Monday, 15 April 2013

difference between Vulnerability Assessment and Penetration Testing


  • A Vulnerability Analysis answers the question: “What are the present Vulnerabilities and how do we fix them?”
  •  A Penetration Testing simply answers the questions: “Can any External Attacker or Internal Intruder break-in and what can they attain?”
  • Vulnerability Analysis is the process of identifying vulnerabilities on a network .
  •  Penetration Testingis focused on actually gaining unauthorized access to the tested systems and using that access to the network or data, as directed by the client.
 
Penetration Testing consists of a Vulnerability Analysis, but it goes one step ahead where in you will be evaluating the security of the system by simulating an attack usually done by a Malicious Hacker.

Sunday, 14 April 2013

policy ,standard, guidelines & procedure


·         Policy:
->Outlines the security roles and responsibilities.
->defines the scope of the information need to be protected.
->provide a high level description of control that must be in place to protect information.
->In addition it should make preference to the standard and guidelines that support it.
->it should make preference to the standard and guidelines that support it.
->should be produced by senior management.

·         Standard:
->are low level mandatory controls that helps, enforce & support mandatory control.

·         Guidelines:
->consists of recommended non-mandatory controls that helps supports standard and served as references when no applicable standard is in place

·         Procedure:
->consists of step-by-step instruction to assist worker in implementing various policy ,standard & guidelines.