Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] [Professional IT Security Reviewers - Exposed] SecReview ( F - ) |
|---|---|
| Date: | Thu, 20 Dec 2007 14:20:36 -0600 |
This rating is based entirely off my personal feelings after reading several of the emails you've sent out to the Full Disclosure list. I bring up the following as my reasoning: 1.) What are your qualifications for reviewing these companies? 2.) Your criteria for review is clearly flawed. Reviewing marketing material, websites, etc. is just ridiculous. Typically these are not created by the security team itself, but instead the marketing department for a company. You only just mentioned that you started reviewing sample reports, and that not all companies are willing to provide these. How could you possibly review a company WITHOUT a sample report at the minimum? 3.) What is your scoring system? Do you even have one? 4.) If company A does not submit themselves for review, and therefore will not provide you with the information you need to review them, do they get a lower score? In any case, a consulting company provides far more then simply a marketing site and sample deliverables. Unless you can survey a companies customers, I don't see how you could ever make a reasonably accurate assumption. Therefore, I rate SecReview as an F-.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] IBM Domino Web Access Upload Control dwa7w.dll Memory Corruption, Elazar Broad |
|---|---|
| Next by Date: | Re: Design flaw in AS3 socket handling allows port probing, fukami |
| Previous by Thread: | [Full-disclosure] IBM Domino Web Access Upload Control dwa7w.dll Memory Corruption, Elazar Broad |
| Next by Thread: | Re: [Full-disclosure] [Professional IT Security Reviewers - Exposed] SecReview ( F - ), Mike Vasquez |
| Indexes: | [Date] [Thread] [Top] [All Lists] |