Ethical Penetration Testing
Ethical penetration testing simulates real-world attacks, exposes vulnerabilities, verifies defenses, and guides remediation.
4 slides · 3 min read · Domain 6
Penetration testing simulates the actions of a threat actor using information the threat actor is likely to have available. This form of testing is a controlled process, with clearly defined rules of engagement (RoE), which detail the circumstances under which the penetration is to be attempted. This approach to testing is useful in determining if an organization's controls are effective, but improperly conducted, presents a significant risk to the organization's operations, systems, and reputation. The definition of the RoE and the authorization by the organization is always required for the penetration tester.
An RoE should also specify the limits of liability that the penetration testers have, if any, in working on a contract service provider basis with the system's owners.
It must be stressed that without a signed contract in place, penetration testers are at risk of being found in violation of criminal and civil laws in many different jurisdictions. Testers can also be held liable for any disruptions that their testing causes to the organization under test. In sum, the ethical penetration tester is a contractually legal penetration tester.
Many security professionals and
Ethical penetration testing has increasingly communities prefer to call this ethical been defined by compliance frameworks as part of best practice when evaluating the penetration testing. This explicitly links the planning and conduct of the testing to the effectiveness of the organization's security contractual, legal, and ethical basis of the practices. For example, both NIST's Risk Management Framework and the SOC 2 contractual agreement between the testers and the systems owners, which is reflected
Type 2 report highlight this practice. in their RoE. After all, sophisticated The tester is given limited information and attackers use many of the same penetration is not knowledgeable of the test's technical test strategies and techniques, yet clearly details. In some cases, the test is doubletheir intention makes their activities blind, where the organization's team unethical and probably illegal. Ethical charged with protecting the infrastructure testers are bound by a code that requires is not made aware of the activities of the them to keep their activities and findings penetration tester. While this allows the confidential unless the contracting party organization to exercise its detection gives written consent. This is in addition and incident response processes, it is not to contractually enforceable nondisclosure without risk. The individuals authorizing agreements.
the test must take measures to ensure deconfliction of the tester's activities in the event the defenders uncover the test.
Another important aspect of penetration testing is the scope of the exercise. The test's objectives will impact its scope. For example, the Payment Card Industry Data Security Standard (PCI DSS) mandates penetration testing, and it specifically requires testing of the network and application layers within the cardholder data environment. Other scenarios may include a wireless component, social engineering techniques, or physical intrusion of facilities.
Depending on the objectives (e.g., response readiness), various teams may be involved in the exercise of emulating potential attacks and exploitation opportunities. Blue teams, red teams, and purple teams are the terms used in the industry. Blue teams represent the defenders in an operational environment (i.e., internal security team). They defend against red teams, a group of mock attackers. The purple team aims to maximize the effectiveness of the blue and red teams by noting the gaps in security defenses and recommending strategies to enhance the security posture.
