The sites listed next are of general security interest. These organizations offer many resources to help build effective security.
Carnegie Mellon CERT
www.cert.org
International Information Systems Security Certification Consortium (ISC2)
www.isc2.org
Infosec security portal
www.infosyssec.com
InfraGard (FBI and business security partnership program)
www.infragard.net
Information Systems Security Association
www.issa.org
National Infrastructure Protection Center
www.nipc.gov
SANS develops and maintains a large collection of research documents about various aspects of information security.
www.sans.org
Introduction to Assessing Network Vulnerabilities
Foundations and Principles of Security
Why Risk Assessment
Risk-Assessment Methodologies
Scoping the Project
Understanding the Attacker
Performing the Assessment
Tools Used for Assessments and Evaluations
Preparing the Final Report
Post-Assessment Activities
Appendix A. Security Assessment Resources
Appendix B. Security Assessment Forms
Appendix C. Security Assessment Sample Report
Appendix D. Dealing with Consultants and Outside Vendors
Appendix E. SIRT Team Report Format Template