Given the upcoming public release of ISECOM‘s
Open Source Security Testing Methodology Manual (OSSTMM)
version 3, I took the opportunity to have a closer look at it. While we at ERNW
never adopted the OSSTMM for our own way of performing security assessments
(mostly due to the fact that performing assessments is our main business since
2001 and our approach has been developed and constantly honed since then so that
we’re simply used to doing it “our way”) I’ve followed parts of ISECOM’s work
quite closely as some of the brightest minds in the security space are
contributing to it and they come up with innovative ideas regularly.
So I was eager to get an early copy of it to spend some weekend time going
through it (where I live we have about 40 cm of snow currently so there’s
“plenty of occasions for a cosy reading session” ;-))
One can read the OSSTMM (at least) two ways: as a manual for performing security
testing or as a “whole philosophy of approaching [information] security”. I
did the latter and will comment on it in a two-part post, covering the things I
liked first and taking a more critical perspective on some portions in the
second. Here we go with the first, in an unordered manner:
ISECOM
Our Favorite Subject: [It’s all about] Risk
Some days ago my old friend Pete Herzog from ISECOM
posted a blog entry titled “Hackers May Be Giants with Sharp Teeth”
here
which – along with some quite insightful reflections on the way kids perceive
“bad people” – contains his usual rant on (the uselessness of) risk
assessment.
Given that this debate (whether taking a risk-based infosec approach is a wise
thing or not) is a constant element of our – Pete’s and mine – long lasting
relationship I somehow feel enticed to respond 😉