Government Agencies debate over automatic penetration tools
It seems that debate over the automatic tools vs. manual penetration tools raises serious questions within the government agencies.South Carolina and Delaware already use Core Impact, other might follow:
Let’s assume you’ve signed off on a decision to run penetration tests because you want to know how vulnerable your agency is to outside attacks. Now what? Should your agency hire a consultant? Buy automated software to perform the tests? Both?
Answering 10 questions can help you decide whether hiring a consultant or buying software is the right answer.
- What is your risk tolerance for information technology security threats?
- Does your agency perform critical functions or have stewardship of critical or sensitive data? How serious are the implications of disrupted service or lost or compromised data?
- Do you know how well your software patching system is working?
- Do you have the in-house expertise necessary to run and interpret automated tests?
- Have you determined a baseline of IT security?
- Are you required to have a third-party assessor review your IT security?
- Does your agency have a robust presence on the Web?
- Does your agency primarily use custom applications or does it mostly use commercial software?
- How frequently do you want to test your system and network vulnerability?
- What level of spending can your budget support?
Federal Computer Week magazine has the full story
Thank you for reading this post. You can now Leave A Comment (0) or Leave A Trackback.
Print This Post
Post Info
This entry was posted on Tuesday, February 27th, 2007 . Tagged with:You can follow any responses to this entry through the Comments Feed. You can Leave A Comment, or A Trackback.
Previous Post: Think Twice When Choosing Pentesters »
Next Post: VOIP calls through firewalls and NATs »
Read More
Related Reading:
Latest Posts:
- Securing Your Network from Web Threats
- My Twitter Notes on 2010-07-25
- New NetWitness Visualize : Welcome To The Future!
- My Twitter Notes on 2010-07-18
- My Twitter Notes on 2010-07-11
- My Twitter Notes on 2010-06-27
- Qualys and Imperva Integration: Natural Evolution
- My Twitter Notes on 2010-06-20
- Pro CERT – First Romanian Commercial CERT
- GFI EventsManager 2010 Review



