Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-18-2008, 10:25 AM
MJ
Guest
 
Posts: n/a
Default Best Practices for Security definitions

Just want to get some best practices on the following plus what is the
source of the answer.
1. What is the review frequency of an IT information systems?
2. Best practice for the maximum limit of invalid login.
3. How long will the limit in no. 2 be defined in the system?
4. How long will the session be inactive before it will be terminated?
5. What are the standard auditable events?
6. What is the common practice if there is an system audit failure or
audit storage capacity being reached?
7. How long should an audit log be retain?
8. How often should personnel be train as a refresher for contigency
planning?
9. How often should a contingency plan be tested?
10. How often should a contingency plan be reviewed?
11. What is the generally acceptable up-time of the alternate
processing site if the primary site went down?
12. How about for the telecom services?
13. How often should a complete system back-up be made?
14. How long before an inactive user be inactive in the USERID system
before all access be disabled?
15. How frequent should an incident capability response be tested?
16. How often should an uthorized personnel list be updated?

I can't find any source in the internet for the list above.

Thanks in advance

Reply With Quote
  #2 (permalink)  
Old 03-18-2008, 02:58 PM
Todd H.
Guest
 
Posts: n/a
Default Re: Best Practices for Security definitions

MJ <spectrum_527@yahoo.com> writes:

> Just want to get some best practices on the following plus what is the
> source of the answer.


I've always tried to avoid doing other people's homework for them.

Seems the point of the exercise is to get to find this information on
your own and cite a source because none of them have universally
accepted answers for all situations and all countries (as some
questions require legal input and are industry dependent as well).

> I can't find any source in the internet for the list above.


Nah, actually the problem is that you can find too many opinions.

One place to do some looking is NIST, and focus on the documents that
include "security benchmark" in their title
http://csrc.nist.gov/checklists/repo.../category.html

--
Todd H.
http://www.toddh.net/

Reply With Quote
  #3 (permalink)  
Old 03-19-2008, 05:03 AM
MJ
Guest
 
Posts: n/a
Default Re: Best Practices for Security definitions

Todd,

You are right, i can't seem to find which source should i check. This
is what frustrate my search, that is why i asked the group.

Thanks for your help.

Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Best Practices for secure delivery / transportation of physical media (tapes, CDs, etc.) chrislewis21@gmail.com comp.security.misc 1 04-25-2007 07:49 AM
Symantec definitions 4 April 2006 Luigi Donatello Asero alt.computer.security 21 10-10-2006 11:10 PM
best practices to secure home's network strutsng@gmail.com alt.internet.wireless 31 10-14-2005 10:22 AM
Backup Best Practices: Read This First! Ablang alt.comp.hardware 4 10-06-2005 04:09 PM
Some pretty pictures, and definitions and thoughs. mikeNZ NZ Wireless 2 12-02-2003 07:06 AM


All times are GMT. The time now is 10:13 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45