Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Re: Why Penetration Test? |
|---|---|
| Date: | 13 Jun 2005 11:25:24 -0000 |
hi, thanx to everyone for brain-stroming on this point. i asked this question cause i failed to understand why certain clients are bent on penetration testing cause the results totally depend on the skill set of the person/company performing the penetration testing. I am of the opine that the companyx should get a two vulnerability assessments (not penetration testing) done. Scan 1: With its preventive and reactive controls switched off (IPS/IDS/HIPS etc). Results ranked not on technical ranking (most tools/VA companies tabulate on tech rankings) but on business impact ranking. Scan 2: with the preventive and detective controls switched on (IPS/IDS/HIPS etc). Again results ranked on business impact rankings. The second result with test the effectiveness of security controls in place. Based on the two scans, the companyx should go about plugging those vulnerabilities in phased manner: Phase I: Plug those which could be "identified" (not necessarily exploited) inspite of security controls switched on and have high business impact. Phase II: Plug those which could be "identified" (not necessarily exploited) inspite of security controls switched on and have medium or low business impact. Phase III: Plug those which could be "identified" (not necessarily exploited) when security controls were switched off and have high business impact. (To ensure "safety" even when any preventive or detective control fails) Phase IV: Plug those which could be "identified" (not necessarily exploited) when security controls were switched off and have medium or low business impact. (To ensure "safety" even when any preventive or detective control fails) What say ppl. Does this approach make any sense into the chaos? Regards
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Pentesting a SONUS / SIP Network, Luis H. Gomez-Danes Mejia |
|---|---|
| Next by Date: | RE: Why Penetration Test?, vince |
| Previous by Thread: | RE: Why Penetration Test?, Tony Tulio |
| Next by Thread: | Re: Why Penetration Test?, Terry Vernon |
| Indexes: | [Date] [Thread] [Top] [All Lists] |