NIST SP 800-115 Explained: Assessment Techniques for PenTest+
NIST Special Publication 800-115 is the Technical Guide to Information Security Testing and Assessment. It carries weight because it is a recognised government standard, so referencing it satisfies auditors in a way a commercial methodology may not. For the comparison of methodologies generally, see the companion article linked at the end. This one covers 800-115's own structure. The four phases Planning. Treated as a project management activity. Gather rules of engagement, define scope and objectives, obtain management approval, and establish logistics and communications. Nothing technical happens here, and the document is explicit that assessments fail more often for lack of planning than for lack of technical skill. Discovery. Two parts. Information gathering — network discovery, port and service identification, OS fingerprinting — and then vulnerability analysis, comparing what was found against known vulnerabilities. Attack. Verifying vulnerabilities by attempting to e...