Rabu, 03 September 2014

Penetration Testing Methodology

Penetration testing, often abbreviated as pentest, is a process that is followed to conduct an in-depth security assessment or audit. A methodology defines a set of rules, practices, and procedures that are pursued and implemented during the course of any information security audit program. A penetration testing methodology defines a roadmap with practical ideas and proven practices that can be followed to assess the true security posture of a network, application, system, or any combination thereof. This chapter offers summaries of several key penetration testing methodologies. Key topics covered in this chapter include:

• A discussion on two well-known types of penetration testing—black box and white box
• Describing the differences between the vulnerability assessment and penetration testing
• Explaining several industry-acceptable security testing methodologies and their core functions, features, and benefits
• A general penetration testing methodology that incorporates the 10 consecutive steps of a typical penetration testing process
• The ethical dimension of how the security testing projects should be handled 

Penetration testing can be carried out independently or as a part of an IT security risk management process that may be incorporated into a regular development life cycle (for example, Microsoft SDLC). It is vital to notice that the security of a product not only depends on the factors that are related to the IT environment but also relies on product-specific security best practices. This involves the implementation of appropriate security requirements, performing risk analysis, threat modeling, code reviews, and operational security measurement.

Penetration testing is considered to be the last and most aggressive form of security assessment. It must be handled by qualified professionals and can be conducted with or without prior knowledge of the targeted network or application. A pentest may be used to assess all IT infrastructure components including applications, network devices, operating systems, communication medium, physical security, and human psychology. The output of penetration testing usually consists of a report divided
into several sections that address the weaknesses found in the current state of the target environment, followed by potential countermeasures and other remediation recommendations. The use of a methodological process provides extensive benefits to the pentester to understand and critically analyze the integrity of current defenses during each stage of the testing process.

Types of penetration testing
Although there are different types of penetration testing, the two most general approaches that are widely accepted by the industry are the black box and white box. These approaches will be discussed in the following sections.

Black box testing
While applying this approach, the security auditor will be assessing the network infrastructure and will not be aware of any internal technologies deployed by the targeted organization. By employing a number of real-world hacker techniques and going through organized test phases, vulnerabilities may be revealed and potentially exploited. It is important for a pentester to understand, classify, and prioritize these vulnerabilities according to their level of risk (low, medium, or high). The risk can be
measured according to the threat imposed by the vulnerability in general. An ideal penetration tester would determine all attack vectors that could cause the target to be compromised. Once the testing process has been completed, a report that contains all the necessary information regarding the targets' real-world security posture, categorizing, and translating the identified risks into a business context, is generated. Black box testing can be a more expensive service than white box testing.

White box testing
An auditor involved in this kind of penetration testing process should be aware of all the internal and underlying technologies used by the target environment. Hence, it opens a wide gate for a penetration tester to view and critically evaluate the security vulnerabilities with minimum possible efforts and utmost accuracy. It does bring more value to the organization in comparison to the black box approach in the sense that it will eliminate any internal security issues lying at the target infrastructure's environment, thus making it more difficult for a malicious adversary to infiltrate from the outside. The number of steps involved in white box testing is similar to that of black box testing. Moreover, the white box approach can easily be integrated into a regular development life cycle to eradicate any possible security issues at an early stage before they get disclosed and exploited by intruders. The time, cost, and knowledge level required to find and resolve the security vulnerabilities is comparably less than with the black box approach.

Selasa, 02 September 2014

Mengelola Program Audit

Program audit dapat mencakup pertimbangan satu atau lebih standar sistem manajemen audit, yang dilakukan baik secara terpisah atau dalam kombinasi.

Manajemen harus memastikan bahwa tujuan program audit ditetapkan dan menetapkan satu atau orang yang lebih kompeten untuk mengelola program audit. Luasnya program audit harus didasarkan pada ukuran dan sifat dari organisasi yang diaudit, serta pada sifat, fungsi, kompleksitas dan tingkat kematangan dari sistem manajemen yang akan diaudit. Prioritas harus diberikan untuk mengalokasikan sumber daya audit program untuk mengaudit hal-hal penting dalam sistem manajemen.

