Ethical Penetration Testing - Basic Methodology

6 slides · 2 min read · Domain 6

Ethical Penetration Testing - Basic Methodology

Ethical penetration testing activities are performed in a predictable, defined fashion, which is controlled and specified by a lawful and legally binding contract between the penetration tester and the owners or responsible executive officers of the system under test.

The methodology must be followed rigorously, as it directly affects the evaluation of the risks associated with the testing activities.

Chartering

Once the organization has determined that a penetration test should be conducted, Rules of Engagement (RoE) are drafted, which define the scope, methods and constraints associated with the penetration test activities. The RoE will be subjected to formal risk assessment by the organization.

If the assessment is being conducted by a third party, the RoE will be incorporated into the contract between the two entities that authorizes the testing. The RoE will also define the individuals in the organization responsible for authorizing the penetration testing, incident reporting procedures and any legal constraints to the penetration testing.

Discovery

Consistent with the RoE, the testers will identify the potential breadth of the environment. This could include a variety of reconnaissance activities, which map the potential systems in the subject environment.

This step may be unnecessary if the RoE explicitly defines the individual systems or environments to be tested.

Scanning

Once a system has been identified as being in the scope of the test, it will be subjected to scanning to identify any potential weaknesses.

Exploitation

The exploit is delivered, and the tester documents the results of the compromise. Rigorous adherence to the RoE is necessary, as the penetration test may have provided an opportunity for real damage to the targeted system.

The weaknesses will be further researched to fully "fingerprint" the system so that exploits targeting that particular system can be properly crafted.

In withdrawing from the compromised system, the tester is responsible to ensure the compromise does not increase the possibility that a malicious actor may further exploit the system.

Reporting

The activities performed by the tester are compiled with particular attention to the results of the penetration test. An executive summary is generally prepared and addresses any recommendations to address the exploited weaknesses.

All materials related to the test are returned to the client, to include any credentials obtained during the course of the test.

Test this domain