Continuous Full-Cycle Testing
4 slides · 2 min read · Domain 6
Continuous Full-Cycle Testing
Pen testing as an event is a point-in-time activity, reflecting the results of one set of tests against the organization's infrastructure.
While helpful in giving assurance of the effectiveness of the organization's controls, the real world is not as static or forgiving. The environment is constantly changing, and the threats evolve rapidly.
The evolution of the threat has resulted in a number of continuous testing approaches. These approaches complement the frameworks, which expect continuous monitoring of risk and expect organizations to respond to risk in a timely manner. Breach attack simulation tools automate the testing activities so that they can be performed continuously against the organization's infrastructure. Coupled with threat intelligence information that tracks active threats and integrated with the organization's change management activities, breach attack simulation tools can provide a different level of assurance than traditional penetration testing.
Chaos engineering provides another avenue to ensuring the organization can respond to compromise. This approach forces production systems to fail, and then tracks the detection, incident response and recovery activities.
The parts of the organization, which are expected to respond to the failure, are not informed of the test in advance and treat the failure as if it were an actual attack, not a simulation.
This is not an approach to be considered lightly. Many systems are not engineered with the resilience necessary to sustain production shutdown without significant cost to the organization.
No single approach will provide an absolute guarantee of the effectiveness of an organization's control environment.
And in most organizations, people have not been acculturated nor trained to deal with emergency situations.
Further, the approach does not simulate the actions of a true attacker, in that the disruptions are scripted by people with internal knowledge.
Selecting the right approaches to assessing the security controls in an organization requires consideration of the organization's business goals, technical capabilities, compliance obligations and maturity.
