Picture of Nick Bleech
Nick Bleech: businesses could still have trust concerns

Ethical hackers face new test

Scheme to improve business trust in penetration testing still needs industry backing

Written by Tom Young

From next month organisations and individuals that provide security penetration testing services will be subject to an accreditation process.

The scheme, being run by trade association the Council of Registered Ethical Security Testers (Crest) is designed to provide firms with greater confidence when they appoint third parties to perform ethical hacking to identify system weaknesses.

Crest will certify that penetration testers meet minimum standards of ethics, methodologies and technical capabilities, and wants to outlaw vendors that prey on businesses’ lack of knowledge about what a comprehensive security test involves.

‘The lines are unclear as to what constitutes security assessment and people need to be presented with a holistic standard,’ said Paul Docherty, who sits on Crest’s operational management committee.

The committee says demand has been high from the penetration industry and its customers.

‘The fact that we already have firms who are clamouring to become members because businesses are demanding our accreditation shows the customer demand for this standard,’ said the committee’s Paul Vlissidis.

The individuals creating the original assessments were also involved in setting up Check, a very similar scheme that only applies to the government sector.

Mark Raeburn, another member of the committee, says the assessments themselves will be as rigorous as Check.

‘Each candidate will not only have to run the correct tools to test security, but explain why they are running certain tools and what those tools are doing to demonstrate a rounded knowledge of the issues,’ he said.

But Nick Bleech, information security director at engineering giant Rolls-Royce, says businesses could still have trust concerns.

‘At present I rely on companies that ensure their people have been through the government-run Check scheme, because this tells me that a tester has been subject to a level of vetting or background checking and an independent test of skills,’ he said.

‘There are a lot of problems about doing background checks outside the government context, companies might not be interested in a ‘new’ certification which says, in effect, “trust us, we self-certify against some company-defined code of practice”.’

The Crest committee members say they have sought extensive consultation with the organisations they will be testing, and ongoing relationships will ensure the standard remains appropriate to the threat environment.

Crest has established an industry advisory panel of key user organisations.

Carrie Hartnell, programme manager at Intellect, believes users will support the scheme if it liases with the industry.

‘Intellect believes companies could support a non-government scheme, especially if it avoids the market of testers being fragmented into non-government and government sectors,’ said Hartnell.

‘The key is continued liaison with their employers to ensure standards remain relevant.’

reader comments

related articles

Picture of Nick Coleman

Professional security accreditation moves closer

Standard should be in place within 3 years 18 Jan 2007

 

Government works on supplier accreditation

Standards for public sector data interchange on the way 13 Mar 2002

Bankers back security professionals’ accreditation

Institute of Information Security Professionals launched 02 Mar 2006

Analysis: Experts discuss security in a recession

Benchmarking study highlights where firms are failing 27 Feb 2009

NetSuite urged to join online software group

NetSuite asked to join new industry group set up at Intellect, as all other software suppliers have already signed up to the project 19 Mar 2009

AA Awards 2008: Outstanding Industry Contribution

Peter Wyman wins the Outstanding Industry Contribution 13 Nov 2008

related whitepapers

today's top stories

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Open source bites back

Recession-hit companies are tired of vendors holding a gun to their heads over software licensing, says CEO of Ingres 09 Jul 2009

"We will ensure Britain remains at the forefront of the digital revolution"

As new trials of superfast broadband get under way, minister Pat McFadden explains the government’s digital vision 09 Jul 2009

Put social networks to work on your career

Increasing numbers of IT professionals using sites such as LinkedIn to grow contacts and find jobs 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation