Hack Tool Repository Logo

Hack Tool Repository

white curve white curve

Article: Results pentest questionnaire

This site is no longer maintained and kept for archiving purposes.

I am writing my thesis for my EDP auditor education. In my thesis I will compare the used methods and standards used by penetration testers with the method and standards used by the Dutch IT auditor association.

I need to know which methods and standards are used the most by penetration testers and how the final report looks like. To get my answers I have developed a short questionnaire about penetration testing. It asks questions about methodologies, standards, classification and reports.

You can still fill out the questionnaire if you haven't done so already: http://www.thesistools.com/web/?id=201555

Does the definition below cover the term penetration test? You can choose from 1-4, which stands for not, a bit mostly and totally.
The definition above covers the term penetration test (Not - Totally)
A penetration test is the controlled attempt at penetrating a computer system or network from “outside” in order to detect vulnerabilities. It employs the same or similar techniques to those used in a genuine attack.
113 (9.85 %)
239 (29.55 %)
359 (44.7 %)
421 (15.91 %)

n = 132
# 132



Penetration testing is security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network. It often involves launching real attacks on real systems and data that use tools and techniques commonly used by attackers. Most penetration tests involve looking for combinations of vulnerabilities on one or more systems that can be used to gain more access than could be achieved through a single vulnerability.
The definition above covers the term penetration test (Not - Totally)
16 (4.65 %)
219 (14.73 %)
358 (44.96 %)
446 (35.66 %)

n = 129
# 129



Penetration testing is the portion of security testing in which the evaluators attempt to circumvent the security features of a system. The evaluators may be assumed to use all system design and implementation documentation, which may include listings of system source code, manuals, and circuit diagrams. The evaluators work under the same constraints applied to ordinary users.
The definition above covers the term penetration test (Not - Totally)
120 (15.63 %)
257 (44.53 %)
340 (31.25 %)
411 (8.59 %)

n = 128
# 128



A penetration test is a method of evaluating the security of a computer system or network by simulating an attack from a malicious source. The process involves an active analysis of the system for any potential vulnerabilities that could result from poor or improper system configuration, hardware or software flaws, or operational weaknesses in process or technical countermeasures. The intent of a penetration test is to determine the feasibility of an attack and the amount of business impact of a successful exploit, if discovered.
The definition above covers the term penetration test (Not - Totally)
116 (12.4 %)
224 (18.6 %)
354 (41.86 %)
435 (27.13 %)

n = 129
# 129



A penetration test is a live test of the effectiveness of security defenses through mimicking the actions of real-life attackers.
The definition above covers the term penetration test (Not - Totally)
113 (10 %)
224 (18.46 %)
352 (40 %)
441 (31.54 %)

n = 130
# 130



Which of the following penetration testing methodologies do you use frequently? Please specify to which extent you use the methodology.
The Open Source Security Testing Methodology (OSSTM)
At least once a week11 (18.03 %)
At least once a month25 (40.98 %)
At least once a year25 (40.98 %)

n = 61
# 61



Which of the following penetration testing methodologies do you use frequently? Please specify to which extent you use the methodology.
NIST SP800-115
At least once a week4 (7.84 %)
At least once a month15 (29.41 %)
At least once a year32 (62.75 %)

n = 51
# 51



Which of the following penetration testing methodologies do you use frequently? Please specify to which extent you use the methodology.
Information Systems Security Assessment Framework (ISSAF)
At least once a week6 (13.64 %)
At least once a month14 (31.82 %)
At least once a year24 (54.55 %)

n = 44
# 44



Which of the following penetration testing methodologies do you use frequently? Please specify to which extent you use the methodology.
Penetration Testing Model by BSI
At least once a week6 (15 %)
At least once a month11 (27.5 %)
At least once a year23 (57.5 %)

n = 40
# 40



Which of the following penetration testing methodologies do you use frequently? Please specify to which extent you use the methodology.
Guideline for IS audits based on IT-Grundschutz
At least once a week0 (0 %)
At least once a month8 (22.22 %)
At least once a year28 (77.78 %)

n = 36
# 36



Which of the following penetration testing methodologies do you use frequently? Please specify to which extent you use the methodology.
Penetration Test Framework by www.vulnerabilityassessment.co.uk
At least once a week6 (13.04 %)
At least once a month15 (32.61 %)
At least once a year25 (54.35 %)

n = 46
# 46



Which of the following penetration testing methodologies do you use frequently? Please specify to which extent you use the methodology.
OWASP
At least once a week30 (40 %)
At least once a month30 (40 %)
At least once a year15 (20 %)

n = 75
# 75



Which of the following penetration testing methodologies do you use frequently? Please specify to which extent you use the methodology.
Developed in house
At least once a week39 (53.42 %)
At least once a month15 (20.55 %)
At least once a year19 (26.03 %)

