Presented by Heorot.net.  Understand the need for a PenTest Methodology  Identify the most-used methodologies  Understand Advantages and Limitations.

Slides:



Advertisements
Similar presentations
PROJECT MANAGEMENT BASICS
Advertisements

Successful Project Management Justice, E-Government, & the Internet June 28, 2000 – Dallas, Texas Lawrence P. Webster.
Software Quality Assurance Plan
Module 2 – PenTest Overview
Project Change Management
A framework for describing IT Project Management Processes and Tool Set Features Enterprise Project Management Framework.
Project Integration Management Sections of this presentation were adapted from A Guide to the Project Management Body of Knowledge 4 th Edition, Project.
CS Integration Management (Part 6) Bilgisayar Mühendisliği Bölümü – Bilkent Üniversitesi – Fall 2009 Dr.Çağatay ÜNDEĞER Instructor Bilkent University,
Successful Project Management Justice, E-Government, & the Internet June 28, 2000 – Dallas, Texas Lawrence P. Webster.
Project Management Session 7
Project Management based on the Project Management book of knowledge Risk Identify, analyse and respond to risks Resources Make most effective use of human.
The 9 Things in the PMBOK 19-Nov-08. The PMBOK “Project Management Body of Knowledge” –sum of knowledge within the profession of project management –used.
© 2008 Prentice Hall11-1 Introduction to Project Management Chapter 11 Managing Project Execution Information Systems Project Management: A Process and.
Project Execution.
Project Management Body of Knowledge PMBOK
The Project Management Body of Knowledge (PMBOK)
Project management INTRODUCTION. Information Technology Project Management, Fourth Edition 2 IT projects have a terrible track record. A 1995 Standish.
Project Management Framework. PMBOK ® Guide, Third Edition.
PRESENTED BY TRUST THOMAS EROMOSELE STUDENT NO:
Project Management Lecture 5+6 MS Saba Sahar.
18/21/20151 Instructor: Suprakash Datta (datta[at]cse.yorku.ca) ext Lectures: Tues (CB 122), 7–10 PM Office hours: Wed 3-5 pm (CSEB 3043), or by.
What is Business Analysis Planning & Monitoring?
Degree and Graduation Seminar Project Management Processes
Human Resources Management Course Objectives The purpose of this course is to learn the Project Management Institute (PMI) processes required to make.
Module 8: Risk Management, Monitoring and Project Control We would like to acknowledge the support of the Project Management Institute and the International.
Project Management Process Overview
PMP® Exam Preparation Course
Introduction to the PMI Project Management Body of Knowledge Pilat Management Consulting Integrated Solutions Shay Shargal, PMP
The PMBOK® Guide Distilled for the SPI Professional
Project ManagementDay 1 in the pm Project Management (PM) Structures.
Project Management. The Project Management Institute
PMI PMBOK Matt.cyt. 2 PMI Standards Background 1969 – PMI founded 1983 – PMI Special Report on Ethic, Standards, and Accreditation – the Standards portion.
Management & Development of Complex Projects Course Code - 706
What’s a Project? AD642. Why the Emphasis on Project Management? Copyright 2011 John Wiley & Sons, Inc. 1-2  Many tasks do not fit neatly into business-as-usual.
Centro de Estudos e Sistemas Avançados do Recife PMBOK - Chapter 4 Project Integration Management.
Centro de Estudos e Sistemas Avançados do Recife PMBOK - Chapter 11 Project Risk Management.
Systems Analysis & Design Project Management. 2 Question ●When someone says ‘project’ what comes to mind?
1 Our Expertise and Commitment – Driving your Success Project Management Brown Bag October 2014 Offices in New York and Northern VA.
MGT 461 Project Management Institute Knowledge Areas
Project Management April 2013 Inf Sys 3810 Information Systems Analysis Spring 2013 Understand Project Management Principles 1.
Lecture 11 Managing Project Execution. Project Execution The phase of a project in which work towards direct achievement of the project’s objectives and.
ISM 5316 Week 3 Learning Objectives You should be able to: u Define and list issues and steps in Project Integration u List and describe the components.
Project Life Cycle.
Project Management Process Groups and Knowledge Areas Source: PMBOK 4 th Edition Prepared
Dr. A.K.M. Saiful Majid Professor,IBA University of Dhaka.
Project Management Components (Part 5)
Project Management Processes for a Project
The Project Management Institute Introduction / Chapter 1.
Quick Recap. Project Initiation overview Awareness of the need for change (situation, context) and recognition by stakeholders that only a project can.
P r o j e c t : from INITIATING to CLOSING ( 1 ).
The Project Plan Plan Your Work, then Work Your Plan
Project Management Processes for a Project
Introduction To Project Management Unit 1. What is a Project? temporary endeavor undertaken to create a unique product, service, or result.
~ pertemuan 4 ~ Oleh: Ir. Abdul Hayat, MTI 20-Mar-2009 [Abdul Hayat, [4]Project Integration Management, Semester Genap 2008/2009] 1 PROJECT INTEGRATION.
Project Management Processes for a Project Chapter 3 PMBOK® Fourth Edition.
Information Security and the Project Management Body of Knowledge Kati Reiland COSC 481 Spring 2006.
The Project Management Process Groups
What is a WBS? A Work Breakdown Structure is not a list of tasks, a schedule or an organization chart. Rather it provides the basis on which a task.
Agenda  Purpose  Processes  Deliverables  Executing Activities 4.3.
Prof. Shrikant M. Harle.  The Project Life Cycle refers to a logical sequence of activities to accomplish the project’s goals or objectives.  Regardless.
Project Management PTM721S
Process and customizations
Project Management Body of Knowledge PMBOK
Project Management and Information Security
Project Management Processes
CIS12-3 IT Project Management
Project Human Resource Management
Time Scheduling and Project management
Working with Project Management Processes
Presentation transcript:

