RE: Certification for Win2k Web Servers
SANS has a site auditing and certification program called S.C.O.R.E.
(Security Consensus Operational Readiness Evaluation), in collaboration with
Center for Internet Security (CIS). It's a site certification, and has 3
levels, and a bunch of criteria to meet (such as certified personnel,
certified software etc.)
More info at: http://www.sans.org/SCORE/
Rajesh Sampath
> -----Original Message-----
> From: Matt Hodge [mailto:security@hodgefamily.org]
> Sent: Friday, November 01, 2002 2:44 PM
> To: focus-ms@securityfocus.com
> Subject: Certification for Win2k Web Servers
>
>
>
>
> I work at a company that offers web services to industries
> that are fairly
> paranoid about security. With each customer we encounter they seem to
> wince at hosting their data through our servers instead of hosting it
> themselves. So we are repeatedly going through security
> audits of various
> types. My question is this, are there any standards or
> companies that can
> do an audit on a regular basis, who has enough standing in
> the community
> that other companies will take their audit instead of doing
> their own? We
> have already hired independent companies to do audits and we
> always turn
> out fine but from a sales point of view it is becoming a
> major hurdle to
> have to jump over each time. Thanks
>
>
Received on Fri Nov 8 10:33:05 2002
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:24 EDT
|