Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Penetration Testing: RE: Business justification for pentesting

RE: Business justification for pentesting

From: Craig Wright <cwright_at_bdosyd.com.au>
Date: Fri, 2 Sep 2005 09:31:56 +1000

This is for a small visa processing site where a full audit is not
required.

This can not be used as a blanket statement. For larger PCI clients and
issuers, an onsite audit (which is extremely detailed if done correctly)
must be completed

Craig

-----Original Message-----
From: Vic N [mailto:vic778_at_hotmail.com]
Sent: 1 September 2005 9:04
To: sectraq_at_gmail.com; pen-test_at_securityfocus.com
Subject: RE: Business justification for pentesting

For Visa / MC PCI 1.0 specification (requirement 11.3), an annual pen
test of network infrastructure and applications must take place once a
year w/remediation.

www.visa.com/cisp (see PCI data security standard)

>hi all,
>
>a few classic question that i would appriciate any answers for.
>1- i would like to briefly know how to quantify information assets. In
>other words, i hear a pentester say: if a hacker breaks in ur network,
>u will loose up to 40000$ for example. how can he come up with such
figures?
>
>2- are there any other means to justify pentesting for management
>except for $$$?
>
>3- are there any official statistics, figures etc. for justifying
>pentesting. ther more official it is the better.
>
>4- any other information you guys might find helpful in justifying a
>pentest would be appriciated.
>
>thnx in advance for ur help.
>
>T.N
>

------------------------------------------------------------------------
------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on
your website. Up to 75% of cyber attacks are launched on shopping carts,
forms, login pages, dynamic content etc. Firewalls, SSL and locked-down
servers are futile against web application hacking. Check your website
for vulnerabilities to SQL injection, Cross site scripting and other web
attacks before hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
------------------------------------------------------------------------
-------

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner:

Hackers are concentrating their efforts on attacking applications on your
website. Up to 75% of cyber attacks are launched on shopping carts, forms,
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for vulnerabilities
to SQL injection, Cross site scripting and other web attacks before hackers do!
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------
Received on Sep 02 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos