Skip to content
BOL Conferences
Thread Options
#148281 - 01/09/04 11:02 PM penetration testing
Jokerman Offline
10K Club
Joined: Nov 2003
Posts: 12,846
Does anyone know off the top of their head where to find regulatory guidance on how often to conduct penetration testing? Thanks.

Return to Top
eBanking / Technology
#148282 - 01/09/04 11:47 PM Re: penetration testing
Czargazer Offline
Gold Star
Czargazer
Joined: May 2003
Posts: 298
Pacific Northwest
I think at this point it is entirely risk based. The updated FFIEC IT Exam Handbook (Dec. 2003), Information Security Booklet, states on page 81 "The frequency of testing should be determined by the institution's risk assessment. High-risk systems should be subject to an independent diagnostic test at least once a year." The word "independent" in this context only means that the individuals performing the testing have independance from creating or developing the systems being tested. So these could be internal auditors or it could be out-sourced, either would work.
_________________________
Everyone has to make a living, mine just happens to involve thumbscrews.

Return to Top
#148283 - 01/10/04 07:02 PM Re: penetration testing
Wayne Barnett Offline
Member
Wayne Barnett
Joined: Nov 2002
Posts: 58
Dallas, Texas
Penetration testing is important. I do such testing as a standard part of my IT audits, and I find weaknessess 30% of the time. In almost every instance, the vendor for the firewall has a patch that eliminates the weakness. However, no one at the bank knows to check the vendor's web site for updated software.

At a minimum, I recommend penetration testing once a year. I also recommend that the vendor's web site be checked once a month, to ensure the firewall is running the most current version of its software. It only takes 60 seconds to do the check, and it's one of the best things you can do to protect yourself from Hackers.

Regards,
Wayne Barnett, CPA
800-680-8692
www.barnettcpa.com

Wayne Barnett Software
A Texas Corporation
877-945-4344
www.barnettsoftware.com

Return to Top

Moderator:  Andy_Z