官术网_书友最值得收藏!

Client IT team notifications

Penetration tests are also used as a means to check the readiness of the support staff in responding to incidents and intrusion attempts. You should discuss this with the client whether it is an announced or unannounced test. If it's an announced test, make sure that you inform the client of the time and date, as well as the source IP addresses from where the testing (attack) will be done, in order to avoid any real intrusion attempts being missed by their IT security team. If it's an unannounced test, discuss with the client what will happen if the test is blocked by an automated system or network administrator. Does the test end there, or do you continue testing? It all depends on the aim of the test, whether it's conducted to test the security of the infrastructure or to check the response of the network security and incident handling team. Even if you are conducting an unannounced test, make sure that someone in the escalation matrix knows about the time and date of the test. Web application penetration tests are usually announced.

主站蜘蛛池模板: 唐海县| 通州市| 北京市| 延边| 修武县| 云龙县| 巴塘县| 珠海市| 定南县| 大足县| 安顺市| 宁河县| 文化| 天长市| 肥西县| 横山县| 郧西县| 军事| 正蓝旗| 东丽区| 都昌县| 临潭县| 长宁区| 错那县| 永年县| 广灵县| 鹤岗市| 抚宁县| 广德县| 大方县| 永德县| 内丘县| 新河县| 鲜城| 肇源县| 进贤县| 额济纳旗| 达拉特旗| 德钦县| 错那县| 罗定市|