n = 73
# 73



Which of the following penetration testing methodologies do you use frequently? Please specify to which extent you use the methodology.
Other
At least once a week16 (34.78 %)
At least once a month13 (28.26 %)
At least once a year17 (36.96 %)

n = 46
# 46




Do you perform all steps (when applicable) specified in the method you use the most?
Yes53 (46.9 %)
No60 (53.1 %)

n = 113
# 113




Do you do more than specified in the methodology you use the most?
Yes82 (72.57 %)
No31 (27.43 %)

n = 113
# 113




A standard gives the expected results for a test. Which of the following standards do you use? (multiple answers possible)
OWASP63 (68.48 %)
ISSAF23 (25 %)
Developed in house57 (61.96 %)
Other (please specify)7 (7.61 %)

n = 92
# 150




Do you use a formal method to determine the classification of the found vulnerability?
MITRE-CVE44 (48.35 %)
CVSS37 (40.66 %)
RAV from OSSTMM12 (13.19 %)
Security scanner defaults30 (32.97 %)
Developed in house40 (43.96 %)
Other (please specify)8 (8.79 %)

n = 91
# 171




Which of the following aspects do you take into account when assessing the risk of a vulnerability?
Remote vs. local68 (72.34 %)
Complexity to exploit69 (73.4 %)
Availability to others44 (46.81 %)
Information needed (like credentials)62 (65.96 %)
Availability, integrity and confidentiality73 (77.66 %)
Requirements of the organization38 (40.43 %)
Importance of information or processes on the system63 (67.02 %)
Nr of systems affected28 (29.79 %)
Remediation effort40 (42.55 %)
Other (please specify)9 (9.57 %)

n = 94
# 494




Which of the following do you have in your report?
The name of the client76 (82.61 %)
A description of the systems72 (78.26 %)
Period of the test85 (92.39 %)
Which method is used73 (79.35 %)
Which criteria were used68 (73.91 %)
Restrictions63 (68.48 %)
Distribution restrictions48 (52.17 %)
Who is responsible for what (Tester/Client relationship)43 (46.74 %)
Summary of the tests84 (91.3 %)
A description of the performed tests69 (75 %)
Conclusion80 (86.96 %)
Recommendations85 (92.39 %)
Date of the report83 (90.22 %)
Name and place of the tester55 (59.78 %)

n = 92
# 984




Which of the following describes the management summary or the conclusion of your report the best:
A list of findings25 (25.51 %)
A list of risks28 (28.57 %)
A judgment about the state of security45 (45.92 %)

n = 98
# 98




What is your gender
Male90 (92.78 %)
Female7 (7.22 %)

n = 97
# 97




Which of the following age groups are you in?
Under 182 (2.06 %)
18 to 2513 (13.4 %)
25 to 3551 (52.58 %)
35 to 4519 (19.59 %)
45 to 6010 (10.31 %)
60+2 (2.06 %)

n = 97
# 97




In which sector do you work?
Financial21 (21.88 %)
Consumer Goods and Retail3 (3.13 %)
Professional Services27 (28.13 %)
Trade and Industry1 (1.04 %)
Energy and Utilities2 (2.08 %)
Technology, Media and Telecom25 (26.04 %)
Construction, Real Estate and Infrastructure1 (1.04 %)
Public Sector11 (11.46 %)
Non Profit5 (5.21 %)

n = 96
# 96




If you work in the private sector, what type of company do you work for?
Self employed10 (12.5 %)
Small local business14 (17.5 %)
Large local business11 (13.75 %)
Branch of national company13 (16.25 %)
Branch of multi-national company32 (40 %)

n = 80
# 80




How often do/did you perform a penetration test?
At least once a week28 (29.79 %)
At least once a month32 (34.04 %)
At least once a year23 (24.47 %)
Not anymore6 (6.38 %)
Never5 (5.32 %)

n = 94
# 94




For how long have you been performing penetration tests
None10 (10.64 %)
Less than a year12 (12.77 %)
1-5 years47 (50 %)
5-10 years15 (15.96 %)
10+ years10 (10.64 %)

n = 94
# 94




How big is the team you work in (and also perform penetration tests)?
None8 (8.51 %)
Only me17 (18.09 %)
2-543 (45.74 %)
6-1015 (15.96 %)
11-206 (6.38 %)
21+5 (5.32 %)

n = 94
# 94



Legend:
n = Number of respondents that has seen the queston
# = Number of received answers


Hits: 2260
Added: 2011-06-13 11:12:30
Updated: 2011-09-04 21:04:24
 
Olderchurch Web Site About Us | Site Map | Contact Us | ©2012 Olderchurch Security Consultancy