Search in ISMS Guides

Google
 
Showing posts with label Software and Tools. Show all posts
Showing posts with label Software and Tools. Show all posts

Thursday, August 16, 2007

What is PTA ?

Software technology and tools for performing Practical Threat Analysis

PTA (Practical Threat Analysis) is a software technology and a suite of tools that enable users to find the most beneficial and cost-effective way to secure computerized systems and applications according to their specific functionality and environment.

How does it work?

The threat analysis process begins by describing the specific threats and vulnerabilities of the system. The threats are then associated with assets that might be damaged. The process continues by finding the exact countermeasures that will fit different threats. The risk level, potential damage and countermeasures required are all presented in real $ values. PTA automatically calculates the level of risk and the maximum available mitigation and advises on the most cost effective way to mitigate threats and reduce overall system risk.

Who should use PTA?

PTA was designed to assist the work of security consultants, software security engineers and information security officers.

When should Practical Threat Analysis be done?

The best time to use PTA is during system design phase. Potential losses and security countermeasures may be defined at the start and prevent future problems. For systems already in operation, PTA can identify areas of corrective actions. Since threats, vulnerabilities and countermeasures vary throughout a system’s life cycle, threat analysis should be a continuous task.

What are the common problems arising during system threat analysis?

  1. Analyzing only a particular ‘environment’, for example networking, makes it difficult to thoroughly explore threats. This is especially true in complex applications with many interfaces.
  2. Analyzing a system only once during it's life cycle.
  3. There is no quantitative valuation of the severity of threats in real $ value.
  4. The outcome of the analysis does not include clear recommendations on the most efficient and cost-effective countermeasures required.
  5. Threat analysis models are not dynamic; changes in any parameter of the model will not be immediately reflected in the countermeasures recommended.

Quickly build threat models, analyze risks and manage risk mitigation policies

Using PTA, analysts can quickly build threat models, analyze risks and manage risk mitigation policies relevant to the application's domain. Inputs may be obtained from a variety of external sources e.g. vulnerability scanners, real-time network analyzers, security event repositories and security standards databases. The information can be entered manually as well as automatically.

PTA will save you time and money. In addition to recommending the most cost effective countermeasures, PTA presents the current level of security of the monitored system. Once used, PTA enables dynamic changes in each of the defined threats, vulnerabilities, assets and countermeasures parameters. This allows an effective and continuous security management, throughout the application's life cycle without duplicating efforts and at minimal cost.

Threat Analysis Methodology in-depth - Calculative Threat Analysis Software Tools
Home Page

Practical Threat Analysis of Complex Software

Abstract

This paper describes Practical Threat Analysis(PTA); a structured methodology implemented in a Windows application freeware that helps analysts and developers to assess system risks and build an most effective risk reduction program for their complex software system.

Software appears simple but imbued with power to the casual observer. For the programmers, the code becomes obscure when viewed later and tests of correctness can be quite difficult to perform. With the steep rise in reported data breaches in recent years it is becoming apparent that basic software flaws are at the root of system vulnerabilities that enabled exploitation by hackers and trusted insiders.

PTA helps the security, application development and deployment teams identify and prioritize remediation of flaws in a cost-effective manner.


Read More

Wednesday, August 8, 2007

THE ISO 27000 TOOLKIT

As the international standards for information security, ISO 27001 and ISO 27002 (also known as ISO 17799) are, by their very nature, highly complex. But whether you wish to pursue certification, achieve compliance, or simply position your organization against them, the first question usually is: where do you start?

THE ISO27000 TOOLKIT

The answer to this question surely is The ISO27000 Toolkit. This is a series of materials and documents brought together specifically to help you achieve these objectives, and support both ISO27001 and ISO27002 (ISO17799).

It comprises the following essential components:

Both parts of the standard: ISO 27002 (formerly ISO 17799) and ISO 27001

A management presentation

A complete set of ISO 27002 compliant information security policies

A Business Continuity Kit (Ref: section 12)

A jargon busting glossary of information security and IT terms

A BIA questionnaire

The certification roadmap

The essential audit kit (Ref: section 12) for a network system

THE ESSENTIAL STARTER KIT

The ISO 27000 Toolkit will get you off to an excellent start in understanding the two ISO 27000 standards, and addressing the key issues. Further, the support resources and materials included in the kit should prove to be useful for many years to come.

All the items in the kit have been designed and created from the standpoint of helping with the ISO 27001 and ISO 27002 compliance initiative. Indeed, their quality is such, that some are sold stand alone, as independent security products. However, purchase within the toolkit delivers significant and substantial savings.

Each item within the toolkit is described more fully on its own page. To view, simply select from the menu on the left hand side. For more information, please feel free to contact us

PURCHASE & DOWNLOAD

To purchase the product and download the full toolkit for a special price of just $995, please visit our secure ISO27000 purchase page.

Monday, August 6, 2007

ISO 17799 SOFTWARE

We are sometimes asked about the role of software/products with respect to ISO17799, particularly the two most well known offerings, COBRA and The ISO17799 Toolkit. Where do they fit in? Are they competitor products or do they compliment each other? How do they help?

The truth is that they fulfill completely different needs:

B) COBRA is designed to help you manage that compliance. It takes you through the standard and ultimately measures your compliance level, pointing out where you fall short. Quite apart from this it is one of the most widely used (possibly THE most widely used) risk analysis systems in the world... and bear in mind that risk analysis is integral to the requirements of the standard... references to 'as determined by risk assessment' are almost interwoven.

In essence therefore, one product gets you started, the other helps you manage.

A) The ISO17799 Toolkit on the other hand comprises the basic building blocks: the standard itself (both parts), 17799 cross referenced security policies, and so on. It is intended to 'get you going' on the right path straight away, by providing some basics, as well as guidance and explanations by way of a presentations, glossary, roadmap, etc. It can basically be seen as an introduction and starting pack for compliance with the standard.


From : 17799-news.the-hamster.com