官术网_书友最值得收藏!

Client IT team notifications

Penetration tests are also used as a means to check the readiness of the support staff in responding to incidents and intrusion attempts. You should discuss this with the client whether it is an announced or unannounced test. If it's an announced test, make sure that you inform the client of the time and date, as well as the source IP addresses from where the testing (attack) will be done, in order to avoid any real intrusion attempts being missed by their IT security team. If it's an unannounced test, discuss with the client what will happen if the test is blocked by an automated system or network administrator. Does the test end there, or do you continue testing? It all depends on the aim of the test, whether it's conducted to test the security of the infrastructure or to check the response of the network security and incident handling team. Even if you are conducting an unannounced test, make sure that someone in the escalation matrix knows about the time and date of the test. Web application penetration tests are usually announced.

主站蜘蛛池模板: 伊通| 江津市| 景谷| 灵石县| 任丘市| 墨竹工卡县| 平谷区| 霍城县| 衢州市| 福海县| 佳木斯市| 屯门区| 枣庄市| 玉溪市| 香河县| 潜山县| 乌拉特后旗| 治多县| 平原县| 金沙县| 阿图什市| 黑龙江省| 隆林| 漯河市| 泾川县| 论坛| 娱乐| 宁蒗| 台中市| 海南省| 新乡县| 祁门县| 嘉鱼县| 苏尼特右旗| 广饶县| 鸡泽县| 成都市| 盐源县| 海南省| 佳木斯市| 贺州市|