SlideShare une entreprise Scribd logo
1  sur  11
Penetration TestingPenetration Testing
Need of Penetration Testing?Need of Penetration Testing?
What is Penetration Testing ?
A Penetration Testing, or sometimes Pentest
Is a software attack on a computer system that looks for security weaknesses,
Potentially gaining access to the computer's features and data.
Security issues that the penetration test uncovers should be reported to the
system owner.
Penetration test reports may also assess potential impacts to the
organization and suggest countermeasures to reduce risk.
Objectives / Goals of Penetration Testing are
Why we need Penetration Testing Team
 There are many reasons for organizations should seriously consider
performing penetration tests.
 A penetration test is a highly specialized, security-specific validation of
controls in place.
 Penetration testing is really a form of QA that looks for flaws in
network architecture and design, operating system and application
configuration, application design, and even human behaviour as it
relates to security policies and procedures.
 This can range from testing network and application access
controls, to software code and IT operational processes.
Advantages of a Penetration TestAdvantages of a Penetration Test
Penetration testing can be extremely useful to people who wish to get extra
reassurance when it comes to critical web facing systems.
However they can also be useful in a variety of other ways, such as:
a) Testing a System Administrator to see if he is keeping systems updated
and secured.
b) Compliance & the Payment Card Industry (PCI), when operating
an online payments system.
c) Risk reduction and risk mitigation factors for insurance or other
industries.
d) Protection of Confidentially, Integrity and Availability (CIA triad)
of data.
a) Testing a System Administrator to see if he is keeping systems updated
and secured.
b) Compliance & the Payment Card Industry (PCI), when operating
an online payments system.
c) Risk reduction and risk mitigation factors for insurance or other
industries.
d) Protection of Confidentially, Integrity and Availability (CIA triad)
of data.
Most Common Types of Penetration TestsMost Common Types of Penetration Tests
Two of the more common types of penetration tests are black box and white box
penetration testing.
Black Box TestBlack Box Test,,
no prior knowledge of the corporate system is given to
the third party tester. This is often the most preferred test as it is an
accurate simulation of how an outsider/hacker would see the network
and attempt to break into it.
White Box Test,White Box Test,
on the other hand is when the third party organisation is
given full IP information, network diagrams and source code files to the
software, networks and systems, in a bid to find weaknesses from any of
the available information.
Common Measurements for Penetration TestingCommon Measurements for Penetration Testing
What kinds of metrics make sense for penetration testing and vulnerability
assessments?
For vulnerability assessments, common measurements to track include:
 Number of vulnerabilities found;Number of vulnerabilities found;
 Criticality and types of vulnerabilities;Criticality and types of vulnerabilities;
 Percentage of systems and applications scanned;Percentage of systems and applications scanned;
 Number of “unowned” or questionable assets detected.Number of “unowned” or questionable assets detected.
For penetration tests, the key is a baseline:For penetration tests, the key is a baseline:
o How many critical vulnerabilities were found vs. the last test?How many critical vulnerabilities were found vs. the last test?
o User accounts and/or passwords compromised;User accounts and/or passwords compromised;
o Data records accessed.Data records accessed.
A penetration test is useful service if your business can justify the expenseA penetration test is useful service if your business can justify the expense
and importance of having its web facing equipment properly secured.and importance of having its web facing equipment properly secured.
Rest assured that cybercrime is a growing problem, costing business andRest assured that cybercrime is a growing problem, costing business and
the government millions each year.the government millions each year.
The cyber criminals don’t look to be giving up anytime soon and with allThe cyber criminals don’t look to be giving up anytime soon and with all
this money to be made by them online, who’s to say your business won’tthis money to be made by them online, who’s to say your business won’t
be next?be next?
A penetration test is useful service if your business can justify the expenseA penetration test is useful service if your business can justify the expense
and importance of having its web facing equipment properly secured.and importance of having its web facing equipment properly secured.
Rest assured that cybercrime is a growing problem, costing business andRest assured that cybercrime is a growing problem, costing business and
the government millions each year.the government millions each year.
The cyber criminals don’t look to be giving up anytime soon and with allThe cyber criminals don’t look to be giving up anytime soon and with all
this money to be made by them online, who’s to say your business won’tthis money to be made by them online, who’s to say your business won’t
be next?be next?
ResourcesResources
http://testbytes.net/testing-services/penetration-testing/http://testbytes.net/testing-services/penetration-testing/
http://searchsecurity.techtarget.com/magazineContent/How-to-pen-test-Why-you-need-http://searchsecurity.techtarget.com/magazineContent/How-to-pen-test-Why-you-need-
an-internal-security-pen-testing-programan-internal-security-pen-testing-program
http://bizsecurity.about.com/od/informationsecurity/a/Penetration-Testing-What-Is-It-http://bizsecurity.about.com/od/informationsecurity/a/Penetration-Testing-What-Is-It-
Do-I-Need-It.htmDo-I-Need-It.htm
Why we need Penetration Testing

