Deployment: Penetration Testing (PT)

The overall goal of the Penetration Testing practice is quality control. Those performing penetration testing must ensure the detection and correction of security defects. The SSG must enforce adherence to standards and the reuse of approved security features.

DEPLOYMENT: PENETRATION TESTING
Vulnerabilities in final configuration, feeds to defect management and mitigation.
  Objective Activity Level
PT1.1 demonstrate that your organization's code needs help too use external pen testers to find problems 1
PT1.2 fix what you find to show real progress feed results to defect management/mitigation (T: config/vuln mgmt)
PT2.1 create internal capability use pen testing tools internally 2
PT2.2 promote deeper analysis provide pen testers with all available information (T: AA & code review)
PT2.3 sanity check constantly periodic scheduled pen tests for app coverage
PT3.1 keep up with edge of attacker's perspective use external pen testers to perform deep dive (one-off bugs/fresh thinking) 3
PT3.2 automate for efficiency without losing depth have SSG customize pen testing (tools and scripts)
one

PT Level 1: Remediate penetration testing results. Managers and the SSG must initiate the penetration testing process, with internal or external resources. Managers and the SSG must ensure that deficiencies discovered are fixed and that everyone is made of aware of progress.

two

PT Level 2: Schedule regular penetration testing by informed, internal penetration testers. The SSG must create an internal penetration testing capability that is periodically applied to all applications. The SSG must share its security knowledge and testing results with all penetration testers.

three

PT Level 3: Carry out deep-dive penetration testing. Managers must ensure that the organization's penetration testing knowledge keeps pace with advances by attackers. The SSG must take advantage of organizational knowledge to customize penetration testing tools.