Security Test Definitions

From: Patrick Fröger (patrick.froeger@web.de)
Date: Mon May 15 2006 - 08:38:17 EDT


Hello list members,

at the moment, i'm writing my diploma thesis in the field of penetration
testing.
i wonder if there exist some 'official' definitions about the different
types of tests one can do. i know that every pen-tester/company has his
own definitions of what they call a "penetration test", "security
assessment", "security review", "security audit", "application audit"
etc... but are there some standards that define the different types of
security tests?
i had a look at ISSAF and OSSTMM, but neither come up with definitions
of tests...

Regards,

Patrick

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:58 EDT