It seems that rarely a month goes past without the all too familiar headlines, such as those above, dominating our media channels. Public perception around information security (and the processes by which government and suppliers handle or share data) has never been so low.
In response to these security lapses, the UK Government released its final report on Data Handling Procedures in Government in June 2008. One of key recommendations was the introduction of ‘new rules on the use of protective measures, such as encryption and penetration testing of systems Ethical Hacking
The UK penetration testing market has grown greatly in recent years, with a number of organisations in the industry offering a wide range of services differing widely in terms of the benefits, cost and quality of the service. But just how far can penetration testing help reduce failings in information security This article offers some thoughts on what considerations should be taken to ensure organisations take a comprehensive and responsible approach to penetration testing.
There are many factors that influence the requirement for the penetration testing of a service or facility, and many variables contribute to the outcome of a test. It is first important to obtain a balanced view of the risk, value and justification of the penetration testing process; the requirement for testing may be as a result of a code of connection requirement (CoCo) or as a result of an independent risk assessment.