In my corporate environment I use ethtereal for packet sniffing, and started with ISO17799 (BS7799 in UK) as the starting point for considering what Security Policies I wanted to initially define. I would look around in the SANS Reading Room and at some of the NIST documents.




Reply With Quote