官术网_书友最值得收藏!

The ethics

The ethical vision of security testing constitutes rules of engagement that have to be followed by an auditor to present professional, ethical, and authorized practices. These rules define how the testing services should be offered, how the testing should be performed, determine the legal contracts and negotiations, define the scope of testing, prepare the test plan, follow the test process, and manage a consistent reporting structure. Addressing each of these areas requires careful examination and design of formal practices and procedures that must be followed throughout the test engagement. Some examples of these rules have been discussed below.

  • Offering testing services after breaking into the target system before making any formal agreement between the client and auditor should be completely forbidden. This act of unethical marketing can result in the failure of a business and may have legal implications depending on jurisdictions of a country.
  • Performing a test beyond the scope of testing and crossing the identified boundaries without explicit permissions from a client is prohibited.
  • Binding a legal contract that should limit the liability of a job unless any illegal activity is detected. The contract should clearly state the terms and conditions of testing, emergency contact information, statement of work, and any obvious conflicts of interest.
  • Scope definition should clearly define all the contractual entities and the limits imposed to them during security assessment.
  • Test plan concerns the amount of time required to assess the security of a target system. It is highly advisable to draw up a schedule that does not interrupt the production of business hours.
  • Test process defines the set of steps necessary to follow during the test engagement. These rules combine technical and managerial views for restricting the testing process with its environment and people.
  • Test results and reporting must be presented in a clear and consistent order. The report must mark all the known and unknown vulnerabilities, and should be delivered confidentially to the authorized individual only.
主站蜘蛛池模板: 方正县| 云阳县| 敖汉旗| 浦北县| 伽师县| 蓬溪县| 丹巴县| 麟游县| 志丹县| 铜川市| 筠连县| 奉节县| 淮南市| 珲春市| 遂川县| 泰兴市| 青冈县| 北川| 驻马店市| 苏州市| 彭阳县| 钟祥市| 新宾| 双牌县| 大名县| 惠州市| 正定县| 延安市| 江永县| 大石桥市| 江北区| 苗栗县| 宁晋县| 肥城市| 华宁县| 天祝| 青阳县| 通辽市| 四平市| 衢州市| 静安区|