zoukankan      html  css  js  c++  java
  • Penetration Test

    Communication

    IMPPORTANCE OF COMMUNICATION
    • Good communication is critical to the penetration test success
    • Most penetration tests should be conducted openly
      • Unless discretion is a stated goal
    • Cooperation is enhanced with communication
    • Who authorizes the project and provides funding?
    • Who should be contacted if unexpected consequences occur?
    • Who will resolve conflicts?
    • Who will provide required technical assistance?
    • How will you escalate issues that are not resolved in a timely manner?
    • Communication timing and frequency
    • Communication triggers
      • Critical findings - something that really can't wait
      • Stages - moving from one phase to another
      • Indicators of prior compromise - finding evidence that an attacker has already been here
      • Other defined milestones or events
        • Periodic reports
        • Critical tests started/completed
        • Obstacles put in place/removed(i.e. affect on operations)
    REASONS FOR COMMUNICATION
    • Situational awareness - most common recurring reason
    • De-escalation - information or action is needed to reduce critical risk
    • De-confliction - resolve conflict of any type
      • Pen test team vs operations/users
      • Pen test team vs service provider
      • Pen test team vs management
    • Goal reprioritization - changes to pen testing plan
      • Unexpected impact
      • Unexpected findings
      • Organizational changes - management change, merger, acquisition
      • Conflict with team, management, resources, etc.
    • All changes must follow change procedures
    QUICK REVIEW
    • Good communication is critical to pen test project success
    • Managing communication expectations, including frequency, reduces conflict
    • Define triggers that initiate communication
    相信未来 - 该面对的绝不逃避,该执著的永不怨悔,该舍弃的不再留念,该珍惜的好好把握。
  • 相关阅读:
    Docker简介
    分类技术
    龙果支付系统
    [徐培成系列实战课程]docker篇
    高手速成android开源项目【developer篇】
    高手速成android开源项目【项目篇】
    高手速成android开源项目【tool篇】
    高手速成android开源项目【View篇】
    JAVA代理分析
    程序员的2013回顾及2014钱途
  • 原文地址:https://www.cnblogs.com/keepmoving1113/p/14156931.html
Copyright © 2011-2022 走看看