官术网_书友最值得收藏!

Organization chart

You may be wonder why an organization chart is a valuable and required piece of documentation for a penetration test. But when you think about it, people in higher positions tend to get targeted because they have the power to transfer money, or have access to important items. Knowing the chain of command for all employees within an organization allows us, as penetration testers, to see other individuals that can be targeted with the hopes of getting all the way to the top. This information can help show the penetration tester whom to potentially target first. It may be easier for a hacker to get a junior accountant to click on a link and install the malware for the hacker to have remote access than it would be for them to try the same approach with the CFO. Now, we are pretty sure the CFO will have more access compared to the junior accountant, but once you have a foothold within an organization, moving around becomes a lot easier. Remember: People are typically the weakest link in security.

Here is a simple example of an organization chart:

主站蜘蛛池模板: 延边| 民权县| 聊城市| 青川县| 吉安县| 禹城市| 全椒县| 津南区| 泸西县| 阜城县| 安顺市| 五莲县| 灵寿县| 巨野县| 灌云县| 静宁县| 新津县| 客服| 崇仁县| 会泽县| 玛多县| 措勤县| 锡林郭勒盟| 浦北县| 阿合奇县| 太仆寺旗| 仙游县| 辰溪县| 苏尼特右旗| 阿巴嘎旗| 葫芦岛市| 唐海县| 镇沅| 丰台区| 珠海市| 石狮市| 金寨县| 方正县| 运城市| 金湖县| 当雄县|