Penetration testing
Penetration testing is a planned attack on an information system that attempts to simulate what an actual information system would experience if it was being attacked by a hacker. The types of penetration tests that the organization can choose to implement include:
- Social engineering: This type of test attempts to lure a user into revealing information that would benefit an attacker in further exploiting the organization. Information that the attacker would look to gain from a user includes:
- Client-side: This type of test serves to test the end user environment by testing applications on the desktop environment.
- Wireless security: This test attempts to discover and exploit and organization's wireless networking capability.
- Network services: This type of test looks to exploit systems and services located on the enterprise network.
- Physical security: This type of test looks to exploit the physical security of the organization, such as locks and alarms.