{"title":"A study on penetration testing process and tools","authors":"Hessa Mohammed Zaher Al Shebli, B. Beheshti","doi":"10.1109/LISAT.2018.8378035","DOIUrl":null,"url":null,"abstract":"Information is more vulnerable than ever; and every technological advance raises new security threat that requires new security solutions. Penetration testing is conducted to evaluate the security of an IT infrastructure by safely exposing its vulnerabilities. It also helps in assessing the efficiency of the defense mechanisms tools and policy in place. The Penetration testing is conducted regularly to identify risks and manage them to achieve higher security standards. In this paper we discuss the importance of penetration testing, factors and components considered while conducting a penetration test, we present a survey of tools and procedures followed, role of penetration test while implementing in the IT governance in an organisation and finally the professional ethics to be possessed by the team involved in penetration test.","PeriodicalId":161643,"journal":{"name":"2018 IEEE Long Island Systems, Applications and Technology Conference (LISAT)","volume":"124 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-05-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"46","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE Long Island Systems, Applications and Technology Conference (LISAT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/LISAT.2018.8378035","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 46
Abstract
Information is more vulnerable than ever; and every technological advance raises new security threat that requires new security solutions. Penetration testing is conducted to evaluate the security of an IT infrastructure by safely exposing its vulnerabilities. It also helps in assessing the efficiency of the defense mechanisms tools and policy in place. The Penetration testing is conducted regularly to identify risks and manage them to achieve higher security standards. In this paper we discuss the importance of penetration testing, factors and components considered while conducting a penetration test, we present a survey of tools and procedures followed, role of penetration test while implementing in the IT governance in an organisation and finally the professional ethics to be possessed by the team involved in penetration test.