Penetration Testing mailing list archives
Re: Vulnerability Assessment vs. PenTest
From: harshal.mehta () niiconsulting com
Date: 10 Aug 2006 06:17:45 -0000
This is a very hot debated topic, i will just give a brief difference between the two Vulnerablity Assessment: Vulnerability Identification Vulnerability validation Usually done on site Exploitation of identified vulnerabilities is not carried. It covers wider area of an organisation but doesnot cover the depth. Penetration testing All activities of VA Could be onsite or offsite Done to check for a particular component like web application or nwk etc Exploitation of vulnerablities identified (could be by VA) Could be of various type like White Box, Black Box ,Gray Box Penetration testing requires more time as well as effort. Harshal Mehta Information Security Analyst ISO 27001 IA CEH cVa NII Consulting Mobile: +91 9819066601 Website: www.niiconsulting.com ================================================================= Penetration Testing Services http://www.niiconsulting.com/services/security_assessment/pentest.html ================================================================= ISO 27001 Compliance http://www.niiconsulting.com/services/irm/iso27001.html ================================================================= ------------------------------------------------------------------------------ This List Sponsored by: Cenzic Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details. ------------------------------------------------------------------------------
Current thread:
- Re: Vulnerability Assessment vs. PenTest, (continued)
- Re: Vulnerability Assessment vs. PenTest Magdelin Tey (Aug 07)
- RE: Vulnerability Assessment vs. PenTest StyleWar (Aug 08)
- RE: Vulnerability Assessment vs. PenTest Bob Radvanovsky (Aug 06)
- RE: Vulnerability Assessment vs. PenTest Omar A. Herrera (Aug 07)
- Re: Vulnerability Assessment vs. PenTest Gray Ghost (Aug 07)
- RE: Vulnerability Assessment vs. PenTest Craig Wright (Aug 09)
- RE: Vulnerability Assessment vs. PenTest David M. Zendzian (Aug 09)
- RE: Vulnerability Assessment vs. PenTest Craig Wright (Aug 09)
- Port Listening Chris Esezobor (Aug 10)
- RE: Port Listening Luke Walsh (Aug 10)
- Port Listening Chris Esezobor (Aug 10)
- Re: Vulnerability Assessment vs. PenTest harshal . mehta (Aug 10)
- Re: Vulnerability Assessment vs. PenTest lakshminarayanan79 (Aug 21)
- Re: Vulnerability Assessment vs. PenTest Marco Ivaldi (Aug 28)