Re: List of Computer-based Security Testing Methodologies

View: New views
5 Messages — Rating Filter:   Alert me  

Parent Message unknown Re: List of Computer-based Security Testing Methodologies

by Eduardo dos Santos :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi all,
Can anyone tell what computer-based security testing methodologies are
available?

The only one I've found was OSSTMM. Does anyone know another else?

Best regards,

--
Eduardo dos Santos

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------


Re: List of Computer-based Security Testing Methodologies

by lister-4 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message


* Hacking Exposed (book)
* ISSAF
* NIST 800-42
* NIST 800-115
* OSSTM
* OWASP Testing Project
* Sensepost
* IDART
* IAM/NSA
* Web Application Hackers Handbook (book)


On Wed, Oct 14, 2009 at 10:28:53PM -0300, Eduardo dos Santos wrote:

> Hi all,
> Can anyone tell what computer-based security testing methodologies are
> available?
>
> The only one I've found was OSSTMM. Does anyone know another else?
>
> Best regards,
>
> --
> Eduardo dos Santos
>
> ------------------------------------------------------------------------
> This list is sponsored by: Information Assurance Certification Review Board
>
> Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
>
> http://www.iacertification.org
> ------------------------------------------------------------------------

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------


Re: List of Computer-based Security Testing Methodologies

by ¨˜”°º•C0D3w@lk3r•º°”˜¨ :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

check the ISSAF
http://www.oissg.org/information-systems-security-assessment-framework-issaf-3.html

and http://www.vulnerabilityassessment.co.uk/Penetration%20Test.html

--
¨˜”°º•C0D3w@lk3r•º°”˜¨



On Thu, Oct 15, 2009 at 6:58 AM, Eduardo dos Santos
<eduardosantos3011@...> wrote:

> Hi all,
> Can anyone tell what computer-based security testing methodologies are
> available?
>
> The only one I've found was OSSTMM. Does anyone know another else?
>
> Best regards,
>
> --
> Eduardo dos Santos
>
> ------------------------------------------------------------------------
> This list is sponsored by: Information Assurance Certification Review Board
>
> Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
>
> http://www.iacertification.org
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------


Re: List of Computer-based Security Testing Methodologies

by Marat Vyshegorodtsev :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Take a look at ISSAF [0] and VulnerabilityAssessment.co.uk Pentest
Framework [1].

[0] http://www.oissg.org/information-systems-security-assessment-framework-issaf.html
[1] http://www.vulnerabilityassessment.co.uk/Penetration%20Test.html

2009/10/15 Eduardo dos Santos <eduardosantos3011@...>:

> Hi all,
> Can anyone tell what computer-based security testing methodologies are
> available?
>
> The only one I've found was OSSTMM. Does anyone know another else?
>
> Best regards,
>
> --
> Eduardo dos Santos
>
> ------------------------------------------------------------------------
> This list is sponsored by: Information Assurance Certification Review Board
>
> Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
>
> http://www.iacertification.org
> ------------------------------------------------------------------------
>
>



--
Vyshegorodtsev Marat nosafety@...

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------


Re: List of Computer-based Security Testing Methodologies

by Robert Portvliet :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

The Penetration Test Framework is excellent:
http://www.vulnerabilityassessment.co.uk/

NIST also has a document on information security assesment here:
http://csrc.nist.gov/publications/nistpubs/800-115/SP800-115.pdf



On Wed, Oct 14, 2009 at 9:28 PM, Eduardo dos Santos
<eduardosantos3011@...> wrote:

> Hi all,
> Can anyone tell what computer-based security testing methodologies are
> available?
>
> The only one I've found was OSSTMM. Does anyone know another else?
>
> Best regards,
>
> --
> Eduardo dos Santos
>
> ------------------------------------------------------------------------
> This list is sponsored by: Information Assurance Certification Review Board
>
> Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.
>
> http://www.iacertification.org
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
This list is sponsored by: Information Assurance Certification Review Board

Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified.

http://www.iacertification.org
------------------------------------------------------------------------