Defense Department suggests regular cybersecurity testing

According to Steven Hutchison, head of the Defense Information Systems Agency’s test and evaluation group, IT managers should continuously test the security of their systems throughout the development process, starting as soon in the process as possible. “We do extensive testing of our systems in our environment to ensure that as they are developed, they don’t have built-in vulnerabilities,” Hutchison said. “We try to find those and fix those before systems are deployed.” Network World (6/11)


What is Penetration Testing?

A penetration test, or pen test, is an attempt to evaluate the security of an IT infrastructure by safely trying to exploit vulnerabilities. These vulnerabilities may exist in operating systems, service and application flaws, improper configurations, or risky end-user behavior. Such assessments are also useful in validating the efficacy of defensive mechanisms, as well as, end-user adherence to security policies.


