Re: Reporting aspect of pen-testing

From: Stephen de Vries (stephen_at_twisteddelight.org)
Date: 12/02/03

  • Next message: Keenen Milner: "RE: System Security Audits"
    Date: Mon, 1 Dec 2003 21:50:33 -0500 (EST)
    To: "TJ O'Grady" <tjogrady@flyingwithouta.net>
    
    

    TJ,

    Depending on the organisation, you are probably going to have different
    audiences for the pentesting report. It will be usefull for managers to
    be able to quickly understand what the business impact of the pentest are
    without getting into the details, while the sys admins and security staff
    would be keen to see all the gory details. I'd suggest the following
    layout:

    *Introduction
    *Objectives
    *Scope
       - What did you do, which system did you test, what tests did you omit etc.
    *Executive Summary
       - Summary of findings at a high level. Bare in mind that your reader
    is a manager and wants to know what the real risks are, try and use
    simple language (and mono-syllables ;-) )
       - Business impact of findings: what do these findings mean to the
    business? How and where can they lose money?
       - Recommendation: again high level, focus more on processes than on
    individual items. If their IIS server is full of holes, suggest a
    regular process of patching etc.

    *Methodology
       - Some more detail on the methodology you followed.
    *Technical Findings
       - A tabular list of each finding. This could include a finding number,
    vulnerability name, description, severity rating, references, fix
    information. Try and organise this so that it is usefull for the
    reader, e.g. Group according to business unit, or a long list according
    to severity.

    *Conclusion
       - What was the overall rating? How does this client compare to others
    in the same industry? Is this is kind of security you'd expect for
    their industry?

    *Appendix
    List relevant technical details like port scan results, screen shots that
    prove vulnerabilities, vuln scan results etc.

    Remember that the report is confidential information and distribution
    should be treated with care.

    cheers,
    Stephen

    > Hi folks,
    >
    > I am putting together a pen testing proposal as part of my final
    > Master's project. If it's good enough, it will lead to a full pen test
    > of a real network. This list has been very helpful with the technology
    > background, but the part I am stuck on right now is the reporting
    > piece. When a pen-test is complete, what do you include in the report?
    > How do you structure the information for business contacts, I imagine
    > raw data is often not helpful in many cases. Any hints or tips would
    > be greatly appreciated.
    >
    > Thank you,
    > TJ
    >
    >
    > ---------------------------------------------------------------------------
    > ----------------------------------------------------------------------------
    >

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Keenen Milner: "RE: System Security Audits"

    Relevant Pages

    • Re: Starting a Pen-Testing Career
      ... Perhaps my perceptions of the business are a bit naive, ... Buinsesses don't care about security and vulnerabilty and exposure. ... How else would they be able to provide such a report in isolation - ... written vulnerability scanner' to produce reports. ...
      (alt.computer.security)
    • Re: Starting a Pen-Testing Career
      ... How else would they be able to provide such a report in isolation - ... and making their business plans work to worry so much about security. ... they hire a pen-tester or ethical hacker to tell them the things ... informed as to how the vulnerabilities exisit, how they can be exploited and ...
      (alt.computer.security)
    • Re: OT ~ RatherGate Resurfaces
      ... it's right there in the report. ... MY point is that the Bastard Media only prints or brodcasts ... the way the business works. ... carried the story and one of these phantom power plants was supposed to be ...
      (rec.outdoors.rv-travel)
    • Re: OT ~ RatherGate Resurfaces
      ... it's right there in the report. ... MY point is that the Bastard Media only prints or brodcasts ... the way the business works. ... carried the story and one of these phantom power plants was supposed to be ...
      (rec.outdoors.rv-travel)
    • Re: Web Application Project - ReportViewer Control
      ... My project already contains business object classes that return datatables, ... not have to create new datasets for every report. ... option for 'new data source', or for 'show only data components'. ... How can I get the report to recognize the datasource in order to design it? ...
      (microsoft.public.dotnet.framework.aspnet)