<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Tag penetration test</title>
    <link>http://blog.clearnetsec.com/articles/tag/penetrationtest</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>Competing for network-based security assessments</title>
      <description>When competing for security assessment projects it is often painful for the customer to distinguish the level of service or effort between proposals.  We used to respond to RFPs with the intention of satisfying all the services the customer is soliciting &#8211; of course in the end in nearly every case that isn&#8217;t what wins the bid.
&lt;p /&gt;&lt;br /&gt;
We came up with a quick flow diagram to illustrate the differences in the level of effort between network-based security assessments.  This has helped us tremendously with clients and with keeping the playing field level.  It&#8217;s not complete or exact by any means, but it works.
&lt;p /&gt;&lt;br /&gt;
&lt;img src="http://blog.clearnetsec.com/files/Flowchart_for_Security_Assessments.jpg"&gt;
&lt;p /&gt;&lt;br /&gt;
We add some verbiage to help customers relate it to real world:
&lt;p /&gt;&lt;br /&gt;
&lt;b&gt;Sample attacker profile:&lt;/b&gt;&lt;br /&gt;
&lt;span class="orange"&gt;Basic&lt;/span&gt;: Attacker spending minimal effort; downloading free 'hacking' tools and running them with minimal attention
&lt;br /&gt;
&lt;span class="navy"&gt;Intermediate&lt;/span&gt;: A motivated attacker spending more time and resources with greater attention to detail and actively searching for a weakness
&lt;br /&gt;
&lt;span class="red"&gt;Advanced&lt;/span&gt;: A serious attacker with intent to harm or steal information assests
&lt;p /&gt;&lt;br /&gt;
&lt;b&gt;Security assurance profile:&lt;/b&gt;&lt;br /&gt;
&lt;span class="orange"&gt;Basic&lt;/span&gt;:  Minimal; relies on a limited set of tools to discover weaknesses
&lt;br /&gt;
&lt;span class="navy"&gt;Intermediate&lt;/span&gt;: Good; relies on running many tools with overlapping functions, specialty tools, tuned for bandwidth and latency conditions, and includes manual investigation, validation, and research into findings
&lt;br /&gt;
&lt;span class="red"&gt;Advanced&lt;/span&gt;: Excellent; goes beyond Intermediate to prove the existence of vulnerabilities, includes checking non-public domains for the existence of 0-day exploits
&lt;br /&gt;

</description>
      <pubDate>Tue, 19 Sep 2006 15:21:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:02e7642e-02ab-4df6-b9bc-c66aa29c2d21</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2006/09/19/competing-for-network-based-security-assessments</link>
      <category>security</category>
      <category>Audit</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>vulnerability</category>
      <category>security assessments</category>
      <category>penetration test</category>
      <category>scan</category>
    </item>
  </channel>
</rss>