Presented by Heorot.net

 Understand the need for a PenTest Methodology  Identify the most-used methodologies  Understand Advantages and Limitations of the OSSTMM  Identify structure of the OSSTMM for Engineers and Managers

 Use the templates available in the OSSTMM  Modify the OSSTMM templates and test requirements to match your individual need

 “The objective of this manual is to create one accepted method for performing a thorough security test” – OSSTMM  OSSTMM = Project Management  “Collection of processes and knowledge areas generally accepted as best practice” - PMBOK

 Phases within a Project Initiating Planning Executing Monitoring and Controlling Closing  Processes within a Project Inputs (documents, plans, designs, etc.) Tools and Techniques (mechanisms applied to inputs) Outputs (documents, products, etc.)

 Nine Knowledge Areas within a Project Project Integration Management Project Scope Management Project Time Management Project Cost Management Project Quality Management Project Human Resource Management Project Communications Management Project Risk Management Project Procurement Management

 Project Integration Management Describes the process required to ensure that the various elements of the project are properly coordinated. It consists of: ○ project plan development ○ project plan execution ○ integrated change control

 Project Scope Management Describes the process required to ensure that the project includes all the work required to complete the project successfully. It consists of: ○ initiation ○ scope planning ○ scope definition ○ scope verification ○ scope change control

 Project Time Management describes the process required to ensure timely completion of the project. It consists of: ○ activity definition ○ activity sequencing ○ activity duration estimating ○ schedule development ○ schedule control

 Project Cost Management Describes the process required to ensure that the project is completed within the approved budget. It consists of: ○ resource planning ○ cost estimating ○ cost budgeting ○ cost control

 Project Quality Management Describes the process required to ensure that the project will satisfy the needs for which it was undertaken, It consists of: ○ quality planning ○ quality assurance ○ quality control

 Project Human Resource Management Describes the process required to make the most effective use of the people involved with the project. It consists of: ○ organizational planning ○ staff acquisition ○ team development

 Project Communications Management Describes the process required to ensure timely and appropriate generation, collection, dissemination, storage and ultimate disposition of project information. It consists of: ○ communications planning ○ information distribution ○ performance reporting ○ administrative closure

 Project Risk Management Describes the process required to ensure that the various elements of the project are properly coordinated. It consists of: ○ project plan development ○ project plan execution ○ integrated change control

