What To Look For In A Penetration Testing Company
What To Look For In A Penetration Testing Company
A penetration testing company is a key component of any organisation's information security framework. Even the most apparently rigorous information security measures may still have vulnerabilities, which can only be discovered by thorough testing. Larger organisations may have their own in-house expertise, but most smaller companies will need to call upon the services of a penetration testing company for regular tests of their network defences.
So what should you look for when commissioning a penetration testing company? The following points are a start, but are not exhaustive:
Qualifications are essential in this highly technical area. For example, the penetration testing firm might be a member of CREST (Council of Registered Ethical Security Testers), a trade association based on recognised technical standards and the highest ethical standards.
There are other certification bodies to look for when considering a penetration testing company, such as the new "Tiger Scheme" for advanced practitioners, or perhaps the EC-Council's CEH (Certified Ethical Hacker), an entry-level certificate. An individual penetration tester may also be a CHECK consultant, which means s/he is cleared to work on UK Government projects.
Individual security testers may likewise be certified by CREST. This qualification, unlike some others in the field, includes both theoretical and practical examinations, and so is extremely rigorous.
However, qualifications are only part of the picture. When hiring a penetration testing company, it is particularly important to check their commitment to the highest ethical standards. A penetration tester may gain access to highly sensitive material, and it would be a grave mistake to hire someone who may not have the best interests of your business at heart. Hence you should check on the procedure for vetting of security testers, since penetration testing companies that employ former criminal hackers should be avoided.
You should also check whether the computer testers' knowledge is up-to-date. The field of penetration testing is constantly changing, and an active programme of Continuing Professional development is essential for any penetration testing consultant who wishes to remain current.
Finally, it is always a good idea to ask for references from previous clients. The security testing form should be willing to provide these to you, or give you the contact details of former clients.
A penetration testing company does not need to be geographically close to your business premises, since some computer security tests of this kind can be carried out remotely over the Internet. However, for other tests, the tester will need access to your computer systems and so will travel to your location. Whichever company you choose, however, it is always good practice to institute a programme of regular penetration testing rather than only occasional tests. In this way, unforeseen security vulnerabilities are more likely to be discovered in good time, before malicious hackers can find and exploit them. This makes it all the more important to choose your penetration testing company wisely, using the criteria given above.
A Regular Ventilation Cleaning Programme Is Only As Good As The People Doing It Terminating Onerous Contracts To Cut Costs Can Help Save A Company In Difficulties Dehumidification explained Ear Piercing In Bangalore-- How To Talk Dirty - Guide To Making It Better Change Your Life by Identifying Your Life Purpose Talk Dirty To Your Husband - Introducing It In 4 Easy Steps Ron Hellems Talk Dirty To Him Talking Dirty To Your Man Weekends Corbett National park Tempo Ultra WP 420 Gram Jars – The Most Effective Insecticide Talking Dirty - Figuring Out If It Is Right For You Pregency Timeline:Your Must Know Advice of Exactly What is Still to Happen
www.yloan.com
guest:
register
|
login
|
search
IP(216.73.216.114) California / Anaheim
Processed in 0.017046 second(s), 5 queries
,
Gzip enabled
, discuz 5.5 through PHP 8.3.9 ,
debug code: 18 , 3320, 85,