官术网_书友最值得收藏!

Penetration Testing Execution Standard

The Penetration Testing Execution Standard consists of seven main sections. They cover everything concerning a penetration test  from the preliminary communication and effort behind a pen test; through the information-gathering and threat-modeling phases where testers are working behind the scenes to get a better understanding of the tested corporation; through vulnerability research, exploitation, and post-exploitation, where the practical security knowledge of the testers come to play and combine with the business intelligence; and finally to reporting, which outlines the entire procedure in a format that the customer can understand.
This version can be considered v1.0 as the core elements of the standard are solidified, and have been field-tested for over a year through the industry. v2.0 is in the making, and will provide more granular work in terms of levels  as in the intensity levels at which each of the elements of a penetration test can be performed. As no pen test is like another, and testing will range from web application or network tests to a full-on red-team black-box engagement, said levels will enable an organization to outline how much complexity they expect their testers to unveil, and enable the tester to step up the intensity in the areas that the organization deems necessary. Some of the initial work on levels can be seen in the intelligence—gathering section.
The following are the main sections defined by the standard as the basis for executing penetration tests:

  • Pre-engagement interactions
  • Intelligence-gathering
  • Threat-modeling
  • Vulnerability analysis
  • Exploitation
  • Post-exploitation
  • Reporting
主站蜘蛛池模板: 白城市| 武夷山市| 汶川县| 加查县| 南郑县| 青州市| 和林格尔县| 海南省| 科技| 淳安县| 永城市| 庄河市| 会昌县| 昌邑市| 灵宝市| 喜德县| 西青区| 玛多县| 永德县| 麻江县| 内黄县| 衢州市| 中宁县| 牙克石市| 巨鹿县| 祥云县| 都匀市| 绵竹市| 娄烦县| 六枝特区| 枣强县| 濮阳市| 蓬安县| 托里县| 全州县| 晋中市| 洪洞县| 和硕县| 白城市| 鞍山市| 饶河县|