 Project Procurement Management Describes the processes required to acquire goods and services from outside the performing organization. It consists of: ○ procurement planning ○ solicitation planning ○ solicitation ○ source selection ○ contract administration ○ contract closeout

 How do PenTest Methodologies fit within Project Management? Very poorly, but they are trying OSSTMM ○ Rules Of Engagement (2 pages in length) Sales and Marketing (Cost?) Assessment / Estimate Delivery (Time) Contracts and Negotiations (Procurement/Cost) Scope Definition (Scope (barely)) Test Plan (not a Knowledge Area – process) Test Process (not a Knowledge Area – process) Reporting (Communications)

 So… when does any work get done? Work Breakdown Structure (WBS) ○ Created during Scope Management ○ The 100% Rule captures all deliverables – internal, external, interim – in terms of the work to be completed ○ It is not an exhaustive list of work ○ Outcome-oriented and not prescriptive of methods

 How PenTest Methodologies succeed as a WBS Mutually exclusive elements ○ Each step within a PenTest Methodology Builds on the next without repeating effort Planned outcomes, not planned actions ○ OSSTMM provides high-level objectives ○ OSSTMM does not dictate methods

 How PenTest Methodologies fail as a WBS No heirarchy (Decomposition) No progressive elaboration of “Terminal Element”: ○ associated work statement ○ specifications ○ scheduled milestones ○ start and completion dates ○ budgets

 Does this mean a PenTest Methodology is worthless? No!

 OSSTMM (Open Source Security Testing Methodology Manual ) ○ “peer-reviewed methodology for performing security tests and metrics” ○  ISSAF ( Information Systems Security Assessment Framework) ○ “seeks to integrate the following management tools and internal control checklists” ○  NIST (National Institute of Standards and Technology)  PMBOK (Project Management Body of Knowledge)

 ISSAF ○  OSSTMM ○  NIST SP ○ Heorot.net

 ISSAF Peer-Reviewed Contains two separate documents ○ Management (ISSAF0.2.1A)‏ ○ Penetration Testing (ISSAF0.2.1B)‏ Checklists for Auditing / Hardening Systems Tool-Centric Heorot.net

 ISSAF Advantages ○ Does not assume previous knowledge ○ Provides examples of pentest tool use ○ “In the weeds” Disadvantages ○ Out of date quickly ○ Pentest tool examples are not extensive ○ Last update: May 2006 Heorot.net

 OSSTMM Peer-Reviewed Most popular methodology Assessments are discussed at a high-level Includes unique technology (RFID, Infrared)‏ Extensive templates Heorot.net

 OSSTMM Advantages ○ More flexibility for Pentesters ○ Frequent updates Disadvantages ○ Steeper learning curve Tool and OS knowledge necessary beforehand ○ Latest version requires paid subscription Heorot.net

 NIST SP Federal Publication Least comprehensive methodology Tools-oriented NIST publications rarely get updated If you can't use anything else, at least use something Heorot.net

 OSSTMM Current Version: 2.2 ○ New release arriving soon: 3.0 The more popular methodology ○ Flexibility for the penetration tester ○ Much more broad in scope ○ Easier to modify to meet your organizational needs Heorot.net

 Sections Section A – Information Security Section B – Process Security *Section C – Internet Technology Security Section D – Communications Security Section E – Wireless Security Section F – Physical Security Heorot.net

 Sections Modules ○ Each section contains 1 or more module ○ Example: Section D – Communications Security -PBX Testing -2. Voic Testing -3. FAX Review -4. Modem Testing Heorot.net

 Sections Modules ○ Description of the Module ○ Expected Results ○ Tasks Additionally (sometimes) ○ Report Templates Heorot.net

 For Managers and Project Managers Document Scope Compliance Rules of Engagement Process Security Map Risk Assessment Security Metrics Heorot.net

 Understand the need for a PenTest Methodology  Identify the most-used methodologies  Understand Advantages and Limitations of the OSSTMM  Identify structure of the OSSTMM for Engineers and Managers