Another important consideration is that the results of penetration testing are aimed toward providing an independent, unbiased view of the security stance and posture of the systems being tested; the outcome, therefore, should be an objective and useful input into the security procedures.
The testing process should not be seen as either obstructive or attempting to identify security shortfalls in order to lay blame or fault on the teams responsible for designing, building or maintaining the systems in question. An open and informative test will require the assistance and co-operation of many people beyond those actually involved in the commissioning of the penetration test.
A properly executed penetration test provides customers with evidence of any vulnerabilities and the extent to which it may be possible to gain access too or disclose information assets from the boundary of the system. They also provide a baseline for remedial action in order to enhance the information protection strategy.
One of the initial steps to be considered during the scoping requirements phase is to determine the rules of engagement and the operating method to be used by the penetration testing team, in order to satisfy the technical requirement and business objectives of the test. A penetration test can be part of a full security assessment but is often performed as an independent function Incident Response
The mechanics of the penetration testing process involves an active analysis of the system for any potential vulnerabilities that may result from improper system configuration, known hardware or software flaws, or from operational weaknesses in process or technical operation. Any security issues that are found during a penetration test should be documented together with an assessment of the impact and a recommendation for either a technical solution or risk mitigation.
A penetration test simulates a hostile attack against a customer’s systems in order to identify specific vulnerabilities and to expose methods that may be implemented to gain access to a system. Any identified vulnerabilities discovered and abused by a malicious individual, whether they are an internal or external threat, could pose a risk to the integrity of the system.