Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Firefox 3 Brings More Security Features | Main | Bhutto Assassination Exploited for Spreading Malware »

NIST Recommends Penetration Testing

The National Institute of Standards and Technology (NIST) is recommending penetration testing in its forthcoming "Guide for Assessing Security Controls in Federal Information Systems”, due out in March, 2008. The recommendations NIST develops for federal systems are applicable to commercial sites as well, so it's worth taking note of what they say. For example, from SC Magazine:

NIST recommends that government agencies train selected personnel in penetration testing tools and techniques, which should be updated on a regular basis to address newly discovered exploitable vulnerabilities.

The guidelines also express a preference for the use of automated penetration tools.

But cautions:

"significant oversight and resources" should be applied to the testing process and that tests must be carefully planned to avoid potentially disruptive attacks that are not fully authorized.

and

The use of outside auditors to conduct penetration tests also would limit the number of federal employees trained to undertake sophisticated attacks, reducing the possibility that a disgruntled government staffer could use the knowledge gleaned from simulated tests to mount a real attack, Larson [executive managing director of computer forensics consultants Stroz Friedberg] noted.

Developing penetration testing skills and plans will take time. This isn't as simple a matter as installing and patching AV software. There are serious downsides to penetration testing gone wrong.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/576

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net