Contenu connexe

Plus de jananya213

Mobile software testing guide
Mobile software testing guideMobile software testing guide
Mobile software testing guidejananya213
 
Penetration Testing
Penetration TestingPenetration Testing
Penetration Testingjananya213
 
Softbreaks - Job Search App
Softbreaks -  Job Search AppSoftbreaks -  Job Search App
Softbreaks - Job Search Appjananya213
 
Reasons to Employ GPS School Bus Tracking System
Reasons to Employ GPS School Bus Tracking SystemReasons to Employ GPS School Bus Tracking System
Reasons to Employ GPS School Bus Tracking Systemjananya213
 
Tips for school bus drivers
Tips for school bus driversTips for school bus drivers
Tips for school bus driversjananya213
 
The role of abu dhabi education council
The role of abu dhabi education councilThe role of abu dhabi education council
The role of abu dhabi education counciljananya213
 
10 reasons to choose the yii framework
10 reasons to choose the yii framework10 reasons to choose the yii framework
10 reasons to choose the yii frameworkjananya213
 
Yii Development
Yii DevelopmentYii Development
Yii Developmentjananya213
 
Major misconceptions about student tracking
Major misconceptions about student trackingMajor misconceptions about student tracking
Major misconceptions about student trackingjananya213
 
Best School Bus Tracking System
Best School Bus Tracking SystemBest School Bus Tracking System
Best School Bus Tracking Systemjananya213
 
Career Planning
Career PlanningCareer Planning
Career Planningjananya213
 
Best out of the parent portal available
Best out of the parent portal availableBest out of the parent portal available
Best out of the parent portal availablejananya213
 
Shocking truth behind student kidnappings!
Shocking truth behind student kidnappings!Shocking truth behind student kidnappings!
Shocking truth behind student kidnappings!jananya213
 
Emerge from KHDA Inspections with flying colours!
Emerge from KHDA Inspections with flying colours!Emerge from KHDA Inspections with flying colours!
Emerge from KHDA Inspections with flying colours!jananya213
 
15 Popular Movies that Highlight the Power of Education !
15 Popular Movies that Highlight the Power of Education !15 Popular Movies that Highlight the Power of Education !
15 Popular Movies that Highlight the Power of Education !jananya213
 

Plus de jananya213 (16)

Mobile software testing guide
Mobile software testing guideMobile software testing guide
Mobile software testing guide
 
Penetration Testing
Penetration TestingPenetration Testing
Penetration Testing
 
Softbreaks - Job Search App
Softbreaks -  Job Search AppSoftbreaks -  Job Search App
Softbreaks - Job Search App
 
Reasons to Employ GPS School Bus Tracking System
Reasons to Employ GPS School Bus Tracking SystemReasons to Employ GPS School Bus Tracking System
Reasons to Employ GPS School Bus Tracking System
 
Tips for school bus drivers
Tips for school bus driversTips for school bus drivers
Tips for school bus drivers
 
The role of abu dhabi education council
The role of abu dhabi education councilThe role of abu dhabi education council
The role of abu dhabi education council
 
10 reasons to choose the yii framework
10 reasons to choose the yii framework10 reasons to choose the yii framework
10 reasons to choose the yii framework
 
Yii Development
Yii DevelopmentYii Development
Yii Development
 
Major misconceptions about student tracking
Major misconceptions about student trackingMajor misconceptions about student tracking
Major misconceptions about student tracking
 
Best School Bus Tracking System
Best School Bus Tracking SystemBest School Bus Tracking System
Best School Bus Tracking System
 
ADEC
ADECADEC
ADEC
 
Career Planning
Career PlanningCareer Planning
Career Planning
 
Best out of the parent portal available
Best out of the parent portal availableBest out of the parent portal available
Best out of the parent portal available
 
Shocking truth behind student kidnappings!
Shocking truth behind student kidnappings!Shocking truth behind student kidnappings!
Shocking truth behind student kidnappings!
 
Emerge from KHDA Inspections with flying colours!
Emerge from KHDA Inspections with flying colours!Emerge from KHDA Inspections with flying colours!
Emerge from KHDA Inspections with flying colours!
 
