Thursday, November 8, 2007

Security Testing Framework

Looking for a methodologies on security testing i found a very interesting paper called "Open Source Security Testing Methodology Manual (OSSTMM)" The current version is 2.1 but version 3 is expected soon . Here is the official web site of the people making it - http://www.isecom.org/. They provide training and i guess that is not very bad idea. Most of the companies out there hire external security audits every now and then, well here is a framework that will help you keep this internal. And of-course if you are lazy like me here is the wikipedia.org article about the framework.

No comments: