[VOIPSA Best Practices] Welcome to the VOIPSA Best Practices project... and some weekend reading for you all (if you get this)
Gerald Fehringer (Europe)
Gerald.Fehringer at eu.didata.com
Mon Dec 4 01:01:14 CST 2006
Hi Dan,
first of all, thanks a lot for your sec-voIP initiative !
Just some notes i would like to add...
-as you already mentioned, i would structure the main sections
based on the current deployment architectures (Enterprise (with/without
SBC), SIP Provider, End-to-End etc)
-i wouldn't use to much document references, because to often quick outdated
and the most good papers, are mostly confidential/internal ;-)
(maybe create some legal document repository on your site, based on vendor
?)
0xsec books also mostly mentioned the same best-practices
-what do you think to work together with Pete Herzog (if he is interested)
and
his very cool OSSTMM Project (VoIP-sec is already a part of that) ?
-as volunteer i could offer you Voip-sec tool research & testing, i've also
some contacts for well-known people from the voip-scene, concerning
assessments/audits
-concerning the development process: i really look forward to get this soon
as possible,
because the business/technical needs within this topic, is really urgent
(similar to the
project pete start years ago for pentesting/audits - OSSTMM)
Thanks
Geri
_____
Von: bestpractices-bounces at voipsa.org
[mailto:bestpractices-bounces at voipsa.org] Im Auftrag von dan_york at Mitel.com
Gesendet: Samstag, 2. Dezember 2006 05:37
An: bestpractices at voipsa.org
Betreff: [VOIPSA Best Practices] Welcome to the VOIPSA Best Practices
project... and some weekend reading for you all (if you get this)
.SNIP
What I would be most interested in feedback on over the next week is the
following:
1. Can anyone point to other Best Practices documents that we can add to the
reference page? They need to be publicly available (i.e. not requiring
registration) so that people can see them.
2. What do people think about how we should best structure the document?
(See my notes on the Development Process page.)
3. Do you agree with what I identified as the target audience?
4. I've identified about 10 potential volunteer roles... do you agree with
my thoughts?
5. If so, anyone already willing to step forward and say how they'll
contribute?
6. Any thoughts on the questions I raise at the bottom of the Development
Process page?
.SNIP
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://voipsa.org/pipermail/bestpractices_voipsa.org/attachments/20061204/e9a05805/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3120 bytes
Desc: not available
URL: <http://voipsa.org/pipermail/bestpractices_voipsa.org/attachments/20061204/e9a05805/attachment.bin>
More information about the bestpractices
mailing list