Re: Pentest Letter of Achievement/CertificateFrom: "blowfish 448" <blowfish448 () hotmail com> Date: Wed, 13 Jul 2005 10:29:18 +0200
Tom, Ralph,
thanks for the input, and I totally agree. Should have been paying more
attention
to the wording I used. It's not so much providing a certificate of success,
here I
agree with your arguments, but rather an objective statement of penetration
testing
has been executed at a certain period in time on infrastructure X at
customer Y by
company Z. This so they can show to their customer base they take security
serious
and have undergone testing.
From my experience in the financial market customers and partners - e.g.
other banks -
of financial organisations asking for such proof is absolutely not so
uncommon.