首页> 外文期刊>Computer law & security report >An approach to minimizing legal and reputational risk in Red Team hacking exercises
【24h】

An approach to minimizing legal and reputational risk in Red Team hacking exercises

机译:在Red Team黑客练习中最大程度降低法律和声誉风险的方法

获取原文
获取原文并翻译 | 示例
           

摘要

Robust cyber-resilience depends on sound technical controls and testing of those controls in combination with rigorous cyber-security policies and practices. Increasingly, corporations and other organizations are seeking to test all of these, using methods more sophisticated than mere network penetration testing or other technical audit operations. More sophisticated organizations are also conducting so-called “Red Team” exercises, in which the organization tasks a small team of highly skilled and trained individuals to try to gain unauthorized access to physical and logical company assets and information. While such operations can have real value, they must be planned and conducted with great care in order to avoid violating the law or creating undue risk and reputational harm to the organization. This article explores these sometimes tricky issues, and offers practical risk-based guidance for organizations contemplating these types of exercises.
机译:强大的网络弹性取决于完善的技术控制和对这些控制的测试,以及严格的网络安全政策和实践。公司和其他组织越来越多地寻求使用比单纯的网络渗透测试或其他技术审核操作更复杂的方法来测试所有这些。更为复杂的组织也正在进行所谓的“红队”演习,该组织会派遣一支由高技能且训练有素的人员组成的小团队,以尝试未经授权访问物理和逻辑公司资产和信息。尽管这样的操作具有真正的价值,但必须精心计划和执行这些操作,以避免违反法律或对组织造成不适当的风险和声誉损害。本文探讨了这些有时棘手的问题,并为考虑此类练习的组织提供了基于风险的实用指导。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号