官术网_书友最值得收藏!

Dealing with third parties

Today, many businesses are utilizing cloud services. There is a high probability that you will encounter cloud servers within your penetration scope. It's important to keep in mind who owns the server. In the case of a cloud environment, the server is not owned by the business that the penetration test is being conducted for, but rather the cloud provider.

Big players in the cloud space, such as Microsoft, Amazon, and Google, all have penetration testing rules-of-engagement documents. These documents detail what you are allowed to do and what you are not allowed to do.

Microsoft defines its rules of engagement here:  https://www.microsoft.com/en-us/msrc/pentest-rules-of-engagement.
Amazon defines its rules of engagement here:   https://aws.amazon.com/security/penetration-testing/ .
Google defines its rules of engagement here:   https://cloud.google.com/security/overview/ .

Make sure that you obtain the correct approvals from the cloud provider if you have any cloud services within your penetration scope; failure to do so might lead to legal consequences.

主站蜘蛛池模板: 阆中市| 出国| 汉阴县| 保山市| 安达市| 桓台县| 陈巴尔虎旗| 繁峙县| 德兴市| 芜湖县| 麻阳| 青冈县| 巴彦县| 抚顺市| 银川市| 电白县| 尼勒克县| 遂宁市| 武胜县| 图片| 囊谦县| 平江县| 盐城市| 兰溪市| 芦溪县| 长岭县| 西吉县| 金溪县| 前郭尔| 耿马| 伊宁市| 杂多县| 宣城市| 蕉岭县| 西青区| 内黄县| 天祝| 东乡县| 江安县| 麟游县| 越西县|