官术网_书友最值得收藏!

Organization chart

You may be wonder why an organization chart is a valuable and required piece of documentation for a penetration test. But when you think about it, people in higher positions tend to get targeted because they have the power to transfer money, or have access to important items. Knowing the chain of command for all employees within an organization allows us, as penetration testers, to see other individuals that can be targeted with the hopes of getting all the way to the top. This information can help show the penetration tester whom to potentially target first. It may be easier for a hacker to get a junior accountant to click on a link and install the malware for the hacker to have remote access than it would be for them to try the same approach with the CFO. Now, we are pretty sure the CFO will have more access compared to the junior accountant, but once you have a foothold within an organization, moving around becomes a lot easier. Remember: People are typically the weakest link in security.

Here is a simple example of an organization chart:

主站蜘蛛池模板: 陈巴尔虎旗| 南郑县| 安岳县| 准格尔旗| 红桥区| 普定县| 环江| 定日县| 历史| 龙门县| 宁强县| 东安县| 霍山县| 孝感市| 漾濞| 石城县| 曲阜市| 陈巴尔虎旗| 边坝县| 海盐县| 越西县| 军事| 天镇县| 高陵县| 康乐县| 额济纳旗| 浦东新区| 昭平县| 工布江达县| 东城区| 台东市| 绥芬河市| 周口市| 吉水县| 荆州市| 远安县| 前郭尔| 石泉县| 如东县| 托克托县| 蒙自县|