Hey, I also tweet and blog. Contact Me|Research

Information Security Assessments

In these articles, I've summarized my advice on security assessment practices.

Tips for Creating an Information Security Assessment Report Cheat Sheet

This cheat sheet presents recommendations for creating a strong report as part of an information security assessment project.

Security Architecture Cheat Sheet

This 2-page cheat sheet offers tips for reviewing security architecture of complex Internet applications.

5 Security Assessment Steps for Mid-Sized Firms

Budget, time and staff limitations require companies to be selective about information security spending. This article presents key steps that outline what to look for.

Testing for Client-Side Vulnerabilities

This article describes how to test for client-side vulnerabilities during a security assessment.

Social Engineering During Security Assessments

This article explains how to incorporate social engineering into information security assessments.

Security Assessment Tips: Where the Risks Are

This article describes the various types of information security assessments, and offers tips for deciding which assessment is right for your situation.

Information Security Assessment RFP Cheat Sheet

This cheat sheet offers tips for planning, issuing and reviewing Request for Proposal (RFP) documents for information security assessments.