SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> IT Workplace >> Human Resources Issues

Penetration testing: dead in 2009?

Penetration testing: dead in 2009?

By:  Bill Brenner  On: 22 Dec 2008 For: CSO (US)(NA) 

Is the practice of penetration testing headed the way of desktop publishing and the PDA? Well probably not dead as is dead and gone, it just won't be as cool as it was before. Here's a look at the possible reincarnation of penetration testing

Assessment is the key to plugging security holes

Max Caceres, director of research and development at Matasano Security in New York, said he can understand the perspective of people who want penetration testing to be part of something larger. "I can totally see where his customers are coming from," Caceres said. "All things being equal, preventing holes from even existing is a much more interesting approach than riding the find-report-hope-somebody-fixes-it hamster wheel."

But, he added, Chess' prediction may be more of an imagined utopia than a real alternative. "We have been findings bugs for a while, the most common problems are well understood and documented, yet we keep deploying vulnerable apps," he said. "If we believe true perfection is unattainable -- and I do, particularly for application development, we have yet to invent the tool that produces bug-free code -- then apps will always have bugs that need fixing, and some of them will be security related."

And that's where penetration testing will remain valuable, he said.

Kevin Riggins, a senior information security analyst for a company in the Des Moines, Iowa, area, said it's hard to argue with Chess' premise that the goal should be fewer failures. But he doesn't believe that sentiment has anything to do with the need for or the use of penetration testing. Furthermore, he said, echoing Jabbusch, production monitoring and measuring and penetration testing do not address the same issue.

"The first measures the availability and effectiveness of your production environment," he said in exchanges via Twitter and e-mail. "The second measures its ability to resist intrusion or attack. They are not the same and you can't get from one to the other by transformation."

A better argument for the death of penetration testing is that there will always be issues found, some of which can not be fixed or effectively mitigated, he added. Therefore, what is the real value to the organization in performing this type of test?

"Don't get me wrong, I don't subscribe to this argument either," Riggins said. In the final analysis, he said, security pros can't stop performing penetration tests until the current compliance requirements are removed. That's not happening any time soon.

"Penetration tests and vulnerability scans help us find where our processes, procedures, and standards might need work," he said.

CSO (US)










Sign up for our Newsletters












Print |  Views: 2323   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Bill Brenner Bill Brenner is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

RealPlayer Version 11 may contain exploit code
RealPlayer Version 11 may contain exploit codeA Russian security company discovers what is called a stack overflow bug that could seriously affect users of the popular multimedia software. US-CERT investigates the scope of the problem
Safety by disclosure
Safety by disclosureIs full, public disclosure of security vulnerabilities a better strategy than trying to keep them secret?
Security and reliability aren’t islands anymore
Security and reliability aren’t islands anymoreThere is a difference between a probable event and a deliberate attack, but as network techologies evolve, those differences mean less and less. Take a closer look at the terminology behind IT safeguards
A simple way to improve IT usability: the flanker test
every time i get my eyes checked i’m just waiting for bad news. it doesn’t help that every time i visit the optometrist, they seem to have installed a new piece
blog comments powered by Disqus