<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Advancements at the Monastery &#187; SCORE</title>
	<atom:link href="http://blog.securitymonks.com/category/score/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.securitymonks.com</link>
	<description>Information about developments at the Monastery</description>
	<lastBuildDate>Fri, 03 Sep 2010 05:41:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>A Little Light Reading</title>
		<link>http://blog.securitymonks.com/2007/01/20/a-little-light-reading/</link>
		<comments>http://blog.securitymonks.com/2007/01/20/a-little-light-reading/#comments</comments>
		<pubDate>Sun, 21 Jan 2007 05:54:28 +0000</pubDate>
		<dc:creator>John Gerber</dc:creator>
				<category><![CDATA[CIS]]></category>
		<category><![CDATA[COBIT]]></category>
		<category><![CDATA[ISACA]]></category>
		<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[SCORE]]></category>
		<category><![CDATA[Web Application]]></category>

		<guid isPermaLink="false">http://blog.securitymonks.com/?p=17</guid>
		<description><![CDATA[


With the holidays and studying for the GSNA certification, I have fallen behind in my reading.  I spent Friday evening printing out documents.

From the National Institute of Standards and Technology:

Guide to Integrating Forensic Techniques into Incident Response
Guide to Secure Web Services (DRAFT)
Guide to Intrusion Detection and Prevention (IDP) Systems (DRAFT)
Guide for Developing Performance Metrics [...]]]></description>
			<content:encoded><![CDATA[<table>
<tr>
<td><a title="Bookworm" href="http://www.answers.com/topic/carl-spitzweg"><img width="126" height="238" align="left" alt="Bookwarm" title="Bookworm" src="/images/Carl_Spitzweg_021.jpg" /></a></td>
<td>With the holidays and studying for the GSNA certification, I have fallen behind in my reading.  I spent Friday evening printing out documents.</p>
<p>
From the <a title="NIST" href="http://csrc.nist.gov/publications/nistpubs/">National Institute of Standards and Technology</a>:</p>
<ul>
<li><a title="Integrating Forensic Techniques into Incident Response" href="http://csrc.nist.gov/publications/nistpubs/800-86/SP800-86.pdf">Guide to Integrating Forensic Techniques into Incident Response</a></li>
<li><a title="Guide to Secure Web Services" href="http://csrc.nist.gov/publications/drafts.html#sp800-95">Guide to Secure Web Services (DRAFT)</a></li>
<li><a title="IDP Systems" href="http://csrc.nist.gov/publications/drafts.html#sp800-94">Guide to Intrusion Detection and Prevention (IDP) Systems (DRAFT)</a></li>
<li><a title="Performance Metrics" href="http://csrc.nist.gov/publications/drafts.html#sp800-80">Guide for Developing Performance Metrics for Information Security</a></li>
<li><a title="800-53" href="http://csrc.nist.gov/publications/nistpubs/800-53-Rev1/800-53-rev1-final-clean-sz.pdf">Recommended Security Controls for Federal Information Systems</a></li>
</ul>
</td>
</tr>
</table>
<p>From <a title="ISACA" href="http://www.isaca.org/">ISACA</a>:</p>
<ul>
<li><a title="COBIT and ITIL" href="http://www.isaca.org/Template.cfm?Section=COBIT_Mapping1&#038;Template=/MembersOnly.cfm&#038;ContentFileID=12791">COBIT Mapping: Mapping of ITIL with COBIT 4.0</a></li>
<li><a title="COBIT and PRINCE2" href="http://www.isaca.org/Template.cfm?Section=COBIT_Mapping1&#038;Template=/MembersOnly.cfm&#038;ContentFileID=12792">COBIT Mapping: Mapping of PRINCE2 with COBIT 4.0</a></li>
<li><a title="COBIT and ISO/IEC 17799:2005" href="http://www.isaca.org/Template.cfm?Section=COBIT_Mapping1&#038;Template=/MembersOnly.cfm&#038;ContentFileID=12717">COBIT Mapping: Mapping of ISO/IEC 17799:2005 With COBIT 4.0</a></li>
<li><a title="Sarbanes-Oxley" href="http://www.isaca.org/Template.cfm?Section=home&#038;CONTENTID=27507&#038;TEMPLATE=/ContentManagement/ContentDisplay.cfm">IT Control Objectives for Sarbanes-Oxley</a></li>
</ul>
<p>Concerning Securing Mac OS X:</p>
<ul>
<li><a title="A Corsaire White Paper" href="http://www.corsaire.com/white-papers/050819-securing-mac-os-x-tiger.pdf">A Corsaire White Paper: Securing Mac OS X</a></li>
<li><a title="Apple Mac OS X Security Configuration" href="http://images.apple.com/server/pdfs/Tiger_Server_Security_Config.pdf">Mac OS X Server Security Configuration for Version 10.4 or Later</a></li>
<li><a title="CIS Mac OS X" href="http://www.cisecurity.org/bench_osx.htm">CIS Mac OS X Tiger Level I Security Benchmark</a></li>
<li><a title="NSA Mac OS X Security Config" href="http://www.nsa.gov/snac/downloads_macX.cfm">NSA Apple Mac OS X v10.3.x &#8220;Panther&#8221; Security Configuration Guide</a></li>
<li><a title="SANS SCORE" href="http://www.sans.org/score/macosxchecklist.php?portal=28353a7aad9bb868c7793bcb1b46d1d5">SANS SCORE: Mac OS X Checklist 1.0</a></li>
<li><a title="SANS CIS Benchmark Tool" href="http://www.cisecurity.org/bench_osx.htm">SANS CIS Benchmark Tool</a></li>
<li><a title="Bastille Mac OS X" href="http://sourceforge.net/project/showfiles.php?group_id=403">Bastille Linux Mac OS X Beta</a></li>
<li><a title="DISA Mac OS X" href="http://iase.disa.mil/stigs/stig/mac-stig-v1r1.pdf">DISA Mac OS X Security Technical Implementation Guide</a></li>
</ul>
<p>Concerning Web Application Security:</p>
<ul>
<li><a title="OWASP Testing Guide" href="http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_RC1_pdf.zip">OWASP Testing Guide 2007 V2</a></li>
<li><a title="Web Applications" href="http://owasp.cvs.sourceforge.net/*checkout*/owasp/guide/current%20draft.pdf">A Guide to Building Secure Web Applications and Web Services<br />
</a></li>
</ul>
<p>Just for Fun:</p>
<ul>
<li><a title="The Pragmatic CSO" href="http://securityincite.com/security-incite-rants/pragmatic-cso">The Pragmatic CSO</a></li>
<li><a title="Optaros" href="http://www.optaros.com/en/publications/white_papers_reports/open_source_catalogue_2007">Optaros: Open Source Catalogue 2007 U.S. Version 1.1</a></li>
</ul>
<p>It sure would be nice to retreat to a monastery and spend a few days just reading this material.  A quote from <a href="http://www.answers.com/topic/doug-larson">Doug Larson</a> sums it up nicely, <a href="http://www.whatquote.com/quotes/Doug-Larson/2559-For-disappearing-act.htm">&#8220;For disappearing acts, it&#8217;s hard to beat what happens to the eight hours supposedly left after eight of sleep and eight of work.&#8221; </a> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.securitymonks.com/2007/01/20/a-little-light-reading/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

