22nd May 2012

I Believe That There Should Be a Security Design Team and a Security Audit Team. All Security Operations Should Be Performed by Network Operations.

Keith Tokash opens up a topic close to my own heart, and one that I am working on right now. Go there and add comments so that my job is easier :-)

I believe that there should be a Security Design team and a Security Audit team. All security operations should be performed by Network Operations.

The SecAudit team should consists on consulting type people who love writing policies, working with management and reviewing the work that has been delivered matches the plan and design. This includes reviewing Securty Operations (which is most likely delivered by Network Operations). They do not perform hands on work, or any day to day activities.

The SecDes team are used to reference and validate all Security changes against the reference designs derived from Policy. They are Network Engineers with a specialisation in Security and can assess impact on Network Integrity.

Leave comments if you want me to expound more on this topic.

CCIE Candidate – What Roles Do Security Teams Play vs. Infrastructure Teams?: “”

This post is copyright of Thropos Ltd ©2008-2011 at Etherealmind.com - contact | email: greg.ferro@packetpushers.net - twitter: @etherealmind | All rights reserved
About Greg Ferro

Greg Ferro is a Network Engineer/Architect, mostly focussed on Data Centre, Security Infrastructure, and recently Virtualization. He has over 20 years in IT, in wide range of employers working as a freelance consultant including Finance, Service Providers and Online Companies. He is CCIE#6920 and has a few ideas about the world, but not enough to really count.

He is a host on the Packet Pushers Podcast, blogger at EtherealMind.com and on Twitter @etherealmind and Google Plus