Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests and 3 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Career Centralarrow Security Consulting Services - What are the services we can offer?
Ethical Hacker Community Forums
December 04, 2008, 01:29:03 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Security Consulting Services - What are the services we can offer?  (Read 4152 times)
0 Members and 1 Guest are viewing this topic.
Manu Zacharia (-M-)
Full Member
***
Offline Offline

Posts: 195



View Profile WWW
« on: February 20, 2007, 08:50:03 AM »

Hi Fellow Ethical Hackers,

After attaining some certifications and courses on Info Sec, I was asked by my boss about starting a security consulting division for our firm. So, the purpose of this post is to discuss the various services that a security consulting can offer like, pen testing, security awareness training etc. I would like request the security professionals of this web portal to guide us on this matter.

Also, is there any legal aspect that needs to be taken care before getting into security consulting?

Any guidance on preparing a Business Plan for the same would be of great help.

Regards and best wishes,

The Morpheus
Logged

Manu Zacharia
Certified ISO 27001:2005 (Information Security Management System) Lead Auditor
Promote the Information Security Day
Visit - http://www.informationsecurityday.com
Kev
Guest
« Reply #1 on: February 20, 2007, 10:30:02 AM »

Congratulations, it can be hard sometime to convince others on the need for security. It can be a little scary for some companies because they feel like they are exposing themselves to an outsider. If you can get beyond that ,then you are ahead. Yes, there are legal things to consider and its important to protect yourself.  Have a very clear document that covers yourself not just on any vulnerability you reveal, but also on any hardware that might go bad during your pen test. Its weird but if any computers  fail while you are doing your pen test, they will try and hold you responsible.
Logged
boney
Jr. Member
**
Offline Offline

Posts: 61



View Profile
« Reply #2 on: February 20, 2007, 11:06:08 AM »

Well you can also get into writing policies for the companies.
Policies like Network Security Policy, Physical Security Policy, Email policy, Storage Policy, Disaster Recovery Policy, Backup Policy and things like these.
If you want any help regarding how to create these Policies, let me know, as I have some specimen of these policies. Maybbe it helps !

And above all, as Kev states, consider all the legal issues and be armed with the proper tools and techniques while doing the pen tests.

Prepare some slides as to give a picture of your cunsulting service which includes the things you'll do for the company. Inform te clients that you'll be sending the audits on regular basis ( or whatever time interval you have decided) with rigorous analysis.

All the best !
Logged

C|EH

All my life I wanted a computer...
Now I want my life back !
Manu Zacharia (-M-)
Full Member
***
Offline Offline

Posts: 195



View Profile WWW
« Reply #3 on: February 20, 2007, 11:45:21 AM »

Thanks for the guidance Kev and Boney.  Smiley

Boney - Can I have the specimen copies. I have send a Personal Message to you containing my email ID's.

Thanks in advance
Logged

Manu Zacharia
Certified ISO 27001:2005 (Information Security Management System) Lead Auditor
Promote the Information Security Day
Visit - http://www.informationsecurityday.com
Cutaway
Jr. Member
**
Offline Offline

Posts: 96


Cutaway


View Profile WWW
« Reply #4 on: February 21, 2007, 11:16:44 PM »

Here is a great resource for Policies http://www.dir.state.tx.us/security/policies/templates.htm

Although these are developed to help the State of Texas Agencies and Universities spin up a security program they are generic enough to use anywhere.

Good Luck,
Cutaway
Logged

Go forth and do good things,
Cutaway
BillV
Hero Member
*****
Offline Offline

Posts: 870


View Profile
« Reply #5 on: February 22, 2007, 07:23:17 AM »

Another good policy link: SANS Security Policies
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.048 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.