Government Agencies debate over automatic penetration tools
It seems that debate over the automatic tools vs. manual penetration tools raises serious questions within the government agencies.South Carolina and Delaware already use Core Impact, other might follow:
Let’s assume you’ve signed off on a decision to run penetration tests because you want to know how vulnerable your agency is to outside attacks. Now what? Should your agency hire a consultant? Buy automated software to perform the tests? Both?
Answering 10 questions can help you decide whether hiring a consultant or buying software is the right answer.
- What is your risk tolerance for information technology security threats?
- Does your agency perform critical functions or have stewardship of critical or sensitive data? How serious are the implications of disrupted service or lost or compromised data?
- Do you know how well your software patching system is working?
- Do you have the in-house expertise necessary to run and interpret automated tests?
- Have you determined a baseline of IT security?
- Are you required to have a third-party assessor review your IT security?
- Does your agency have a robust presence on the Web?
- Does your agency primarily use custom applications or does it mostly use commercial software?
- How frequently do you want to test your system and network vulnerability?
- What level of spending can your budget support?
Federal Computer Week magazine has the full story
If you enjoyed this post, make sure you subscribe to my RSS feed!
Thank you for reading this post. You can now Leave A Comment (0) or Leave A Trackback.
Post Info
This entry was posted on Tuesday, February 27th, 2007 and is filed under Penetration Testing, Articles.You can follow any responses to this entry through the Comments Feed. You can Leave A Comment, or A Trackback.
Previous Post: Think Twice When Choosing Pentesters »
Next Post: VOIP calls through firewalls and NATs »
Read More
Related Reading:- Gemalto - Security To Be Free
- Free alternative to ArcSight ESM ? Hardly..
- Privacy Dilemma: How to Protect Yourself Online
- Solera Networks Deep-Packet Capture Review
- WordPress Exploit Scanner
- Phishing Exposed, Brands Secured
- Scanners: New Nessus Release; New eEye Web Scanner
- Good News from ArcSight and Imperva
- CCTV Security Camera and Surveillance Equipment
- OpenDNS Offers Free Web Content Filtering

