首页> 外文期刊>Australian journal of information systems >PENETRATION TESTING PROFESSIONAL ETHICS: A CONCEPTUAL MODEL AND TAXONOMY
【24h】

PENETRATION TESTING PROFESSIONAL ETHICS: A CONCEPTUAL MODEL AND TAXONOMY

机译:渗透测试专业道德:概念模型和分类法

获取原文
获取原文并翻译 | 示例
           

摘要

In an environment where commercial software is continually patched to correct security flaws, penetration testing can provide organisations with a realistic assessment of their security posture. Penetration testing uses the same principles as criminal hackers to penetrate corporate networks and thereby verify the presence of software vulnerabilities. Network administrators can use the results of a penetration test to correct flaws and improve overall security. The use of hacking techniques, however, raises several ethical questions that centre on the integrity of the tester to maintain professional distance and uphold the profession. This paper discusses the ethics of penetration testing and presents our conceptual model and revised taxonomy.
机译:在不断修补商业软件以纠正安全漏洞的环境中,渗透测试可以为组织提供对其安全状态的现实评估。渗透测试使用与犯罪黑客相同的原理来渗透公司网络,从而验证软件漏洞的存在。网络管理员可以使用渗透测试的结果来纠正缺陷并提高整体安全性。但是,黑客技术的使用提出了一些道德问题,这些问题集中在测试人员的完整性上,以保持专业距离并维护专业。本文讨论了渗透测试的道德规范,并提出了我们的概念模型和修订的分类法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号