EECT029 Cyber Security

  • Subject Code :  

    EECT029

  • Country :  

    UK

  • University :  

    Coventry University

Answers:

Statutory And Ethical Considerations Of a Penetration Tester Working In The Uk 

Penetration testing is also known as ethical hacking. It is an authorized kind of cyber-attack that is done on a computer system as a way of preventing the actual cyber-attack from occurring. It is often performed to ensure that a computer is secure enough. It involves identifying the various vulnerabilities that a system might have which includes the possibility of unauthorized users finding a loophole and getting access into the system and end up causing problems with the system or even maybe using the information obtained to manipulate the system to their advantage. The insecurity issues discovered during penetration testing should be reported to t5he owner of the system and in case it is an organization the same step should be taken, reporting to the concerned personnel. Penetration test helps an organization to come up with countermeasures to ensure the security of the system. (Bishop, 2017)

The National Cyber Security Center in the United Kingdom defines penetration testing as an attempt to ensure the security of a computer system by trying to breach information and resources of the system using tools and techniques that a social engineer would use to manipulate the system. The objectives of performing penetration tests vary from client to client depending on the activity focusing on the main goal of finding the loopholes that the system has that could be sued by an engineer to cause harm to the system. (Weidma, 2014)

In this section, we present the various ethical issues faced by penetration testers in the UK. The section shows how penetration taster value ethics is concerned with penetration testing. The ethical considerations that are to be considered by every penetration tester have a code of ethics and also enable the testers to show some good practice in their work. The code of ethics includes the need to work with the new techniques and tools in doing the test and also enables the testers to be up to date with rules and regulations.

Penetration testers are expected to understand what they are dealing with before undertaking any form of testing. The decision they make should the result of the influence from the ethical, procedural, and technical practice they have covered. Penetration testers are required to undergo training before indulging in any type of activity related to the process.

Penetration testers are not to be ambiguous in their work. They need to be clear enough with their work and give clear results to the owner of the system. In- case of any ambiguity of a penetration tester, the professional level will be questioned and might end in termination of services. The professional has to make the client confident enough about the kind of services offered by ensuring that there is enough trust from the client. (Whitaker and Newman, 2015)

A scholar comes up with a conceptual model strictly for penetration testing ethics which focuses on the virtue of integrity. This model is grounded in specialized writing of infiltration testing, and codes of training, which envelop it. The part of the model indicates to give rules to how it affects moral programmers to act morally. For example, if infiltration analyzers will not draw in with criminal programmers, they are utilizing their abilities just for charged tests and are maintaining the calling. Notwithstanding, there are various ways that infiltration analyzers may neglect to maintain the calling. Additionally, the system suggests that acting legitimately is inseparable from carrying on morally. This neglects to perceive situations of legitimate uncertainty; infiltration analyzers should unload these to decide the proper activity. ( Stewart and Randolph 2014)

Tools, Procedures, And Techniques In The Context Of Penetration Test

Tools

They are several tools that one can use in performing penetration testing. The tools used in the industry today include;

Nmap

This kind of tool is used for both security and network auditing. It provides detailed information on the website and also detects any vulnerabilities of the system.

Nessus

It is a kind of vulnerability detection tool that enables testers to identify any loopholes in a website and any presence of malware.

Metaspoilt

This pen-testing instrument is a system and not a particular application. You can utilize this to make custom devices for specific errands. You can utilize Metasploit to;

  • Select and arrange the adventure to be focused on
  • Select and arrange the payload to be utilized
  • Select and arrange the encoding outline
  • Execute the endeavor
 

Penetration testing tools are often evaluated according to the factors below;

  1. The cost of the tool to be used includes any fee such as training and support fee.
  2. The vendor that is selling the tool, or rather if the tool to be used is open source
  3. The availability and the level of support for the tool
  4. The user interface of the tool either a command line or a graphical user interface
  5. The availability of a firewall auditor
  6. The training on how to use the tool that is in place for testing
  7. The mode that the tool in use is to operate

Methods And Procedures Used

The results that are given after a penetration test entirely depend on the methodology used in performing the test. Organizations have implemented measures to ensure that here systems are working just perfectly, but apart from that, they are also looking for more advanced methodologies to use to perform penetration testing in their system just to cover up loopholes that could be exploited by social engineers to cause harm.