Konsep tersebut pada umumnya dikenal sebagai audit berbasis risiko (risk based audit). Program audit harus mencakup informasi dan sumber daya yang diperlukan untuk mengatur dan melakukan audit yang efektif dan efisien dalam kerangka waktu tertentu dan juga dapat meliputi:
  1. Tujuan untuk program audit dan audit individu.
  2. Batas / jumlah / jenis / durasi / lokasi / jadwal audit.
  3. Prosedur program audit.
  4. Kriteria audit.
  5. Metode audit.
  6. Pemilihan Tim Audit.
  7. Sumber daya yang diperlukan, termasuk perjalanan dan akomodasi.
  8. Proses untuk menangani kerahasiaan, keamanan informasi, kesehatan dan keselamatan, dan hal-hal serupa lainnya.
Pelaksanaan program audit harus dipantau dan diukur untuk memastikan tujuan Perusahaan telah dicapai. Program audit harus ditinjau untuk mengidentifikasi kemungkinan perbaikan. Gambar di bawah ini adalah flowchart dari kegiatan program audit sebagai berikut: 


Sumber: ISO 19011:2011 (Di translate manual oleh Penulis) 

Prinsip Audit

Auditor ketika melakukan kegiatan audit mempunyai beberapa prinsip atau kaidah audit, yaitu: 

1. Integritas adalah dasar profesionalisme Auditor dan orang yang mengelola program audit harus: 
  • Melakukan pekerjaan mereka dengan kejujuran, ketekunan, dan tanggung jawab.
  • Mengamati dan mematuhi persyaratan hukum yang berlaku.
  • Menunjukkan kompetensi mereka saat melakukan pekerjaan mereka.
  • Melakukan pekerjaan mereka dengan cara yang tidak memihak, yaitu tetap adil dan tidak bisa dalam semua urusan mereka. 
  • Peka terhadap segala pengaruh yang mungkin diberikan pada penilaian mereka saat melakukan audit. 

2. Adil adalah kewajiban untuk melaporkan dengan jujur ​​dan akurat untuk temuan audit, kesimpulan audit dan laporan audit harus mencerminkan kejujuran serta akurat untuk kegiatan audit. Kendala yang ditemui selama audit dan opini terkait penyimpangan terselesaikan antara Tim Audit dan Auditee harus dilaporkan. Komunikasi harus jujur, akurat, obyektif, tepat waktu, jelas dan lengkap. 

3. Profesional adalah penerapan bentuk komitmen untuk mewujudkan dan meningkatkan kualitas pekerjaannya. Auditor harus mempunyai ketrampilan yang baik dalam bidang audit dan kecerdasan dalam menganalisis suatu masalah serta cermat dalam mengambil keputusan terbaik. 

4. Kerahasiaan adalah bentuk keamanan informasi yang harus diterapkan oleh Auditor dalam menggunakan dan melindungi informasi yang diperoleh ketika Auditor menjalankan tugas mereka. Informasi audit tidak boleh digunakan untuk keuntungan pribadi oleh Auditor atau Klien audit, atau dengan cara merugikan kepentingan dari Auditee. Konsep ini mencakup penanganan informasi yang bersifat sensitif atau rahasia. 

5. Independen adalah dasar untuk ketidakberpihakan audit dan objektivitas atas kesimpulan audit. Auditor harus independen terhadap kegiatan yang diaudit dan bertindak dengan cara yang bebas dari bias atau tidak jelas dan menghindari dari konflik kepentingan pribadi atau golongan. Auditor harus menjaga objektivitas selama proses audit untuk memastikan bahwa temuan audit dan kesimpulan didasarkan pada bukti audit. 

6. Pendekatan berbasis bukti adalah metode rasional untuk mencapai kesimpulan audit yang handal dan sistematis yang harus diverifikasi terlebih dahulu. Penggunaan sampel yang tepat harus diterapkan, karena ini berkaitan erat dengan kepercayaan dalam kesimpulan hasil audit.

Sumber: ISO 19011:2011 (Di translate manual oleh Penulis)