This document provides guidance on conducting a DIY security assessment through summarizing background information on security life cycles and describing two assessment tools: ISS Internet Scanner and Nessus. It explains that assessments are an important part of the security life cycle. The security life cycle includes policies, assessment, design, deployment, management, and continual training. Assessments evaluate technical and non-technical areas to determine an organization's security posture. The document then gives examples of what to check during assessments and provides basic instructions for using ISS Scanner and Nessus to perform technical vulnerability assessments.