← Back to courses

Information Security Management: Module 6

Penetration Testing

Learn the concepts and fundamentals of pen testing.

Estimated reading time

12 minutes

What is penetration testing?

Penetration testing, simply known as pen testing, is a manually executed, offensive cybersecurity test conducted by an organisation to identify existing vulnerabilities and flaws in a information system's security. This is done so that the existing security's threat detection and response can be improved. They are also a point-in-time assessment, so they only identify vulnerabilities when the test is conducted.

Types of pen testing

In whitebox testing, the conductors of the test have complete information of the system. It is often conducted to validate how effective a control is against threats and vulnerabilties.

In blackbox testing, the conductors of the test do not know what the system does. It is often used to simulate actual cyberattacks. However, this method may not allow all vulnerabilities to be identified in the test.

One reason why these tests are conducted is to identify vulnerabilities in a niche web or mobile application. The findings should also supply essential feedback to improve developers' coding practices. Another one could be to conduct scenario-driven testing to identify vulnerabilities that could emerge from it. Simulating such tests with actual incident data can be useful to inform scenarios and prepare the system for a similar situation. It could also be done to test incident detection and response times, which can be performed with responders being aware of what will happen or as tests where responders will not know how the system's security will be attacked.

Typical pen testing steps

  1. Initial engagement
  2. Scoping
  3. Testing
  4. Reporting
  5. Following up

Initial engagement

According to Rhodes, the conductors of the test must have the right skills and have the proper experience to execute it. The requirements and the context of the test have to clearly specified, especially for uncommon or complex systems like SAP.

Scoping

In this step, all stakeholders involved need to be identified. This includes risk owners, service owners, technical staff and at least one person who can conduct the pen test.

Each participant must contribute to the scope discussion.

  1. Risk and service owners should highlight areas of concern
  2. Technical staff should outline the technical boundaries of the system to be tested
  3. The pen test team should identify the type of testing to use to get a complete idea of the vulnerability of the target

Specific times when testing should happen and systems excluded from testing should be addressed and confirmed. Systems that have to be tested in a particular way should also be addressed.

The discussion must produce an output in the form of an engagement plan, which should include

  1. Boundaries of testing, both technical and physical
  2. Types of testing that will be conducted
  3. Time frame and time constraints on testing and reporting
  4. Needs of the pen test team
  5. Compliance requirements
  6. Reporting requirements

Testing

This is the stage where testing is executed by the team. There are some important aspects to take note of while testing.

  1. The pen test team and the client should remain in communication, in case testing goes wrong and affects other systems
  2. Test team should know how to escalate critical issues
  3. Barriers to effective testing must be reported and resolved as soon as possible
  4. Changes in scope should be acknowledged by all parties, and these changes should be resolved and recorded

Reporting

A draft is sent and reviewed by the most important stakeholders before a report is produced. In this phase, the pen test team needs to be level-headed and diplomatic, so they should not blame people. Collaboration and maintaining positivity is important to obtain the best results for the report.

Following up

The pen test report is required to analysed so that it aligns with the organisational context, the organisation's objectives and the business' impacts. Afterwards, treatment plans can be created based on these findings.

Sources

Rhodes, A. (2023). IFN541 Information Security Management: Vulnerability Management. [Presentation]. Canvas.

Midpoint Assessment

See how much you know about Modules 1-6 of Information Security Management so far.

Previous Next