官术网_书友最值得收藏!

Organization chart

You may be wonder why an organization chart is a valuable and required piece of documentation for a penetration test. But when you think about it, people in higher positions tend to get targeted because they have the power to transfer money, or have access to important items. Knowing the chain of command for all employees within an organization allows us, as penetration testers, to see other individuals that can be targeted with the hopes of getting all the way to the top. This information can help show the penetration tester whom to potentially target first. It may be easier for a hacker to get a junior accountant to click on a link and install the malware for the hacker to have remote access than it would be for them to try the same approach with the CFO. Now, we are pretty sure the CFO will have more access compared to the junior accountant, but once you have a foothold within an organization, moving around becomes a lot easier. Remember: People are typically the weakest link in security.

Here is a simple example of an organization chart:

主站蜘蛛池模板: 元江| 霍州市| 江油市| 团风县| 财经| 新巴尔虎右旗| 邢台县| 松滋市| 清镇市| 观塘区| 宜兰市| 韩城市| 克拉玛依市| 晋城| 绩溪县| 集贤县| 武宁县| 武夷山市| 江都市| 准格尔旗| 新民市| 靖边县| 万宁市| 古田县| 巴林右旗| 麻阳| 库伦旗| 隆林| 文山县| 信宜市| 肥乡县| 苍溪县| 陵川县| 泸州市| 泊头市| 光泽县| 赫章县| 太仆寺旗| 定安县| 涞源县| 新宁县|