Owasp

The Open Web Application is the most used methodology in the industry. This methodology stays updated with the newest technologies and has been helpful to most organizations in detecting vulnerabilities. This type of methodology is used to detect weaknesses in websites and applications used in mobiles. It also detects the complicated errors that crop up during the development of a system. Any organization planning to develop a website or an application should opt for this to ensure that the system is secure enough. Having this methodology in place organizations can be sure of secured systems. This type of methodology differs from any other because it is to be used during the development of an application or a website.

Ptes

The Penetration Testing Methodologies and Standards is one methodology recommended in giving the whole structure and steps to be followed during a penetration test. It gives the guidelines in performing a penetration test, these are the steps which include; initial communication, collection of information, and the danger modeling phases. This type of standard ensures that the testers have identified themselves well with the organization system and technologies before manipulating the weakness that the system might have to identify the serious events of attacks that might occur. The testers are also given a chance to check on the previous exploitation test and try to verify the weakness found and how they were fixed. The standard differs from other methodologies since it gives a seven-phased procedure of the penetration test. ( Mayne, 2017)

Osstmm

This type of standard gives a scientific methodology that is to be used in network penetration testing and the assessment of vulnerability. It gives a guide to testers to identify the weakness in a network system and its various components. It requires the tester to have knowledge of the vulnerabilities that a system might have and the harm that it can bring to the network. This type of standard is meant to give support to network developers during the setting up of a network system.

Nist 

The National Institute of Standards and Technology gives an overall guideline on the measures to be taken in the in-case of cybersecurity attacks. NIST is a have standard for American business persons. It is aimed at ensuring that there is information security in industries, this includes; communications and banking. NIST give pre-established guidelines that companies need to follow during a penetration test to meet the standards of NIST. This methodology ensures that companies meet their cybersecurity controls enabling them to curb the risks of experiencing attacks on the system. ( McDermott,  2011)

Issaf

This strategy is known as Information System Assessment Framework utilized in infiltration testing. This strategy permits the analyzers to execute each progression of the entrance test.

(Bishop, 2017)The approach covers every one of the prerequisites of the testing interaction. At the point when one is utilizing various instruments, ISSAF is the best system to go for. ISSAF offers nitty-gritty data on the various assaults that are to happen. The data offered by the approach allows the analyzer to anticipate an assault that will ensure an association ideal security from any digital assaults.

We provide unmatched quality assignment writing services for all subjects in your curriculum. The most common subjects we cover include Maths, English, Humanities, Social Sciences, Management and more. Our experts have acquired their respective PhDs in specific disciplines from reputed universities. Tell us the subject you need ghostwriters for. We will assign a suitable ghostwriter accordingly. We are not restricted to writing assignments only. We also provide top-notch proofreading services and essay writing services. The essay writers are well-versed in all types of essays such as persuasive, expository, narrative, argumentative, persuasive, etc. Whether you need math homework help or English homework help, we have the right expert for you.

Why Student Prefer Us ?
Top quality papers

We do not compromise when it comes to maintaining high quality that our customers expect from us. Our quality assurance team keeps an eye on this matter.

100% affordable

We are the only company which offers qualitative and custom assignment writing services at low prices. Our charges will not burn your pocket.

Timely delivery

We never delay to deliver the assignments. We are very particular about this. We assure that you will receive your paper on the promised date.

Round the clock support

We assure 24/7 live support. Our customer care executives remain always online. You can call us anytime. We will resolve your issues as early as possible.

Privacy guaranteed

We assure 100% confidentiality of all your personal details. We will not share your information. You can visit our privacy policy page for more details.

Upload your Assignment and improve Your Grade

Boost Grades