Re: Penetration testing scope/outline

From: Nathan Sportsman (nathan@praetoriansolutions.com)
Date: Tue Oct 05 2004 - 12:56:48 EDT


You can use the OSSTMM as a baseline and then customize and reduce
according to the scope of your project.

http://isecom.securenetltd.com/osstmm.en.2.1.pdf

Make sure that the scope encompassing the project is agreed by both you
and the client through an SLA.

If you need an example of a post report, let me know and I'll be happy to
send you one that we use at Praetorian.

Good Luck,
Nathan Sportsman
Praetorian Security Solutions

> Anyone have any documents they are willing to share on the scope of work
> for a pen-test? I have looked online but was unable to find any available
> documentation. If anyone could provide me with a some links or
> documentation outlining a pen-test/network audit it would be greatly
> appreciated.
>
> ------------------------------------------------------------------------------
> Internet Security Systems. - Keeping You Ahead of the Threat
>
> When business losses are measured in seconds, Internet threats must be
> stopped before they impact your network. To learn how Internet Security
> Systems keeps organizations ahead of the threat with preemptive intrusion
> prevention, download the new whitepaper, Defining the Rules of Preemptive
> Protection, and end your reliance on reactive security technology.
>
> http://www.securityfocus.com/sponsor/ISS_pen-test_041001
> -------------------------------------------------------------------------------
>
>

------------------------------------------------------------------------------
Internet Security Systems. - Keeping You Ahead of the Threat

When business losses are measured in seconds, Internet threats must be stopped before they impact your network. To learn how Internet Security Systems keeps organizations ahead of the threat with preemptive intrusion prevention, download the new whitepaper, Defining the Rules of Preemptive Protection, and end your reliance on reactive security technology.

http://www.securityfocus.com/sponsor/ISS_pen-test_041001
-------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:54:07 EDT