首页 | 本学科首页   官方微博 | 高级检索  
     


An approach to minimizing legal and reputational risk in Red Team hacking exercises
Authors:Joseph V. DeMarco
Affiliation:DeVore & DeMarco, LLP, New York, NY, USA
Abstract:Robust cyber-resilience depends on sound technical controls and testing of those controls in combination with rigorous cyber-security policies and practices. Increasingly, corporations and other organizations are seeking to test all of these, using methods more sophisticated than mere network penetration testing or other technical audit operations. More sophisticated organizations are also conducting so-called “Red Team” exercises, in which the organization tasks a small team of highly skilled and trained individuals to try to gain unauthorized access to physical and logical company assets and information. While such operations can have real value, they must be planned and conducted with great care in order to avoid violating the law or creating undue risk and reputational harm to the organization. This article explores these sometimes tricky issues, and offers practical risk-based guidance for organizations contemplating these types of exercises.
Keywords:Data protection  Data security  Cybercrime  Cybersecurity  Cyber-resilience  Computer intrusions  Ethical hacking  Network and information security  Penetration Testing  Red Team
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号