日韩性视频-久久久蜜桃-www中文字幕-在线中文字幕av-亚洲欧美一区二区三区四区-撸久久-香蕉视频一区-久久无码精品丰满人妻-国产高潮av-激情福利社-日韩av网址大全-国产精品久久999-日本五十路在线-性欧美在线-久久99精品波多结衣一区-男女午夜免费视频-黑人极品ⅴideos精品欧美棵-人人妻人人澡人人爽精品欧美一区-日韩一区在线看-欧美a级在线免费观看

歡迎訪問 生活随笔!

生活随笔

當前位置: 首頁 > 编程资源 > 综合教程 >内容正文

综合教程

Penetration Test

發布時間:2023/12/13 综合教程 32 生活家
生活随笔 收集整理的這篇文章主要介紹了 Penetration Test 小編覺得挺不錯的,現在分享給大家,幫大家做個參考.

Writing Reports

PEN TEST REPORT

Communicate findings AND recommendations
Primary recommendations
Only change to make your points
Digest of all activities and conclusions

Some conclusions are drawn during tests
Some result from post-test analysis

Examples:

http://www.pentest-standard.org/index.php/Reporting

https://github.com/juliocesarfort/public-pentesting-reports

http://www.offensive-security.com/reports/sample-penetration-testing-report.pdf

https://www.niiconsulting.com/services/security-assessment/NII_Sample_PT_Report.pdf

TIPS FOR WRITING A REPORT

Tell your story
Know your audience(s)

Executive 1-page summary
Technical/management
Motivation - audit?

Leave the reader with a call to action

Include steps to fix the issues

Your report will be your voice after you leave
Try to answer any questions that may arise

What did you do?
Why did you make the choices you made?
What did you find, and how did your findings affect your conclusions?

After settling on format, you need data
Mostly presentation and summary of data
Collect data

Transform as needed into a common format
Don't spend too much time on this, but try to harmonize data format

Use tools like MS Excel

Easier to read and analyze

COMMON SECTIONS

Executive summary

1 page max - High level summary
Targeted at executives - few details
State the test goals and general findings

Methodology

Your approach to the overall test activities
Tools and techniques
Why you did what you did

And why you didn't do more

Findings and remediation

Ranked list(more details than Executive summary)

What you found (important findings first)
What you recommend the client does - provide options as appropriate

Metrics and measures

Details of what you found
How you assessed each finding
Risk rating

BEST PRACTICES

Risk appetite

Amount of risk client is willing to accept
Tone of the entire report is based on the company's appetite for risk
Risk appetite statement should appear in the report introduction

Report storage

Reports should become part of the organization's document repository
Used as input for future pen tests and other assessments
Security policy should state how long reports are kept

Report handling and disposition

Security policy should state how assessment reports are stored
At the end of life, how are reports disposed of?

QUICK REVIEW

The Pen Test report is your best opportunity to leave a lasting message
Start writing your report early in the testing project
Write to your audiences(executive vs. technical)
Provide a definite "call to action" with remediation recommendations

相信未來 - 該面對的絕不逃避,該執著的永不怨悔,該舍棄的不再留念,該珍惜的好好把握。

總結

以上是生活随笔為你收集整理的Penetration Test的全部內容,希望文章能夠幫你解決所遇到的問題。

如果覺得生活随笔網站內容還不錯,歡迎將生活随笔推薦給好友。