官术网_书友最值得收藏!

Dealing with third parties

Today, many businesses are utilizing cloud services. There is a high probability that you will encounter cloud servers within your penetration scope. It's important to keep in mind who owns the server. In the case of a cloud environment, the server is not owned by the business that the penetration test is being conducted for, but rather the cloud provider.

Big players in the cloud space, such as Microsoft, Amazon, and Google, all have penetration testing rules-of-engagement documents. These documents detail what you are allowed to do and what you are not allowed to do.

Microsoft defines its rules of engagement here:  https://www.microsoft.com/en-us/msrc/pentest-rules-of-engagement.
Amazon defines its rules of engagement here:   https://aws.amazon.com/security/penetration-testing/ .
Google defines its rules of engagement here:   https://cloud.google.com/security/overview/ .

Make sure that you obtain the correct approvals from the cloud provider if you have any cloud services within your penetration scope; failure to do so might lead to legal consequences.

主站蜘蛛池模板: 汉中市| 太康县| 抚松县| 石狮市| 正宁县| 黄陵县| 称多县| 吴堡县| 洪泽县| 宿松县| 满洲里市| 闵行区| 扬中市| 独山县| 平武县| 尤溪县| 舒兰市| 靖远县| 宁国市| 嘉定区| 绥德县| 临清市| 河东区| 梅州市| 元氏县| 汕头市| 玉田县| 公安县| 东乌| 平和县| 长沙县| 共和县| 孝义市| 寿阳县| 平潭县| 富宁县| 青龙| 溧水县| 涟水县| 沾化县| 咸丰县|