Ciso's Guide to Penetration Testing: A Framework to Plan, Manage, and Maximize Benefits
暫譯: CISO的滲透測試指南:規劃、管理與最大化效益的框架

Tiller, James S.

  • 出版商: Auerbach Publication
  • 出版日期: 2020-06-30
  • 售價: $2,670
  • 貴賓價: 9.5$2,537
  • 語言: 英文
  • 頁數: 389
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 0367382008
  • ISBN-13: 9780367382001
  • 海外代購書籍(需單獨結帳)

相關主題

商品描述

CISO's Guide to Penetration Testing: A Framework to Plan, Manage, and Maximize Benefits details the methodologies, framework, and unwritten conventions penetration tests should cover to provide the most value to your organization and your customers. Discussing the process from both a consultative and technical perspective, it provides an overview of the common tools and exploits used by attackers along with the rationale for why they are used.





From the first meeting to accepting the deliverables and knowing what to do with the results, James Tiller explains what to expect from all phases of the testing life cycle. He describes how to set test expectations and how to identify a good test from a bad one. He introduces the business characteristics of testing, the imposed and inherent limitations, and describes how to deal with those limitations.





The book outlines a framework for protecting confidential information and security professionals during testing. It covers social engineering and explains how to tune the plethora of options to best use this investigative tool within your own environment.





Ideal for senior security management and anyone else responsible for ensuring a sound security posture, this reference depicts a wide range of possible attack scenarios. It illustrates the complete cycle of attack from the hacker's perspective and presents a comprehensive framework to help you meet the objectives of penetration testing--including deliverables and the final report.



商品描述(中文翻譯)

《CISO的滲透測試指南:計劃、管理和最大化效益的框架》詳細說明了滲透測試應涵蓋的方法論、框架和不成文的慣例,以便為您的組織和客戶提供最大的價值。該書從諮詢和技術的角度討論了這一過程,提供了攻擊者常用工具和漏洞的概述,以及為何使用這些工具的理由。

從第一次會議到接受交付成果並了解如何處理結果,James Tiller 解釋了測試生命週期各階段的期望。他描述了如何設置測試期望,以及如何區分好的測試和不好的測試。他介紹了測試的商業特徵、施加的和固有的限制,並描述了如何應對這些限制。

本書概述了一個框架,用於在測試期間保護機密信息和安全專業人員。它涵蓋了社會工程學,並解釋了如何調整眾多選項,以最佳方式在您的環境中使用這一調查工具。

本書非常適合高級安全管理人員及任何負責確保安全姿態的人士,該參考資料描繪了各種可能的攻擊場景。它從黑客的角度說明了完整的攻擊循環,並提供了一個全面的框架,以幫助您達成滲透測試的目標,包括交付成果和最終報告。

作者簡介

James S. Tiller is the Vice-President of Security Professional Services, North American BT Global Services.

作者簡介(中文翻譯)

詹姆斯·S·蒂勒(James S. Tiller)是北美BT全球服務的安全專業服務副總裁。