Reporting aspect of pen-testing

From: TJ O'Grady (tjogrady_at_flyingwithouta.net)
Date: 11/30/03

  • Next message: Andy Cuff [Talisker]: "Re: Heavyweight Network Mapping Tools"
    Date: Sun, 30 Nov 2003 08:08:12 -0500
    To: <pen-test@securityfocus.com>
    
    

    Hi folks,

    I am putting together a pen testing proposal as part of my final
    Master's project. If it's good enough, it will lead to a full pen test
    of a real network. This list has been very helpful with the technology
    background, but the part I am stuck on right now is the reporting
    piece. When a pen-test is complete, what do you include in the report?
    How do you structure the information for business contacts, I imagine
    raw data is often not helpful in many cases. Any hints or tips would
    be greatly appreciated.

    Thank you,
    TJ

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Andy Cuff [Talisker]: "Re: Heavyweight Network Mapping Tools"

    Relevant Pages

    • Re: Theism and Deism (was Plague)
      ... raise the successful-prayer rate to 100% for Christians. ... >> Imagine that then thousands of people start reporting ... example of a situation in which skeptics would be convinced, ... I proposed far more people much more frequently reporting ...
      (uk.religion.christian)
    • Re: Basement tinkerers and inventors
      ... year-to-date and yearly requirements for reporting. ... that a complete time record involved from one to six raw ... can possibly NOT have an edit-file update function, ... to retain all the raw data and reiterate the edit/assembly/resolution ...
      (comp.lang.cobol)
    • Re: OT - Here we go again
      ... Just imagine his bravery in reporting for duty day after day in the ...
      (rec.outdoors.rv-travel)
    • Re: Delphi 2007 more Flakey than 2006?
      ... I can't imagine anyone paying me spending>24 hours with reporting a bug to CG. ... downloading+installing VM, buying+installing windows, downloading+installing delphi, then trying to reproduce a bug, reporting the bug to CG, and then leave the VM set as it is for a couple of months in case the report gets oppened and someone needs more information. ...
      (borland.public.delphi.non-technical)
    • Re: In-memory dataset
      ... > databases a lot of years but I can't imagine - what is the task where I need ... I use in-memory datasets for all reporting. ... I also will use them if I need to store some information temporarily loaded from an on-disk file ...
      (borland.public.delphi.thirdpartytools.general)