The next phase of building a secure infrastructure is the actual assessment. This is one of the most critical steps of the project. Presented in this chapter is an overall process, a proven method for finding problems and securing the organization's infrastructure. If you keep to the methodology and practice due diligence, you can complete this portion of the assessment successfully.
Introduction to Assessing Network Vulnerabilities
Foundations and Principles of Security
Why Risk Assessment
Risk-Assessment Methodologies
Scoping the Project
Understanding the Attacker
Performing the Assessment
Tools Used for Assessments and Evaluations
Preparing the Final Report
Post-Assessment Activities
Appendix A. Security Assessment Resources
Appendix B. Security Assessment Forms
Appendix C. Security Assessment Sample Report
Appendix D. Dealing with Consultants and Outside Vendors
Appendix E. SIRT Team Report Format Template