Posts

Showing posts with the label Methodology

NIST SP 800-115 Explained: Assessment Techniques for PenTest+

NIST Special Publication 800-115 is the Technical Guide to Information Security Testing and Assessment. It carries weight because it is a recognised government standard, so referencing it satisfies auditors in a way a commercial methodology may not. For the comparison of methodologies generally, see the companion article linked at the end. This one covers 800-115's own structure. The four phases Planning. Treated as a project management activity. Gather rules of engagement, define scope and objectives, obtain management approval, and establish logistics and communications. Nothing technical happens here, and the document is explicit that assessments fail more often for lack of planning than for lack of technical skill. Discovery. Two parts. Information gathering — network discovery, port and service identification, OS fingerprinting — and then vulnerability analysis, comparing what was found against known vulnerabilities. Attack. Verifying vulnerabilities by attempting to e...

Penetration Testing Methodologies Explained: OSSTMM, PTES and NIST

A penetration testing methodology gives an engagement structure, so results are repeatable and coverage is defensible. PenTest+ expects you to recognise the main ones and know which suits which kind of test. The methodologies Methodology Focus OSSTMM Operational security measurement across five channels PTES End-to-end engagement process, seven phases NIST SP 800-115 Technical assessment guidance, four phases OWASP WSTG / MASTG Web and mobile application testing ISSAF Detailed technical assessment framework MITRE ATT&CK Adversary behaviour catalogue, used for threat-informed testing OSSTMM The Open Source Security Testing Methodology Manual, from ISECOM. Its distinguishing feature is that it aims to measure operational security rather than produce a list of findings. It defines five channels, and the breadth is the thing to remember: human (social engineering), physical , wireless , telecommunications , and data networks . Most methodologies cover only the last; OSST...