May 18, 2007
—
CSO
—
Sample Questions for Finding Information Security Weaknesses
| SUBHYPOTHESES | DIAGNOSTIC QUESTIONS |
| The network perimeter is porous, permitting easy access to any outsider. | - How many sites are connected directly to the core network without intermediate firewalls?
- How many of these sites have deployed unsecured wireless networks?
|
| An outsider can readily obtain access to internal systems because password policies are weak. | |
| Once on the network, attackers can easily obtain administrator credentials. | - How many administrative-level passwords could be compromised in the same time frame?
|
| An intruder finding a hole somewhere in the network could easily jump straight to the core transactional systems. | - How many internal "zones" exist to compartmentalize users, workgroup servers, transactional systems, partner systems, retail stores, and Internet-facing servers?
|
| Workstations are at risk for virus or worm attacks. | - How many missing operating system patches are on each system?
|
| Viruses and worms can spread quickly to large numbers of computers. | - How many network ports are open on each workstation computer?
- How many of these are "risky" ports?
|
| The firms deployments of applications are much riskier than those made by leaders in the field (for example, investment banking). | - Where does each application rank relative to other enterprise applications [we have] stake has examined for other clients?
|
| Application security is weak and relies too heavily on the "out of the box" defaults. | |