官术网_书友最值得收藏!

Client IT team notifications

Penetration tests are also used as a means to check the readiness of the support staff in responding to incidents and intrusion attempts. You should discuss this with the client whether it is an announced or unannounced test. If it's an announced test, make sure that you inform the client of the time and date, as well as the source IP addresses from where the testing (attack) will be done, in order to avoid any real intrusion attempts being missed by their IT security team. If it's an unannounced test, discuss with the client what will happen if the test is blocked by an automated system or network administrator. Does the test end there, or do you continue testing? It all depends on the aim of the test, whether it's conducted to test the security of the infrastructure or to check the response of the network security and incident handling team. Even if you are conducting an unannounced test, make sure that someone in the escalation matrix knows about the time and date of the test. Web application penetration tests are usually announced.

主站蜘蛛池模板: 扶风县| 尚志市| 镇坪县| 日喀则市| 泰宁县| 三穗县| 侯马市| 神农架林区| 东乌珠穆沁旗| 竹北市| 颍上县| 大新县| 阳原县| 嵊州市| 郯城县| 惠来县| 建始县| 广州市| 虎林市| 莱州市| 徐汇区| 兴城市| 鄂托克前旗| 南京市| 金秀| 古浪县| 桐梓县| 宝山区| 民丰县| 郸城县| 沙河市| 盐源县| 鱼台县| 康平县| 福州市| 饶阳县| 玛纳斯县| 自治县| 鄂托克旗| 嘉义市| 兴和县|