Sybex Chapter 2 - Planning and Scoping Penetration Tests Flashcards
what is a “white box” or “crystal box” test?
Known environment OR Full Knowledge
What does ATT&CK stand for in MITRE ATT&CK Framework?
Adversarial Tactics, Techniques, and Common Knowledge
OWASP
Open Web Application Security Project: testing guides for web security, mobile security, firmware
PTES
Penetration Testing Execution Standard: pre-engagement interactions like scoping and client questions; testing techniques and concepts
OSSTMM
Open Source Security Testing Methodology Manual: broad penetration testing methodology guide. Not updated since 2010
NIST
National Institute of Standards and Technology: provides standards and cybersecurity frameworks that includes penetration testing.
ISSAF
Information Systems Security Assessment Framework: highly detailed pen testing framework, but not updated since 2005
SOW
Statement of Work
SOO
Statement of Objective; alternative to SOW. Used by US gov
PSW
Performance Work Statement: used by US gov; alternative to SOW
MSA
Master Service Agreement: defines terms the orgs will use for future work. Prevents the need to renegotiate terms at every SOW
CA
Confidentiality Agreement. Like NDA
GLBA
Gramm-Leach-Bliley Act: complies regarding how financial institutions manage personal information
FIPS 140-2 -> FIPS 140-3
US Gov computer security standard to approve cryptographic modules. Crypto modules can be FIPS 140-2 certified