Re: Business justification for pentesting

rmeijer_at_xs4all.nl
Date: 08/31/05

  • Next message: Flavio A. Fernandez: "Re: Tcleo keylogger v0.3 released"
    Date: Wed, 31 Aug 2005 14:46:31 +0200 (CEST)
    To: sectraq@gmail.com
    
    

    > hi all,
    >
    > a few classic question that i would appriciate any answers for.
    > 1- i would like to briefly know how to quantify information assets. In
    > other words, i hear a pentester say: if a hacker breaks in ur network, u
    > will loose up to 40000$ for example. how can he come up with such figures?

    This is not something for a pentester to be concerned with in most cases.
    The value of assets should be evaluated only in the context of a risk
    assesment done by a skilled statistician, not by a skilled infosec
    technisian.

    In the past I've tried to bring together some of the
    statistician/technisian/management infosec issues in a whitepaper on
    risk assesment and incident response, but it has turend out to be
    close to impossible to bring together these distinct views on infosec
    in a way that not everyone thinks: 'that is the other guys specialty'.
    You may wish to check out 'Security Incident Policy Enforcement' at
    isecom.org to get somewhat of a grasp on this. The document focusses
    on risk assesment in a IR context, but much of it can be seen in a
    wider scope also.

    > 2- are there any other means to justify pentesting for management except
    > for $$$?

    Pentesting is just one of a wide range of security measures, there are
    three ways to justify any security measures:

    1 The projected financial footprint of the diverted risk is substantialy
       higher than the projected cost of the security measure.
    2 The potential financial footprint of diverted risk would be very high
       and the projected cost of the measure not very substancial.
    3) There is insufficient data to asses if either 1 or 2 is true, and the
       measure could supply this data.

    As you see, only the third does not directly involve money as argument, but
    I dont think pentesting could be categorized in that section very often.

    > 3- are there any official statistics, figures etc. for justifying
    > pentesting. ther more official it is the better.

    In my research I have found no sign of any statistic information with
    any usefull span that crosses company borders. This is very unfortunate,
    as it makes risk assesments yield rather high spreads in their risk
    densities, that makes building solid pollicies from them very dificult.
    I personaly believe that this lack of statistics could be responsible for
    a very large portion of overall infosec incident costs.

    > 4- any other information you guys might find helpful in justifying a
    > pentest would be appriciated.
    >
    > thnx in advance for ur help.
    >
    > T.N
    >
    >


  • Next message: Flavio A. Fernandez: "Re: Tcleo keylogger v0.3 released"

    Relevant Pages

    • RE: Business justification for pentesting
      ... I agree with the previous discussion on how to justify to the business the ... Additionally it is a good idea to use something like Octave Risk assessment ... Senior Security Consultant ... Pentesting is just one of a wide range of security measures, ...
      (Pen-Test)
    • RE: Why Easy To Use Software Is Putting You At Risk
      ... I do agree that the additions and changes to Solarius will make it more secure and that this is good. ... Why Easy To Use Software Is Putting You At Risk ... instead I would say that the view that security is ... Four Construction Workers Died after Crane Collapse in Toledo, ...
      (Security-Basics)
    • RE: Why Easy To Use Software Is Putting You At Risk
      ... Why Easy To Use Software Is Putting You At Risk ... Four Construction Workers Died after Crane Collapse in Toledo, ... The first issue to address is yes you found a vulnerability and it was ... a Security Discussion board, that is what we do here. ...
      (Security-Basics)
    • More food for thought
      ... Basic Risk Analysis ... I have taken a position that the professional security community in general ... has and will continue to fail because they are operating under the same ... storing those backups safely offsite in a secure location on a daily basis. ...
      (comp.security.misc)
    • More food for thought
      ... Basic Risk Analysis ... I have taken a position that the professional security community in general ... has and will continue to fail because they are operating under the same ... storing those backups safely offsite in a secure location on a daily basis. ...
      (comp.os.ms-windows.nt.admin.security)