SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsAuditing-in-depth is a concept that will be reinforced throughout this paper; it is the logical extension of 'defense-in-depth' to auditing. Auditing-in-depth is examining the security posture of a system or network from the perspective of possible threat vectors. Too often organizations rely solely on the output of a single network-based vulnerability-scanning tool to audit their security posture. These scans can only address network based vectors. Relying solely on network-based scans can give organizations an incomplete view of their security posture. It also can give security analysts a reputation as 'the guys who just show up and run scans.' For all threat vectors to be addressed the target should be examined from both the inside and outside by a combination of manual tests automated tools and policy review.