Analysis and recommendations for standardisation in penetration testing and vulnerability assessment:penetration testing market survey

William B. Knowles, Alistair Baron, Tim McGarr · Lancaster EPrints (Lancaster University) · 2015

1. Standardization of terminology for the different levels of simulated security evaluations.This would enable clients to understand the service they are purchasing, and enable the provider to compete based on the quality of that service. 2.Guidelines for reporting structure and content.Stakeholders felt providers should supply greater consistency and depth in their use of metrics and recommendations (e.g.analysing root causes, rather than offering spot fixes), while also empowering clients to understand the security threats facing their environments (e.g. through attack narratives). 3.Guidelines for the use of penetration testing as audit evidence, notably within an ISO/IEC 27001 audit.The current implementation within ISO/IEC 27001 isolates penetration testing as a single control, negating its potential for assessing other security controls within the standard.

Read the paper · More papers on PaperTik