Picture of Ollie Ross
Ross: User consultation imperative

Ethical hackers come in for tighter regulation

Crest hope standard will become industry kitemark

Written by Tom Young

Quality standards are to be applied to organisations and individuals that offer security penetration testing services, to improve business confidence.

From 1 April, the Council for Registered Ethical Security Testers (Crest) will accredit ethical hackers who perform tests on company networks to see if they are vulnerable to security breaches.

Paul Vlissidis, a member of the Crest operational management committee, says standards are essential for an industry that requires such a high degree of trust.

‘This industry sector has no kitemark,’ he said. ‘Our customers need a bar to allow them to see who comes above it and who comes below it.’

Crest will assess firms and individuals using written and practical exams. Successful accreditations will last for three years before they need to be renewed.

‘Technology and the threat environment are evolving constantly, and our processes need to evolve with them,’ said Paul Docherty, operational management committee member at Crest.

Crest expects that the international nature of its corporate customers will result in the standard becoming internationally recognised within about a year.

Ollie Ross, head of research at The Corporate IT Forum, warns Crest should learn from the mistakes of other standards.

‘An initiative to provide an approved level of quality assurance should be encouraged,’ she said.

‘But the difficulty many users experienced with the recent launch of the Payments Cards Industry (PCI) data security standard demonstrates the need for increased user consultation.’

reader comments

related articles

Security accreditation on trial

The government is set to trial an IT security accreditation that it hopes will assure both the private and public sectors that software companies, which sell products such as antivirus software and firewalls, meet quality standards. 14 Oct 2004

 

Professional security accreditation moves closer

Standard should be in place within 3 years 18 Jan 2007

Bankers back security professionals’ accreditation

Institute of Information Security Professionals launched 02 Mar 2006

Retailers struggle to meet PCI deadline

Quick fixes not good enough, warn experts 19 May 2008

VeriSign touts virtues of security 'green bar'

Extended Validation authentication programme ups site trust, claims company 03 Oct 2008

PCI standard 'ignores' insider threat

Database security firm warns of gaping holes 23 Jun 2008

related whitepapers

today's top stories

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Got the Knowledge?

Last week the civil service published a new strategy to help government seize the opportunities and meet the challenges of managing knowledge... 01 Dec 2008

Q&A - ntl:Telewest Business managing director Stephen Beynon

The cable provider's chief talks about the future of next-generation broadband access in the UK 28 Nov 2008

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

India will remain open for business - but that's not the real story

One of the duties I have to fulfil as a director of the National Outsourcing Association is to talk to the media... 28 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

ntl:Telewest's Stephen BeynonAnalysis

Q&A - ntl:Telewest Business managing director Stephen Beynon

The cable provider's chief talks about the future of next-generation broadband access in the UK 28 Nov 2008

cowboyFeatures

Guns for hire

David Neal explores the world of interim CIOs and discovers why more firms are turning to them to spur on IT-led change 27 Nov 2008

Advertisement

Primary Navigation