15 Popular Movies that Highlight the Power of Education !
15 Popular Movies that Highlight the Power of Education !15 Popular Movies that Highlight the Power of Education !
15 Popular Movies that Highlight the Power of Education !
 

Dernier

H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DaySri Ambati
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 

Dernier (20)

H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo DayH2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
H2O.ai CEO/Founder: Sri Ambati Keynote at Wells Fargo Day
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 

Why we need Penetration Testing

  • 1. Penetration TestingPenetration Testing Need of Penetration Testing?Need of Penetration Testing?
  • 2.
  • 3. What is Penetration Testing ? A Penetration Testing, or sometimes Pentest Is a software attack on a computer system that looks for security weaknesses, Potentially gaining access to the computer's features and data. Security issues that the penetration test uncovers should be reported to the system owner. Penetration test reports may also assess potential impacts to the organization and suggest countermeasures to reduce risk.
  • 4. Objectives / Goals of Penetration Testing are
  • 5. Why we need Penetration Testing Team  There are many reasons for organizations should seriously consider performing penetration tests.  A penetration test is a highly specialized, security-specific validation of controls in place.  Penetration testing is really a form of QA that looks for flaws in network architecture and design, operating system and application configuration, application design, and even human behaviour as it relates to security policies and procedures.  This can range from testing network and application access controls, to software code and IT operational processes.
  • 6. Advantages of a Penetration TestAdvantages of a Penetration Test Penetration testing can be extremely useful to people who wish to get extra reassurance when it comes to critical web facing systems. However they can also be useful in a variety of other ways, such as: a) Testing a System Administrator to see if he is keeping systems updated and secured. b) Compliance & the Payment Card Industry (PCI), when operating an online payments system. c) Risk reduction and risk mitigation factors for insurance or other industries. d) Protection of Confidentially, Integrity and Availability (CIA triad) of data. a) Testing a System Administrator to see if he is keeping systems updated and secured. b) Compliance & the Payment Card Industry (PCI), when operating an online payments system. c) Risk reduction and risk mitigation factors for insurance or other industries. d) Protection of Confidentially, Integrity and Availability (CIA triad) of data.
  • 7. Most Common Types of Penetration TestsMost Common Types of Penetration Tests Two of the more common types of penetration tests are black box and white box penetration testing. Black Box TestBlack Box Test,, no prior knowledge of the corporate system is given to the third party tester. This is often the most preferred test as it is an accurate simulation of how an outsider/hacker would see the network and attempt to break into it. White Box Test,White Box Test, on the other hand is when the third party organisation is given full IP information, network diagrams and source code files to the software, networks and systems, in a bid to find weaknesses from any of the available information.
  • 8. Common Measurements for Penetration TestingCommon Measurements for Penetration Testing What kinds of metrics make sense for penetration testing and vulnerability assessments? For vulnerability assessments, common measurements to track include:  Number of vulnerabilities found;Number of vulnerabilities found;  Criticality and types of vulnerabilities;Criticality and types of vulnerabilities;  Percentage of systems and applications scanned;Percentage of systems and applications scanned;  Number of “unowned” or questionable assets detected.Number of “unowned” or questionable assets detected. For penetration tests, the key is a baseline:For penetration tests, the key is a baseline: o How many critical vulnerabilities were found vs. the last test?How many critical vulnerabilities were found vs. the last test? o User accounts and/or passwords compromised;User accounts and/or passwords compromised; o Data records accessed.Data records accessed.
  • 9. A penetration test is useful service if your business can justify the expenseA penetration test is useful service if your business can justify the expense and importance of having its web facing equipment properly secured.and importance of having its web facing equipment properly secured. Rest assured that cybercrime is a growing problem, costing business andRest assured that cybercrime is a growing problem, costing business and the government millions each year.the government millions each year. The cyber criminals don’t look to be giving up anytime soon and with allThe cyber criminals don’t look to be giving up anytime soon and with all this money to be made by them online, who’s to say your business won’tthis money to be made by them online, who’s to say your business won’t be next?be next? A penetration test is useful service if your business can justify the expenseA penetration test is useful service if your business can justify the expense and importance of having its web facing equipment properly secured.and importance of having its web facing equipment properly secured. Rest assured that cybercrime is a growing problem, costing business andRest assured that cybercrime is a growing problem, costing business and the government millions each year.the government millions each year. The cyber criminals don’t look to be giving up anytime soon and with allThe cyber criminals don’t look to be giving up anytime soon and with all this money to be made by them online, who’s to say your business won’tthis money to be made by them online, who’s to say your business won’t be next?be next?