NIST 800-115
The National Institute of Standards and Technology Special Publication (NIST-SP-800-115) is the technical guide to information-security testing and assessment. The publication is produced by Information Technology Laboratory (ITL) at NIST.
The guide defines a security assessment as the process of determining how effectively an entity being assessed meets specific security requirements. As you review the guide, you will see it contains a great amount of information for testing. While the document does not get updated as often as we would like, it is a viable resource for us as a reference when building our methodology for testing.
They offer practical guidelines for designing, implementing, and maintaining technical information, security tests, and examination processes and procedures, by covering the key element or technical security-testing and examination.
These can be used for several reasons, such as finding vulnerabilities in a system or network and verifying compliance with a policy or other requirements. The guide is not intended to present an all-inclusive information-security testing and examination program but rather an outline of key elements of technical security testing and examination, with a weight on specific technical techniques, the benefits and limitations of each, and recommendations for their use.
The NIST 800-115 standard provides a great map for pen testers that is an accepted industry standard. This model is a great way to ensure that your penetration testing program complies with best practices.
- 攻守道:企業(yè)數(shù)字業(yè)務(wù)安全風(fēng)險(xiǎn)與防范
- Learning Python for Forensics
- 零信任網(wǎng)絡(luò):在不可信網(wǎng)絡(luò)中構(gòu)建安全系統(tǒng)
- Enterprise Cloud Security and Governance
- 黑客攻防與無線安全從新手到高手(超值版)
- Learning Veeam? Backup & Replication for VMware vSphere
- Python Penetration Testing Cookbook
- 移動(dòng)APT:威脅情報(bào)分析與數(shù)據(jù)防護(hù)
- Applied Network Security
- 計(jì)算機(jī)網(wǎng)絡(luò)安全技術(shù)研究
- 華為防火墻實(shí)戰(zhàn)指南
- 網(wǎng)絡(luò)安全監(jiān)控實(shí)戰(zhàn):深入理解事件檢測(cè)與響應(yīng)
- 云計(jì)算安全技術(shù)與應(yīng)用
- INSTANT Microsoft Forefront UAG Mobile Configuration Starter
- Developing Applications with Salesforce Chatter