<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cupfighter.net &#187; pdf</title>
	<atom:link href="http://www.cupfighter.net/index.php/tag/pdf/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cupfighter.net</link>
	<description>A blog by Schuberg Philis colleagues</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:27:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Security Assessment Agreement Outsourcing</title>
		<link>http://www.cupfighter.net/index.php/2009/10/security-assessment-agreement-outsourcing/</link>
		<comments>http://www.cupfighter.net/index.php/2009/10/security-assessment-agreement-outsourcing/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 11:55:35 +0000</pubDate>
		<dc:creator>Frank Breedijk</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Agreement]]></category>
		<category><![CDATA[ITsec]]></category>
		<category><![CDATA[Madison Gurkha]]></category>
		<category><![CDATA[Ousourcing]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Schuberg Philis]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security asessment agreement outsourcing]]></category>
		<category><![CDATA[word]]></category>

		<guid isPermaLink="false">http://www.cupfighter.net/?p=627</guid>
		<description><![CDATA[My work as security engineer for Schuberg Philis often requires me to deal with the following situation. A customer of our requires us to facilitate a security assessment or the infrastructure we manage on their behalf. More of often then not, the contractual agreements between assessor and client and client and service provider together with [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.schubergphilis.com"><img class="alignright size-full wp-image-630" title="Schuberg Philis logo" src="http://www.cupfighter.net/wp-content/uploads/2009/10/schuberg-philis-met-wit-ruimte.png" alt="Schuberg Philis logo" width="149" height="39" /></a>My work as security engineer for Schuberg Philis often requires me to deal with the following situation. A customer of our requires us to facilitate a security assessment or the infrastructure we manage on their behalf.</p>
<p><a href="http://www.itsec.nl"><img class="alignright size-full wp-image-628" title="ITSEC logo" src="http://www.cupfighter.net/wp-content/uploads/2009/10/ITSEC.jpg" alt="ITSEC logo" width="72" height="96" /></a>More of often then not, the contractual agreements between assessor and client and client and service provider together with a &#8220;third party waivers&#8221; or similar documents do not cover everything that the three parties want to commonly agree upon. After reviewing quite a number of these documents, I decided to write a template agreement (which can be downloaded below) for exactly this situation. This document is not a replacement for the agreement between the client and the assessor, but as an additional agreement between all three parties.</p>
<p><a title="Madison Gurkha webiste" href="http://www.madison-gurkha.com" target="_blank"><img class="alignright size-full wp-image-629" title="Madison Gurkha logo" src="http://www.cupfighter.net/wp-content/uploads/2009/10/madison-gurkha-logo.png" alt="Madison Gurkha logo" width="103" height="48" />Madison Gurkha</a> and <a title="ITsec website" href="http://www.itsec.nl" target="_blank">ITsec</a> have both reviewed and contributed to this agreement and we will use it in our future dealings.</p>
<p>The agreement  covers the following topics.</p>
<p><span id="more-627"></span>Scope of the assessment:</p>
<ul>
<li> What will be tested?</li>
<li>When will the test take place?</li>
<li>What kind of tests will be conducted?</li>
</ul>
<p>Contractual agreements:</p>
<ul>
<li>Does the assessor have a contract with the client?</li>
<li>Does the client have a contract with the service provider?</li>
</ul>
<p>Legal liability:</p>
<ul>
<li>Do both the client and the service provider waive prosecution of the assessor?</li>
</ul>
<p>Risks:</p>
<ul>
<li>Are all parties aware of and agree to the risks of a security assessment?</li>
</ul>
<p>Practical matters:</p>
<ul>
<li>The client requests the service provider to support the assessment</li>
<li>Who are the points of contact?</li>
<li>Where will the assessment take place?</li>
<li>How will the results be reported?</li>
</ul>
<p>Confidentiality:</p>
<ul>
<li>All parties agree to confidentiality</li>
</ul>
<p>The agreement template is released without any reservations of rights. This means you can use and adapt this agreement as you see fit, but completely at your own risk.</p>
<p>You can download the agreement here:</p>
<ul>
<li><a href="http://www.cupfighter.net/wp-content/uploads/2009/10/Security-Assesment-Agreement-Outsourcing-v1.0.doc">Security Assessment Agreement Outsourcing v1.0 (Word document)</a></li>
<li><a href="http://www.cupfighter.net/wp-content/uploads/2009/10/Security-Assesment-Agreement-Outsourcing-v1.0.pdf">Security Assessment Agreement Outsourcing v1.0 (PDF)</a></li>
</ul>
<p>I would like to thank the following people for their contribution:</p>
<ul>
<li>Madison Gurkha: Hans van de Looy and Arjan de Vet</li>
<li>ITsec: Tjerk Nan and Jan van Ek</li>
<li>Fox-It: Mark Koek</li>
<li>Arron Finnon (aka <a title="Arron Finnon onTwitter" href="http://twitter.com/f1nux" target="_blank">@f1nux</a>)</li>
<li>Colin McLean</li>
<li>Robert Ladyman</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cupfighter.net/index.php/2009/10/security-assessment-agreement-outsourcing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

