Why do a penetration test ? Flashcards
1
Q
Lil’ list:
A
IDENTIFY THREATS
REDUCE SECURITY EXPENSES
PROVIDE COMPLETE SECURITY ASSESSMENT
MAINTAIN INDUSTRY STANDARDS AND REGULATIONS
FOLLOW BEST PRACTICES
TEST SECURITY CONTROLS
IMPROVE CURRENT SECURITY INFRASTRUCTURE
PAY PARTICULAR ATTENTION TO SEVERE VULNERABILITIES
PREPARE STEPS FOR PREVENTING EXPLOITATIONS
TEST NETWORK SECURITY DEVICES
2
Q
Significant side notes:
A
- THIS ONE’S EXTRA IMPORTANT: “ROSI” stands for “return of security investment”
- Whenever purchasing equipment, corporations will generally plan for 30% growth. (So, if you had 500 personnel and you purchase a router, it’d have to be able to support 500 personnel, plus 30% (650 personnel))
- In the EU, it’s law that if a customer requests that their data be deleted, a company must fully purge their data (so, if someone from the EU deletes an account, a company can not even hold their data in a database for the purposes of eventual restoration unless they have the consent of the owner of the account)