Security Program management and oversight 5.5 Flashcards
Audits and Assessments
Cyber Security Audit - Examines the IT infrasutrcute, software, devices
Internal Audits
Audit committee, Oversea management activities. All audits start and stop with the internal audit comittees.
External Audits
Contracting a third party company to conduct audits on the
Penetration Tests.
Operating system security can be circumvented by physical means. There is no security without physical security.
Pen-testing Perspectives
Offensive - Red Team
Defensive - Blue Team
Reconnaissance
Gathering information before the the attack.
Passive reconnaissance - Learn as much as you can from open sources. Social media, online forums, reddit
Active Reconnaissance
active reconnaissance,
Visible on netwokr traffic and logs,
pings and scans
DNS Queries, OS Scan.