Linux Today: Linux News On Internet Time.

More on LinuxToday

eBCVG: Automated Penetration Testing--False Sense of Security

Aug 10, 2004, 08:30 (0 Talkback[s])
(Other stories by Jane Frankland)

[ Thanks to Scott for this link. ]

"The security industry has matured quickly over the past few years with penetration testing becoming one of the norms for organisations adopting best-practice processes. Loosely defined as the process of actively assessing an organisations security measures and completely reliant on consultancy services, security manufacturers have been eager to bridge the gap between product and service and more importantly to reap the benefits of additional profits. Not surprisingly, we have seen the emergence of the automated penetration test with a number of providers springing up to fill the sector.

"The main advantages cited by these providers are that they are faster and significantly cheaper than traditional security assessments performed by consultants using a range of tools. With such promises, it has been little wonder that the security industry has seen a new trend evolving and a movement away from the traditional approach to the automated one has become apparent..."

Complete Story

Related Stories: