19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

In This Chapter<br />

Chapter 16<br />

Reporting Your Results<br />

▶ Bringing your test data together<br />

▶ Categorizing vulnerabilities you discover<br />

▶ Documenting and presenting the results<br />

I f you’re wishing for a break after testing, now isn’t the time to rest on your<br />

laurels. The reporting phase of your ethical hacking is one of the most<br />

critical pieces. The last thing you want to do is to run your tests, find security<br />

problems, and leave it at that. Put your time and effort to good use by thoroughly<br />

analyzing and documenting what you find to ensure that security vulnerabilities<br />

are eliminated and your information is more secure as a result.<br />

Reporting is an essential element of the ongoing vigilance that information<br />

security and risk management requires.<br />

Ethical hacking reporting includes sifting through all your findings to determine<br />

which vulnerabilities need to be addressed and which ones don’t really<br />

matter. Reporting also includes briefing management or your client on the<br />

various security issues you find, as well as giving specific recommendations<br />

for making improvements. You share the information you’ve gathered and<br />

give the other parties guidance on where to go from there. Reporting also<br />

shows that the time, effort, and money invested in the ethical hacking tests<br />

were put to good use.<br />

Pulling the Results Together<br />

When you have gobs of test data — from screenshots and manual observations<br />

you documented to detailed reports generated by the various vulnerability<br />

scanners you used — what do you do with it all? You need to go<br />

through your documentation with a fine-toothed comb and highlight all the<br />

areas that stand out. Base your decisions on the following:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!