PM, Charles Polisher wrote: > Adam Behnke wrote: >> Hi everyone, InfoSec Institute author Russ McRee has written up an overview >> on tools to ensure maximum readiness for incident response teams, including >> drill tactics. PCI-DSS audits often require IR testing val

Re: [Full-disclosure] Security Incident Response Testing To Meet Audit

2010-12-12 Thread Christian Sciberras
Just to satisfy my curiosity, but, when was the last AV update performed? One could assume some anti-virus would be up-to-date even if the last update was performed a month or so ago. On the other hand, an anti-virus update usually is done sometimes even several times er day (well, mine does). Hav

Re: [Full-disclosure] Security Incident Response Testing To Meet Audit

2010-12-12 Thread Charles Polisher
Adam Behnke wrote: > Hi everyone, InfoSec Institute author Russ McRee has written up an overview > on tools to ensure maximum readiness for incident response teams, including > drill tactics. PCI-DSS audits often require IR testing validation; drill > quarterly and be ready next audit cycle. > > ht

[Full-disclosure] Security Incident Response Testing To Meet Audit Requirements

2010-12-10 Thread Adam Behnke
Hi everyone, InfoSec Institute author Russ McRee has written up an overview on tools to ensure maximum readiness for incident response teams, including drill tactics. PCI-DSS audits often require IR testing validation; drill quarterly and be ready next audit cycle. http://resources.infosecinst