Re: Review of the Radio Plus debate themed "Cybercriminalité: sommes-nous bien armés ?"

From: S Moonesamy <sm+mu_at_elandsys.com>
Date: Sun, 31 Jan 2016 13:25:55 -0800

Hi Mike,
At 12:22 31-01-2016, Jules Mike Giovanni wrote:
>Thank you for your response! Does it ever happen that you have to
>provide the same report with a different technical level or
>attention to details (e.g one for the management needs and
>understanding and another for any technical department) ?

My report usually goes to management. It may include a technical
section about the problem which was identified if that is
needed. The technical details depend on the technical level of the
technical department; it might be the technical department of another
company. Basically, as you interact with the technical people you
can determine which information to provide. If you are doing a
security-related report, it is better to have all the relevant
details included.

>Do you mean ISO standards like ISO 27001 and ISO 27002 ? Sorry if it
>might be silly, but what are some alternatives of the ISO standards
>for security in that regards and are they as effective as their counterparts?

Yes. The alternatives depends on the country and the standards the
organisation has chosen to comply with. I might refer to a RFC for
the technical part and documented practices from, for example, the
U.S. if the documents have been widely reviewed. Security is not
about blindly complying with some standard.

>I started recently to read through the various technical
>specifications myself. I don't feel at ease that much when the
>subject come up. Even how much I have been using the internet as a
>non-regular user, I'm still in the process of getting acquainted to
>some of the specs of it. That's why I proposed the "verbal"
>discussion first to ensure that I don't spill out wrong information
>that might misguide some of the readers here.

It can take some time to get used to the subject. I would not worry
about spilling incorrect information on here. It is misguided if a
person to blindly uses the information without verifying that it is correct.

Regards,
S. Moonesamy
Received on Sun Jan 31 2016 - 21:28:17 PST

This archive was generated by hypermail 2.3.0 : Sun Jan 31 2016 - 21:36:04 PST