Download Hacking For Dummies

Transcript
Chapter 19
Managing Security Changes
In This Chapter
Automating tasks
Watching for misbehavior
Outsourcing testing
Keeping security on everyone’s mind
I
nformation security is an ongoing process that must be managed effectively
to be successful. This goes beyond applying patches and hardening systems
every so often. Performing your ethical hacking tests again and again is critical;
information security threats and vulnerabilities constantly emerge. Combine
this with the fact that ethical hacking tests are just a snapshot in time view of
your overall information security, so you have to perform your tests on an
ongoing basis to keep up with the latest security issues.
You need to consider a few key issues in your ongoing efforts, such as automating some of the testing, monitoring for malicious use, and even outsourcing
some or all of your ethical hacking and security services. In this chapter, I
cover the critical issues that you can consider to help ensure long-term success in your security efforts.
Automating the Ethical Hacking Process
The ethical hacking tests that can be automated are covered in this book:
Port scans
Password-cracking tests
Vulnerability-assessment tests
You’ve got to have the right tools to automate tests:
Some commercial tools can set up ongoing assessments and create nice
reports for you without any hands-on intervention — just a little setup
and scheduling time up front. This is why I like many of the commercial