Sunday, July 22, 2012

Black Box System Testing

By Daniel Turbin


When you hire an independent security consulting firm to check your company's defenses, one of the more common tests to have performed is a "Black Box text." In cases like these, you do not tell the security consultant anything about your corporation's network. You do not give him anything to work with at all . From his point of view, your company is the hackneyed "black box, "and his goal is to initiate a mock attack against your system's defenses to attempt to obtain access.

If he can, then the test exposes the most vivid failings of your system's security, and paints a vivid picture of the steps that have to be taken to be sure that it does not occur again. If he cannot, then it showcases the power of your system.

In all cases nevertheless , the written report that such independent specialists provide is chock-full of useful info, both in terms of how well your system withstood the ridicule attack, and re the potential weak spots you will want to consider covering further.

Given the significance of info in the daily operation of your business ( any business ), conducting such tests periodically is a good way to ensure that your business is protected and rather more importantly, that it stays protected.

If you cannot remember when your last security audit was, schedule one today. If it's been more than year since your last one, do likewise, and if you've lately suffered a hacking attempt or a successful breech, do likewise.

A once a year security audit provides one of the finest returns on investment you will ever make. Do not make the mistake of simply assuming that all's well. Take the initiative, have regular audits, and be aware of the report you get back. It could well be the thing that saves your business!



No comments:

Post a Comment