First, a quick poll: how many types of security testing do you know? Let me try…
- Penetration testing (PT)
- Red teaming (RT) – differences of PT and RT are discussed here
- Vulnerability assessment
- Application security testing (AST)
- Security rating services (like BitSight and SecurityScorecard)
- Attack, threat, breach simulation tools (details)
- Others, possibly many others….
Now, at the risk of sounding too philosophical, what does it even mean “to test one’s security”? At this early stage of our effort, all bets are off, but we do want to look into testing of security technologies and processes (such as detection and response processes), with the focus on outcomes, not controls. In essence, we want to look into testing the effectiveness, not the presence, of security controls.
Please share how you think of TESTING SECURITY … and please don’t say that “a good pentest should be enough security testing for everybody.” 🙂
Note that we will try to keep the focus of this on actually TESTING, not other forms of evaluating, measuring, assessing or guessing about security … Asking people how secure they think they are isn’t testing. Questionnaires isn’t testing. Reviewing policies isn’t testing. Even reviewing the lists of controls they think they deployed isn’t testing (IMHO).
In fact, overall, paper security isn’t.
Blog posts related to Testing Security project:
The Gartner Blog Network provides an opportunity for Gartner analysts to test ideas and move research forward. Because the content posted by Gartner analysts on this site does not undergo our standard editorial review, all comments or opinions expressed hereunder are those of the individual contributors and do not represent the views of Gartner, Inc. or its management.