SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> IT Workplace >> Human Resources Issues

Penetration testing: dead in 2009?

Penetration testing: dead in 2009?

By:  Bill Brenner  On: 22 Dec 2008 For: CSO (US)(NA) 

Is the practice of penetration testing headed the way of desktop publishing and the PDA? Well probably not dead as is dead and gone, it just won't be as cool as it was before. Here's a look at the possible reincarnation of penetration testing

Penetration testing: Security experts mention it all the time as one of the essential tools of defense-in-depth. Companies have raked in the dough selling the service and the tools for years.

But is it possible that penetration testing -- the art of probing company networks in search of exploitable security holes that can then be fixed -- is an idea whose time is about to expire?

If you ask Brian Chess, co-founder and chief scientist of business software assurance (BSA) vendor Fortify Software Inc., the answer is yes.

"Death sounds rather gloomy, but stuff in high tech dies all the time," Chess said in an interview Tuesday. "Desktop publishing? Dead -- but not gone. Personal Digital Assistant (PDA)? Many of the concepts are still with us, but the PDA is dead."

Penetration testing is headed for a similar fate, he said. The concept as we know it is on its death bed, waiting to die and come back as something else. That doesn't mean pen testers will suddenly be unemployed, he said. It's just that they "won't be as cool" as they've been in more recent years.

Customers are clamoring more for preventative tools than tools that simply find the weaknesses that already exist, he said. They want to prevent holes from opening in the first place.

"Death doesn't mean it goes away, it means it transforms. Pen testing will be reborn in the area of production monitoring and measurement," Chess said. "The goal won't be that failure is found and must be fixed. The goal is that failures will become a much rarer event."

Naturally, security practitioners who swear by pen testing as a critical component of a layered security program are reacting to his hypothesis with more than a little skepticism.

Jennifer Jabbusch, CISO at Carolina Advanced Digital Inc. in the Raleigh-Durham area of North Carolina, took issue with Chess' basic premise that penetration testing will become a component of monitoring and measuring.

"Pen testing will continue," she said in an exchange over the Twitter social networking site. "Monitoring and measuring is not pen testing. It's what you do after pen testing."

She also faulted the example of desktop publishing being a dead art, saying, "Desktop publishing isn't dead. In fact, it's grown. Now you can design on your desktop and deliver via the Internet for printing at FedEx/ Kinkos."

Others agree penetration will continue, but don't necessarily think Chess' position is all that off the mark.

Security resource

Sign up for our Newsletters












Print |  Views: 2113   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Bill Brenner Bill Brenner is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

RealPlayer Version 11 may contain exploit code
RealPlayer Version 11 may contain exploit codeA Russian security company discovers what is called a stack overflow bug that could seriously affect users of the popular multimedia software. US-CERT investigates the scope of the problem
Safety by disclosure
Safety by disclosureIs full, public disclosure of security vulnerabilities a better strategy than trying to keep them secret?
Security and reliability aren’t islands anymore
Security and reliability aren’t islands anymoreThere is a difference between a probable event and a deliberate attack, but as network techologies evolve, those differences mean less and less. Take a closer look at the terminology behind IT safeguards
A simple way to improve IT usability: the flanker test
every time i get my eyes checked i’m just waiting for bad news. it doesn’t help that every time i visit the optometrist, they seem to have installed a new piece

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.