
By John Moore
Excerpt:
“Scottish Re decided to make security testing an inside job. The life reinsurance firm, with operating companies in the U.K., the U.S. and other countries, had been using a third-party provider for penetration testing services. In penetration testing, an authorized individual probes an organization's networks and applications for security vulnerabilities and attempts to exploit them …
“That type of security assessment has been taking place in-house for the last 18 months, says Mark Odiorne, chief information security officer and senior network systems manager at Scottish Re. The company is using Core Security's Core Impact, an automated penetration testing tool that gathers information on the network to be assessed, identifies the operating systems and services running on host computers, and scans TCP/IP ports for vulnerabilities. The tool launches attacks based on that information and then generates a report that provides a list of successfully exploited vulnerabilities.”
Source: Baseline











