Pete Herzog, founder of ISECOM and creator of the Open Source Security Testing Methodology Manual (OSSTMM) talks with Federico Biancuzzi about the upcoming revision 3.0 of the OSSTMM. I'm Pete Herzog, managing director of ISECOM. I live in a small town in Catalonia just outside of Barcelona. It's also where I work part of the year. The other part of the year I work in the US. ISECOM is a non-profit, registered both here and in New York State, USA, with the aggressive mission to "make security make sense". . The link for this article located at TheRegister.co.uk is no longer available. . Pete Herzog, founder of ISECOM, shares insights on the OSSTMM's evolution, highlighting its role in adapting security practices to modern threats and technology.. OSSTMM, Security Testing, ISECOM, Testing Methodology, Open Source Security. . LinuxSecurity.com Team
The Web Application Firewall Evaluation Criteria project announced its first public release. The goal of the project is to develop a testing methodology that can be used by any reasonably skilled technician to independently assess quality of a web application firewall. . The link for this article located at is no longer available. . We are excited to unveil the inaugural public version of the Web Application Firewall Assessment Standards designed to evaluate the effectiveness of firewall solutions.. Web Application Firewall,Evaluation Criteria,Testing Methodology. . LinuxSecurity.com Team
While hiring security specialists with a staff roll of cleared and sanitised white hats is one avenue, companies also hire individuals and less established groups to test their security. As Kenneth de Spiegeleire, manager of security assessment services at ISS, points out: "Unfortunately, not all service providers respect the same code of conduct or rigorous testing methodology.". . .. While hiring security specialists with a staff roll of cleared and sanitised white hats is one avenue, companies also hire individuals and less established groups to test their security. As Kenneth de Spiegeleire, manager of security assessment services at ISS, points out: "Unfortunately, not all service providers respect the same code of conduct or rigorous testing methodology." Toby Ben, products manager at Access Research, agrees. "I class myself among the white hats," he says. "I've been through the checks required by my employer, a security specialist. "But if you're a company and you want to hire a prospective hacker, it's more difficult. You don't have the resources."However, Ben does see a light at the end of the tunnel. "In the short term, the best way is to go with a recognised penetration team. These teams base their entire existence on being able to do comprehensive evaluations. The link for this article located at vnunet is no longer available. . While hiring security specialists with a staff roll of cleared and sanitised white hats is one avenu. while, hiring, security, specialists, staff, cleared, sanitised, white, avenu. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.