Site Maintenance Sunday, July 20, 9:00 AM - 12:00 (noon) EDT / 1300 - 1600 UTC/GMT. Expect intermittent outages.
the most trusted source for computer security training, certification and research


SANS InfoSec Reading Room - Auditing & Assessment

<<Reading Room Home
Most of the computer security white papers in the Reading Room have been written by students seeking GIAC certification to fulfill part of their certification requirements and are provided by SANS as a resource to benefit the security community at large. SANS attempts to ensure the accuracy of information, but papers are published "as is". Errors or inconsistencies may exist or may be introduced over time as material becomes dated. If you suspect a serious error, please contact webmaster@sans.org.

Core_1

Featuring 57 papers as of Jul 20, 2008

Achieving PCI Compliance with Log Management
SenSage - July 2008

Closing Internal User Visibility and Data Governance Gaps with PacketMotion
PacketMotion - April 2008

Auditing Nokia Firewall
Richard Sokal
June 18, 2008
- download paper PDF
Creating a Comprehensive Vulnerability Assessment Program for a Large Company Using QualysGuard
Tim Proffitt
March 31, 2008
- download paper PDF
Auditing a Corporate Log Server
Roger Meyer
February 1, 2008
- download paper PDF
WiFi with BackTrack
Antonio Merola
December 24, 2007
- download paper PDF
NSS Vs NDS
Robert Edwards
November 5, 2007
- download paper PDF
Certification and Accreditation: A madmans dilemma - Costs
Robert Edwards
November 5, 2007
- download paper PDF
Certification and Accreditation: A madmans dilemma - Controls
Robert Edwards
November 5, 2007
- download paper PDF
Certification and Accreditation for Dummies
Robert Edwards
November 5, 2007
- download paper PDF
Certification and Accreditation (C&A) Vs System Development Life Cycle Management (SDLC)
Robert Edwards
November 5, 2007
- download paper PDF
A Taxonomy of Information Systems Audits, Assessments and Reviews
Craig Wright
June 20, 2007
- download paper PDF
VPNScan: Extending the Audit and Compliance Perimeter
Rob VandenBrink
February 12, 2007
- download paper PDF
A Guide to Security Metrics
Shirley C. Payne
January 18, 2007
- download paper PDF
An Introduction to Information System Risk Management
Steve Elky
January 18, 2007
- download paper PDF
Aligning an information risk management approach to BS 7799-3:2005
Ken Biery
November 13, 2006
- download paper PDF
A Practical Guide to Auditing an ASP
Johanna Ollinger
May 17, 2005
- download paper PDF
Sarbanes-Oxley Information Technology Compliance Audit
Dan Seider
May 17, 2005
- download paper PDF
B.A.S.E – A Security Assessment Methodology
Gregory Braunton
May 5, 2005
- download paper PDF
Information Systems Security Architecture: A Novel Approach to Layered Protection
George Farah
January 22, 2005
- download paper PDF
The Application Audit Process - A Guide for Information Security Professionals
Robert Hein
January 22, 2005
- download paper PDF
Information Systems Security Architecture A Novel Approach to Layered Protection
George Farah
January 19, 2005
- download paper PDF
Using Vulnerability Assessment Tools To Develop an OCTAVE Risk Profile
Andrew Storms
March 25, 2004
- download paper PDF
Red Teaming: The Art of Ethical Hacking
Christopher Peake
December 13, 2003
- download paper PDF
Application Security, Information Assurance's Neglected Stepchild - A Blueprint for Risk Assessment
Ted Mina
October 31, 2003
- download paper PDF
Information System Security Evaluation Team: Security Insurance?
Bruce Swartz
October 31, 2003
- download paper PDF
The Art of Reconnaissance - Simple Techniques
Sai Bhamidipati
October 31, 2003
- download paper PDF
Footprint Your Intranet
Bob Brown
October 31, 2003
- download paper PDF
Footprinting: What Is It, Who Should Do It, and Why?
James P. McGreevy
October 31, 2003
- download paper PDF
A Perspective on Threats in the Risk Analysis Process
Arthur Nichols
October 31, 2003
- download paper PDF
System Identification for Vulnerability Assessment
Michael C. Harris
October 31, 2003
- download paper PDF
Conducting a Penetration Test on an Organization
ChanTuck Wai
October 31, 2003
- download paper PDF
Port Scanning Techniques and the Defense Against Them
Roger Christopher
October 31, 2003
- download paper PDF
Distributed Scan Model for Enterprise-Wide Network Vulnerability Assessment
Alexander Lopyrev
October 31, 2003
- download paper PDF
Auditing Inside the Enterprise via Port Scanning & Related Tools
Bob Konigsberg
October 31, 2003
- download paper PDF
An Overview of Threat and Risk Assessment
James Bayne
October 31, 2003
- download paper PDF
Seeking Security: The New Paradigm for Government Agencies
Stephan H. Chapman
October 31, 2003
- download paper PDF
Proactive Vulnerability Assessments with Nessus
Jason Mitchell
October 31, 2003
- download paper PDF
Evaluating Untrusted Software In a Controlled Environment
Jeff Reava
October 31, 2003
- download paper PDF
How-To Make Linux System Auditing a Little Easier
Paul J. Santos
October 31, 2003
- download paper PDF
A Qualitative Risk Analysis and Management Tool - CRAMM
Zeki Yazar
October 31, 2003
- download paper PDF
Case Study - TruSecure Security Certification
David Vos
October 31, 2003
- download paper PDF
Information Classification - Who, Why and How
Sue Fowler
October 31, 2003
- download paper PDF
Quantitative Risk Analysis Step-By-Step
Ding Tan
October 31, 2003
- download paper PDF
Security Assessment Guidelines for Financial Institutions
Karen Nelson
October 31, 2003
- download paper PDF
Application Of The Nsa Infosec Assessment Methodology
Kathryn Cross
October 31, 2003
- download paper PDF
Conducting an electronic information risk assessment for Gramm-Leach-Bliley Act compliance.
Kevin Bong
October 31, 2003
- download paper PDF
Security Program Management and Risk
Archie Andrews
October 31, 2003
- download paper PDF
Strategies for Improving Vulnerability Assessment Effectiveness in Large Organizations
Robert Huber
October 31, 2003
- download paper PDF
The Institutional Need for Comprehensive Auditing Strategies
Steward Milus
October 31, 2003
- download paper PDF
Security Auditing: A Continuous Process
Pam Page
October 31, 2003
- download paper PDF
Network- and Host-Based Vulnerability Assessments: An Introduction to a Cost Effective and Easy to Use Strategy.
Ragi Guirguis
October 31, 2003
- download paper PDF
Data-Centric Quantitative Computer Security Risk Assessment
Brett Berger
October 31, 2003
- download paper PDF
Wireless Network Audits using Open Source tools
Edouard Lafargue
October 31, 2003
- download paper PDF
Auditing-In-Depth For Solaris
Jeff Pike
October 31, 2003
- download paper PDF
Conducting a Security Audit of an Oracle Database
Egil Andresen
March 8, 2002
- download paper PDF
Defining a Risk Assessment Process for Federal Security Personnel
Kathleen Federico
January 26, 2002
- download paper PDF

Contact us: (301) 654-SANS(7267)
Monday - Friday 9am-8pm EST/EDT