


|
Face-Off: Is Penetration Testing Worth It?
sponsored by Information Security Magazine
|
|
|
Posted:
|
05 Mar 2007
|
|
Published:
|
01 Mar 2007
|
|
Format:
|
HTML
|
|
Length:
|
2
Page(s)
|
|
Type:
|
Journal Article
|
|
Language:
|
English
|
|
|
ABSTRACT:
There are security experts who insist penetration testing is essential for network security, and you have no hope of being secure unless you do it regularly. And there are contrarian security experts who tell you penetration testing is a waste of time; you might as well throw your money away. Both of these views are wrong. The reality of penetration testing is more complicated and nuanced. Penetration testing is a broad term. It might mean breaking into a network to demonstrate you can. It might mean trying to break into a network to document vulnerabilities. It might involve a remote attack, physical penetration of a data center or social engineering attacks. It might use commercial or proprietary vulnerability scanning tools, or rely on skilled white-hat hackers. It might just evaluate software version numbers and patch levels, and make inferences about vulnerabilities.
|
|
|
Authors
Marcus Ranum
CSO
,
Tenable Network Security
Bruce Schneier
CTO
,
Counterpane Internet Security
|
 |
BROWSE RELATED
RESOURCES
Network Security | Penetration Testing | Vulnerability Assessments
|
View All Resources
sponsored by Information Security Magazine
|
|
Research Library Copyright © 1998-2008 Bitpipe, Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. TechTarget · 117 Kendrick St · Needham, MA · 02494
Use of this web site constitutes acceptance of the Bitpipe Terms and Conditions and Privacy Policy. webmaster@bitpipe.com
|