19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

36<br />

Part I: Building the Foundation for Ethical Hacking<br />

If you’re an independent consultant or have a<br />

business with a team of ethical hackers, consider<br />

getting professional liability insurance<br />

(also known as errors and omissions insurance)<br />

from an agent who specializes in business<br />

Do you need insurance?<br />

Establishing Your Goals<br />

You can’t hit a target you can’t see. Your ethical hacking plan needs goals.<br />

The main goal of ethical hacking is to find vulnerabilities in your systems so<br />

you can make them more secure. You can then take this a step further:<br />

✓ Define more specific goals. Align these goals with your business objectives.<br />

What are you and the management trying to get from this process?<br />

What performance criteria will you use to ensure you’re getting the most<br />

out of your testing?<br />

✓ Create a specific schedule with start and end dates as well as the times<br />

your testing is to take place. These dates and times are critical components<br />

of your overall plan.<br />

Before you begin any ethical hacking, you absolutely, positively need everything<br />

in writing and approved. Document everything and involve management<br />

in this process. Your best ally in your ethical hacking efforts is a manager who<br />

supports what you’re doing.<br />

The following questions can start the ball rolling when you define the goals<br />

for your ethical hacking plan:<br />

✓ Does ethical hacking support the mission of the business and its IT<br />

and security departments?<br />

✓ What business goals are met by performing ethical hacking? These<br />

goals may include the following:<br />

• Prepping for the internationally accepted security standard of ISO/<br />

IEC 27002:2005<br />

• Working through Statement on Standards for Attestation<br />

Engagements (SSAE) 16 audits<br />

• Meeting federal regulations such as HIPAA, SOX, or PCI DSS<br />

• Meeting contractual requirements of clients or business partners<br />

• Maintaining the company’s image<br />

insurance coverage. This kind of insurance can<br />

be expensive but will be well worth the expense<br />

if something goes awry and you need protection.<br />

Many customers even require the insurance<br />

before they’ll hire you to do the work.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!