http://riskmanagementinsight.com/riskanalysis/?p=532
Very interesting post over at Riskanalysis.is on penetration testing and what it may turn in to.
There's some good reasons to do penetration testing in there and I'd agree that targeted testing to prove or disprove theories about the security environment is a smart way to use penetration testing. My feeling though is that, at the moment, only more mature security organisations will be in a good place to use it in that way.
For most companies there are other reasons why penetration testing is going to remain on the menu in its current form
So whilst I'd definitely like to see smarter use of penetration tests, I don't think that testing as it's used currently is going to go out of fashion any time soon.
Posted by rorym at December 10, 2008 8:20 PM | TrackBack