MIND THE GAP: GOING BEYOND PENETRATION TESTING

No ratings

Presented at RiskSecToronto 2017 by

Subjects like IT security management, threat modelling, incident response and security architecture improvement aren't usually addressed in most penetration tests, and compliance driven audit processes rarely extend beyond the regulation or standard that is being audited. This talk will cover a few great ways to examine, analyze, review and improve organizational and product-oriented security programs using data and experience from Rapid7's consulting teams and will examine frameworks used for security program improvement and review, and discuss common gaps in security programs at different stages of maturity and in different verticals.