{"id":1075,"date":"2017-10-04T19:21:07","date_gmt":"2017-10-04T01:21:07","guid":{"rendered":"http:\/\/www.jedge.com\/wordpress\/?p=1075"},"modified":"2018-05-22T20:21:57","modified_gmt":"2018-05-23T02:21:57","slug":"compliance-based-penetration-testing-youre-doing-it-wrong","status":"publish","type":"post","link":"https:\/\/www.jedge.com\/wordpress\/2017\/10\/compliance-based-penetration-testing-youre-doing-it-wrong\/","title":{"rendered":"Compliance Based Penetration Testing &#8211; You\u2019re Doing it Wrong"},"content":{"rendered":"<p>What is a penetration Test?  According to the National Institute of Standards and Technology (NIST) a penetration test is defined as the following:<\/p>\n<p><em>A test methodology in which assessors, using all available documentation (e.g., system design, source code, manuals) and working under specific constraints, attempt to circumvent the security features of an information system. <\/em> &#8211; <a href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-53a\/rev-1\/archive\/2010-06-29\" target=\"_blank\">NIST<\/a><\/p>\n<p>This definition is a great example members of audit and compliance teams use when defining a penetration test.<\/p>\n<p>Management processes identify the applicable requirements (defined for example in laws, regulations, contracts, strategies and policies) and assess the state of compliance. Melding the two together does not make for a happy or successful marriage.  This presentation will discuss the pitfalls of penetration tests conducted to meet compliance requirements.  Also highlighted will be suggestions and methods to ensure a compliance based penetration test is more than just checking a box on a risk management questionnaire.  The compliance regulation used as the example will be the Payment Card Industry Data Security Standard (PCI-DSS).<br \/>\n<!--more--><br \/>\nThis presentation also focuses on how to properly conduct a Penetration Test.  A proper test can be summed up by the following quote:<\/p>\n<p><em>Successful penetration testers don&#8217;t just throw a bunch of hacks against an organization and regurgitate the output of their tools. Instead, they need to understand how these tools work in-depth, and conduct their test in a careful, professional manner. This course explains the inner workings of numerous tools and their use in effective network penetration testing and ethical hacking projects. <\/em> &#8211; <a href=\"https:\/\/pen-testing.sans.org\/instructors\/author\" target=\"_blank\">Ed Skoudis<\/a><\/p>\n<p>As part of <a href=\"http:\/\/cybersecurity.kennesaw.edu\/\" target=\"_blank\">Cyber Security Awareness Day<\/a> at Kennesaw State University I gave a presentation on this topic.  The presentation can be found <a href=\"https:\/\/youtu.be\/kzUaZUbzRSI\" target=\"_blank\">here<\/a><\/p>\n<p><a href=\"https:\/\/youtu.be\/kzUaZUbzRSI\" target=\"_blank\"><img decoding=\"async\" src=\"http:\/\/ksutv.kennesaw.edu\/images\/events\/00030081.jpg\"><\/a><\/p>\n<p>Resources<br \/>\n<a target=\"_blank\" href=\"https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-53a\/rev-1\/archive\/2010-06-29\">https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-53a\/rev-1\/archive\/2010-06-29<\/a><br \/>\n<a target=\"_blank\" href=\"https:\/\/pen-testing.sans.org\/instructors\/author\">https:\/\/pen-testing.sans.org\/instructors\/author<\/a><br \/>\n<a target=\"_blank\" href=http:\/\/ksutv.kennesaw.edu\/play.php?v=00030081\">http:\/\/ksutv.kennesaw.edu\/play.php?v=00030081<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is a penetration Test? According to the National Institute of Standards and Technology (NIST) a penetration test is defined as the following: A test methodology in which assessors, using all available documentation (e.g., system design, source code, manuals) and working under specific constraints, attempt to circumvent the security features of an information system. &#8211; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[6],"tags":[148,56,54],"class_list":["post-1075","post","type-post","status-publish","format-standard","hentry","category-fyi","tag-compliance","tag-penetration-testing","tag-presentation"],"_links":{"self":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/posts\/1075","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/comments?post=1075"}],"version-history":[{"count":6,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/posts\/1075\/revisions"}],"predecessor-version":[{"id":1081,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/posts\/1075\/revisions\/1081"}],"wp:attachment":[{"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/media?parent=1075"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/categories?post=1075"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jedge.com\/wordpress\/wp-json\/wp\/v2\/tags?post=1075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}