3 Ways Pen Testing Helps DLP (and 2 Ways it Doesn't)

Penetration testing's future has been caught in heated debate recently, sparked by Fortify Co-Founder and Chief Scientist Brian Chess' prediction that the practice would die off this year. [See: Penetration Testing: Dead in 2009]

By Bill Brenner

Mon, March 30, 2009CSO Penetration testing's future has been caught in heated debate recently, sparked by Fortify Co-Founder and Chief Scientist Brian Chess' prediction that the practice would die off this year. [See: Penetration Testing: Dead in 2009]

Many IT security practitioners rose to pen testing's defense, calling it an indispensible tool for uncovering data breach attempts from inside and outside the organization. [See: 12 Reasons Pen Testing Won't Die]

Move away from the security vendor perspective and one will almost always find that the truth is somewhere in the middle. That's been the experience of Ed Bellis, vice president and chief information security officer for Orbitz. During a presentation at last week's CSO Executive Seminar on Data Loss Prevention, Bellis described pen testing as one of many important tools in his arsenal to protect the sensitive customer data that flows throughout Orbitz's cyber pipeline.

"There are two sides to every story, including the one on pen testing," Bellis said, suggesting that vendors like Fortify will always make sweeping predictions about a technology's future while promoting its own products.

Pen testing has indeed been helpful in detecting weaknesses in Orbitz sprawling network, which includes data centers around the world with thousands of hosts and a cornucopia of internal applications that include an agent desktop, home-grown software to process transactions and back-end security controls. "The number of apps we deal with goes into infinity, and you need a variety of security tools to protect them," he said.

Zeroing in on pen testing, Bellis outlined three specific areas where the craft has proven its worth, and a couple areas where its usefulness is more limited:

Pro: Social Engineering Finder

Social engineering has always been a sure path to a company's sensitive data, and Bellis has found that the weak link is usually an insider who is trying to be helpful with no inkling of the dangers.

"Pen testing will help you catch people who try to use social networking to work their way into a call center," he said. "People working in the call center can be overly helpful when they're trying to help customers, and they can and do get burned in the process."

In this scenario, the pen tester can go hunting for cases where a call center employee is opening the door too wide. Then, those weak links can be addressed, Bellis said.

Pro: Legacy App Finder

As Bellis mentioned, the number of applications in use within Orbitz goes into infinity. Buried among them are apps that have been around forever but may no longer be in use. Yet they are sitting on the network, replete with vulnerabilities waiting to be exploited by a data thief.

Software

Loading...
Security MarketSpace
Addressing Log Management Shortfalls
High performance, affordable log and security event management technology is rapidly evolving. Learn more »
Challenges and Opportunities of PCI
Control compliance costs and build a more efficient and reliable IT infrastructure. Learn more »
Balancing Control and Agility in the Virtual Environment
Unparalleled agility is the promise of virtualization. Learn more »
The Prevalence of the Threat of Cyber Crime
This report addresses ways in which cyber security threats and risks have changed, how to more accurately assess them. Learn more »
A Risk Intelligent Executive's Guide to Security and Privacy
Assess your organization's risk intelligence and enhance your approach to security and privacy. Learn more »
PCI DSS Standards Continue to Evolve
This paper covers key strategies for PCI DSS compliance and examines reasonable risk management. Learn more »
 
SPONSORED LINKS
 

Trend Micro ranked #1 against real-world malware. Read more.

Take the Netezza TwinFin TestDrive!

Best Practices to Reduce IT Operational Costs

Maximizing efficiencies with unified communications.

Global Research: CIOs Weigh In On Virtualization

Taking the Service Desk to the Next Level

Manage limitless content todayread EMCs 15-minute guide to ECM.

HP Exstream. Get a Free Document Assessment for Financial Services.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

See why ShoreTel is named best overall VoIP provider by Nemertes Research

AT&T Application Management & Hosting. Let us help you STRETCH

Microsofts new client operating system helped Pella reduce power consumption.

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Trend Micro ranked #1 against real-world malware. Read more.

Webcast: Solve Your Data Visualization Needs with Open Source BI

Webcast: Delivering the Enterprise-Ready Cloud

Ensure cost effective application delivery. Learn More.

Cloud Computing: The Impact CIOs See

What's Next for Enterprise Resource Planning?

Gartner Magic Quadrant, Application Delivery Controllers 2009

Adobe® LiveCycle® solutions for business process automation

What's New in SOA Suite 11g?

Unleash the Power of Java with Oracle JRockit Real Time

SOA Best Practices and Design Patterns

Application Grid: Ideal Platform for IT Consolidation

Verint Systems. Discover the Power of Intelligence in Action"

Let Progress Software help your business make progress.

Efficiency goes up. Costs come down.

Cut Costs & Green Your IT Operations with PC Power Management

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

Does your IDS really work? Find out with a free Endace Audit

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Enterprise search helps employees get more done. Get the facts from Google.

Real-world testing ranks Trend Micro #1 against malware. See results.

Forrester: The real-world financial impact of Windows 7

Turn your desk phone and mobile phone into one with Sprint Mobile Integration.

Stay informed with custom newsletters from Tech Dispenser

Selecting the Right Reporting Technology

An IT Leadership Action Plan for the Economic Recovery

Consolidate data centers and lower IT service costs. Learn How.

WAN optimization techniques significantly improve application performance. Read More.

The Revolution and Evolution of Private Cloud Computing

ROI of Application Delivery Controllers

Enterprise Capture: Your Onramp to Business Process Automation

Adobe® LiveCycle®solutions for intuitive user experience

Unlocking the Mainframe: Modernizing Legacy System to SOA

State of the Data Integration Market

Enhance Customer Loyalty through Higher Responsiveness

 
 
RESOURCE CENTER