Penetration
Testing - Success Criteria
Success Criteria
We believe it is essential to determine the timing
and conditions to start and complete the penetration
test. That is why, no test vectors will be executed
outside of the agreed upon penetration testing timeframe.
Our ‘rules of behavior’ are developed with
predetermined success criteria in mind. An agreed-upon
success state is necessary to determine when the suggested
end conditions are met for the test. Once the success
criteria is accomplished, all penetration attempts are
promptly and safely terminated.
The client defines specific goals for the penetration
test. Some examples of goals include:
- Access to internal resources;
- Reading restricted files;
- Altering restricted files;
- Reading transaction data;
- Executing a program or transaction;
- Access to any user account;
- Access to supervisor privileges;
- Controlling network management systems; and
- Demonstrating ability to control resources.
SecureNet Solutions strongly believes that failure
to properly define conditions for terminating the penetration
test can result in unmet expectations, misunderstandings
about successful penetration of security, or, probably,
the worst possible outcome, a false sense of security.
Back |