Testing your defenses
As explained in the introduction, the best approach for hardening your defense is attacking your existing security controls with the goal of identifying weakness. Some key concepts to consider when developing a strategy for testing your cyber security defenses are as follows:
Black, white, or gray hat approach?
Test a copy or the real system?
Possible risks from Penetration Test?
Who should be informed?
Are you testing detection and response to threats or focusing on identifying vulnerabilities?
Are any compliance standards being considered?
Let's look at establishing a plan for validating our security. We first need to know our baseline for security, so we know what to validate against.
Baseline security
One common question asked by industry experts is what should be the minimal acceptable level for security. Many organizations must be in compliance with mandates specified by their industry and government. Any system accepting payments must adhere to the Payment Card Industry...