
CISO's Guide to Penetration Testing
A Framework to Plan, Manage, and Maximize Benefits
James S. Tiller(Author)
CRC Press
1st Edition
Published on 30. June 2020
Book
Paperback/Softback
389 pages
978-0-367-38200-1 (ISBN)
Description
CISO's Guide to Penetration Testing: A Framework to Plan, Manage, and Maximize Benefits details the methodologies, framework, and unwritten conventions penetration tests should cover to provide the most value to your organization and your customers. Discussing the process from both a consultative and technical perspective, it provides an overview of the common tools and exploits used by attackers along with the rationale for why they are used.
From the first meeting to accepting the deliverables and knowing what to do with the results, James Tiller explains what to expect from all phases of the testing life cycle. He describes how to set test expectations and how to identify a good test from a bad one. He introduces the business characteristics of testing, the imposed and inherent limitations, and describes how to deal with those limitations.
The book outlines a framework for protecting confidential information and security professionals during testing. It covers social engineering and explains how to tune the plethora of options to best use this investigative tool within your own environment.
Ideal for senior security management and anyone else responsible for ensuring a sound security posture, this reference depicts a wide range of possible attack scenarios. It illustrates the complete cycle of attack from the hacker's perspective and presents a comprehensive framework to help you meet the objectives of penetration testing-including deliverables and the final report.
From the first meeting to accepting the deliverables and knowing what to do with the results, James Tiller explains what to expect from all phases of the testing life cycle. He describes how to set test expectations and how to identify a good test from a bad one. He introduces the business characteristics of testing, the imposed and inherent limitations, and describes how to deal with those limitations.
The book outlines a framework for protecting confidential information and security professionals during testing. It covers social engineering and explains how to tune the plethora of options to best use this investigative tool within your own environment.
Ideal for senior security management and anyone else responsible for ensuring a sound security posture, this reference depicts a wide range of possible attack scenarios. It illustrates the complete cycle of attack from the hacker's perspective and presents a comprehensive framework to help you meet the objectives of penetration testing-including deliverables and the final report.
More details
Language
English
Place of publication
London
United Kingdom
Publishing group
Taylor & Francis Ltd
Target group
Professional and scholarly
Academic and Professional Practice & Development
Dimensions
Height: 234 mm
Width: 156 mm
Thickness: 21 mm
Weight
594 gr
ISBN-13
978-0-367-38200-1 (9780367382001)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Classification
Other editions
Additional editions

James S. Tiller
CISO's Guide to Penetration Testing
A Framework to Plan, Manage, and Maximize Benefits
E-Book
04/2016
1st Edition
Auerbach Publishers Inc.
€78.99
Available for download

James S. Tiller
CISO's Guide to Penetration Testing
A Framework to Plan, Manage, and Maximize Benefits
E-Book
04/2016
Auerbach
€78.99
Available for download

James S. Tiller
CISO's Guide to Penetration Testing
A Framework to Plan, Manage, and Maximize Benefits
Book
12/2011
1st Edition
Taylor & Francis
€161.09
Shipment within 15-20 days
Person
James S. Tiller is the Vice-President of Security Professional Services, North American BT Global Services.
Content
Hacking and Security. Hacking Impacts. Black and White. Information Security. The Hacker. The Security Consultant. Business Justification. The Business of Security. Expectations. Timing is Everything. Reasoning. Consultative Approach. Ethics. Logistics. Methodology. Reconnaissance. Vulnerability Assessment. Testing. Tools and Technology. Exposures. Top 25 Tools. Scenarios. Conclusion.