Talk With an Expert

Auditing-In-Depth For Solaris

Auditing-In-Depth For Solaris (PDF, 2.44MB)Published: 31 Oct, 2003
Created by:
Jeff Pike

Auditing-in-depth is a concept that will be reinforced throughout this paper; it is the logical extension of 'defense-in-depth' to auditing. Auditing-in-depth is examining the security posture of a system or network from the perspective of possible threat vectors. Too often organizations rely solely on the output of a single network-based vulnerability-scanning tool to audit their security posture. These scans can only address network based vectors. Relying solely on network-based scans can give organizations an incomplete view of their security posture. It also can give security analysts a reputation as 'the guys who just show up and run scans.' For all threat vectors to be addressed the target should be examined from both the inside and outside by a combination of manual tests automated tools and policy review.

Auditing-In-Depth For Solaris