Find White Papers
Home
About Us
List Your Papers
    
> Core Security > Learn More About Penetration Testing Software: Taking the Guesswork Out of Vulnerability Management

Learn More About Penetration Testing Software: Taking the Guesswork Out of Vulnerability Management

White Paper Published By: Core Security

This IDC white paper examines key trends in the vulnerability management and assessment (VA&M) market and identifies the value of penetration testing as part of a comprehensive security methodology.



Tags : 
vulnerability management, security management, idc, vulnerability, vulnerability assessment, security audit, auditing, security

Core Security
Published:  Aug 21, 2009
Type:  White Paper
Length:  8 pages


moc.cdi.w I D C E X E C U T I V E B R I E F ww 510 P e n etr ati o n Te s ti n g : T aki ng th e 4.539 G u es sw ork Out of V ul ner a bili t y .805. M an a ge m e n t F 002 June 2005 8.278. Adapted from Worldwide Vulnerability Assessment and Management 2004–2008 Forecast and 2003 805 Vendor Shares: Assessing Risk and Compliance, by Charles J. Kolodgy; IDC #32026 .P ASU Executive Overview 10710 Today, IT managers currently have limited capability to assess real A risk, technically validate the effectiveness of security products they M , use, and make intelligent IT security investment decisions. mahgni This Brief will discuss how penetration testing software can efficiently mar address these challenges. Penetration testing is an important F t addition to the vulnerability assessment and management (VA&M) eert portfolio in that it picks up where "scan and identify" products leave S n off, substantiating whether theoretical threats to network security are ee real or not. Penetration testing software provides the capability to pS test the overall IT security infrastructure and polices to ensure that 5 :sr an organization's security investments are actually working. This etr capability will become increasingly important as companies continue auq to spend more on solutions to protect their information assets and dae meet compliance requirements. Management will need to justify H l those investments by proving that they are indeed paying off. abolG Penetration testing is necessary for organizations to:
. Understand the actual risk to their business posed by specific vulnerabilities
. Test the security of their network
. Determine if their current security investments are actually detecting and preventing attacks
Penetration testing software represents the best option for doing so.
05C4497 Introduction The network security efforts of IT managers have so far been focused on keeping the bad guys at bay. Traditionally, this has been accomplished by trying to outsmart hackers by creating barriers or providing defensive mechanisms once a vulnerability was identified. As networks become more complex, however, it's impossible to protect everything. Instead, managers need to prioritize their security to protect the most critical assets and ensure the technology they have deployed is functioning as effectively as possible. Vulnerability scanners can help, but the list of potential vulnerabilities produced by a scanner can be dauntingly long and not wholly accurate.
Additionally, managers should probe deeper to understand the true threat to assets when specific vulnerabilities are exploited on their network. A new class of penetration-testing software products has emerged to do this. These products represent a potential solution for managers to test the security of a network, identify what resources are exposed, and determine if current security investments are actually detecting and preventing attacks. This Brief examines key trends in the vulnerability assessment and management (VA&M) market and identifies the value of penetration testing as part of a comprehensive security methodology.
The Need for Better Vulnerability Management IT infrastructure is getting more complex, and wider access to internal networks is being granted to credentialed users located outside the firewall. Today, IT managers currently have limited capability to assess real risk, technically validate the effectiveness of security products they use, and make intelligent IT security investment decisions.
In addition, the following factors are driving demand for better vulnerability management solutions:
. Organizations need something more than a status check and a laundry list of items to fix. Scanners are good for detecting potential flaws, but companies need to know not only what vulnerabilities they have, but also a means of measuring policy compliance and risk management. Most organizations do attempt to patch known vulnerabilities, but patching everything is not a practical or necessary step in every case. Furthermore, enterprises need to understand their organization’s true exposure in the event of a “real” security compromise.
. Government requirements for security and privacy have become more demanding. Organizations of all sizes have to be concerned about their ability to measure their compliance to security requirements. For ... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search