CUInfoSecurity.com - Information Security News, Regulations, & Education  

Username:
Password:
 

Penetration Testing: Best Practices

< Back

Penetration testing and Vulnerability Analysis is security testing in which a security analyst attempts to circumvent the security features of a system based on their understanding of the system design and implementation. The purpose of penetration testing or vulnerability analysis is to identify methods of gaining access to a system by using common tools and techniques developed by “hackers.” This testing is highly recommended for complex or critical systems (e.g., most organization's networks). It is also mandated by several banking regulations, such as the Section 501(B) of GLBA requiring financial services organizations to maintain a secure computing and network environment.

Penetration testing can be an invaluable technique to an organization's information security program. However, it is a very labor-intensive activity and requires great expertise to minimize the risk to targeted systems. With the information presented during this webinar, the attendees will be prepared to get the most from their next penetration tests and vulnerability analyses. The attendees will be able to walk away with real-world solutions to the growing challenges of maintaining information security posture for their organizations. An organization’s security posture includes consideration of personnel, processes, and technologies. Definition, periodic testing, and continuous maintenance of appropriate information security standards and practices – all vital components of the security architecture of an organization – will be discussed within the context of penetration testing and vulnerability analysis during this presentation.

Are All Penetration Test and Vulnerability Analysis Equal?

Organizations perform penetration testing and vulnerability analyses under several different conditions. The goal is to expose not only vulnerabilities that can be leveraged by outside intruders who have no link to information on the organization, but also vulnerabilities that can be potentially exploited by “insiders” who possess some knowledge and access to the mission-critical systems.

Attendees will hear strategies for gaining the most return from their investments while conducting penetration testing and vulnerability analyses. The speaker will also expand on how successive testing can build upon the knowledge gained during these tests in order to continually strengthen the organization’s security posture.

> Register for this webinar



Terms of Service | Advertise | Archive | Site Map | Contact | Credit Union Information Security RSS Syndication RSS Syndication
Copyright © 2007 CUInfoSecurity.com