Sunteți pe pagina 1din 60

DOCUMENTATION FORMS PENETRATION TESTS

FOR

he reports in this appendix will give you a good idea of what security testers do and how they should present findings to managers and IT personnel. The sample reports show how methodical a security tester must be and emphasize that nothing should be overlooked or assumed to be unimportant. Security testers must consider all factors that might affect the security of a business. The two reports in this appendix are sample documents shared by ISECOM. Few organizations give examples of documentation for a security test, so these reports will be extremely helpful. Some material in the reports might be beyond the scope of information covered in this book, but remember that you can delve into any areas in which you arent well versed. The first sample report is an executive summary usually given to management staff, who typically arent interested in all the details of a security test. Instead, they want a summary of important areas that they can read over quickly to get the bottom line. For these people, you need to emphasize what problems were found and how they can be fixed. The second sample is the technical report that would most likely be given to IT personnel. This type of report includes details of vulnerabilities and exploits as well as possible solutions for the identified problems. Clients who hire security professionals to assess their organizations want a report that details what was found and offers recommendations to help protect their resources. Documentationthe task most IT professionals hateis probably the most important part of a security professionals job. When a team is used to conduct a security test, the person most skilled in report writing should handle creating these reports to management and IT staff.

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

10

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

11

12

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

13

14

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

15

16

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

17

18

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

19

20

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

21

22

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

23

24

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

25

26

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

27

28

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

29

30

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

31

32

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

33

34

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

35

36

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

37

38

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

39

40

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

41

42

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

43

44

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

45

46

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

47

48

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

49

50

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

51

52

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

53

54

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

55

56

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

57

58

Documentation Forms for Penetration Tests

Documentation Forms for Penetration Tests

59

60

Documentation Forms for Penetration Tests

S-ar putea să vă placă și