期刊论文详细信息
Australasian Journal of Information Systems
Penetration Testing Professional Ethics: a conceptual model and taxonomy
Ashley Jones1  Matthew Warren1  Justin Pierce1 
[1] Justin Pierce
关键词: Penetration testing;    computer security;    computer ethics;    ethics;   
DOI  :  10.3127/ajis.v13i2.52
学科分类:计算机科学(综合)
来源: University of Canberra * Faculty of Information Sciences and Engineering
PDF
【 摘 要 】

In an environment where commercial software is continually patched to correct security flaws, penetration testing can provide organisations with a realistic assessment of their security posture. Penetration testing uses the same principles as criminal hackers to penetrate corporate networks and thereby verify the presence of software vulnerabilities. Network administrators can use the results of a penetration test to correct flaws and improve overall security. The use of hacking techniques, however, raises several ethical questions that centre on the integrity of the tester to maintain professional distance and uphold the profession. This paper discusses the ethics of penetration testing and presents our conceptual model and revised taxonomy.

【 授权许可】

Unknown   

【 预 览 】
附件列表
Files Size Format View
RO201912020430935ZK.pdf 135KB PDF download
  文献评价指标  
  下载次数:9次 浏览次数:20次