Skip to main content

Penetration testing

How to get the most from penetration testing





Note

If you have a particular scenario that requires additional assurance, a specifically targeted penetration test may be a good way to obtain that assurance. A suitably qualified penetration testing team will be able to guide you through the selection and scoping process required in this case.

Your testing regime

It's critically important to note that a planned penetration test doesn't mean your normal testing regime should cease to include security tests on the target system. Functional testing of security controls should still occur.

Assessing whether defined security controls are functioning is not a valuable use of penetration testing resources.

A functional testing plan should always include positive tests (such as 'The logon box comes up every time you try to log in and you aren't just allowed in').

Negative testing may be included in your functional testing plan where the skills to perform it are available within your organisation (for example, verifying that 'You can't log in without the correct password').


Published

Reviewed

Version

1.0