Outlining the Pen Testing Methodology

Sean-Philip Oriyano · 2017

This chapter discusses the importance of pen-testing, the type of test required to be performed, the need to get permission and create a contract, and follow the law while testing. The test should ultimately be focused on uncovering and determining the extent of vulnerabilities on the target network. Another choice that will need to be made during this meeting is who will and would not be informed about the test. A penetration test is considered part of a normal IT security risk management process that may be driven by internal or external requirements as the individual situation merits. Once the test process is completed, a report is generated with all the necessary information regarding the target security assessment, categorizing and translating the identified risks into business context. The time and cost required to find and resolve the security vulnerabilities is comparably less than with the black-box approach.

Read the paper · More papers on PaperTik