Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Business justification for pentesting |
|---|---|
| Date: | Tue, 30 Aug 2005 12:22:50 -0700 |
Gartner is the major provider of information regarding this type of stuff. If you aren't able to get access it's a crap shoot on the web. It is true that recovering from an incident costs more than preventing it. To get Pen-testing approved I generally use the fire sprinkler system analogy. We've invested this money in our security now we use pen testing to validate we have achieved what we invested our money for. Or just because you install a sprinkler system doesn't mean you don't test it once a year. Simply because the cost of not having it exceeds the cost of testing and the same is true for pen testing. --Will -----Original Message----- From: sectraq@gmail.com [mailto:sectraq@gmail.com] Sent: Tuesday, August 30, 2005 9:30 AM To: pen-test@securityfocus.com Subject: Business justification for pentesting hi all, a few classic question that i would appriciate any answers for. 1- i would like to briefly know how to quantify information assets. In other words, i hear a pentester say: if a hacker breaks in ur network, u will loose up to 40000$ for example. how can he come up with such figures? 2- are there any other means to justify pentesting for management except for $$$? 3- are there any official statistics, figures etc. for justifying pentesting. ther more official it is the better. 4- any other information you guys might find helpful in justifying a pentest would be appriciated. thnx in advance for ur help. T.N
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | P2P Tools and Shared Directory Tools, nightstorm |
|---|---|
| Next by Date: | RE: Where are Windows "Enforce password history" passwords stored?, Wil.Allsopp |
| Previous by Thread: | Re: Business justification for pentesting, rmeijer |
| Next by Thread: | Re: Business justification for pentesting, Kevin Reiter |
| Indexes: | [Date] [Thread] [Top] [All Lists] |