Ethical hackers get industry association

By David Meyer, ZDNet UK
Friday, April 25, 2008 12:33 PM

An industry association has been created for ethical hackers, in a bid to reassure buyers of systems and applications that such products have been sufficiently tested.

The Council of Registered Ethical Security Testers (Crest) made its public debut on Wednesday at the Infosecurity Europe conference in London. The aim of the council is to standardize ethical penetration testing and provide professional qualifications for the testers.

Crest chair Paul Docherty said: "Penetration testing is a widely accepted method of assuring information security and has become an integral part of many organisations' operational and technology risk management programs."

"Yet despite the widespread use of penetration testing, there has historically been a definite lack of agreed commercial standards and practices. We formed Crest with a number of other providers in order to supply a high level of standard to companies who engage with security testers," he added.

Crest's advisory panel includes representatives from insurance group Aviva, Lloyds TSB and the NHS. Aviva's David King said the organization would "provide an industry standard to allow the purchasing community to have confidence [in the products they are buying]".

Member companies are part of the new Crest trade body, which will govern the Crest professional body that provides for individuals who are not employed by the member companies, in areas such as exams.

Crest is running certification examinations in two streams: infrastructure testing and Web-application testing. Testers can either apply for certification at the corporate level or on a standalone level as a "Crest associate".


See also:  Security
WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Mainsoft: Opening options for Java, .NET developers

Java

Mainsoft provides tools for running .NET code on the Java platform.


Read more »


Tags

  1. against
  2. antivirus
  3. apple
  4. asia
  5. asian
  6. attacks
  7. by
  8. critical
  9. cyber
  10. data
  11. flaws
  12. google
  13. issues
  14. malware
  15. microsoft
  16. online
  17. over
  18. pledges
  19. security
  20. software
  21. spore
  22. symantec
  23. threats
  24. uk
  25. updates
  26. us
  27. vista
  28. web
  29. windows
  30. word
 
Oracle SOA Business Software Centre
Many companies are recognizing the need to adopt standards in their efforts to build service-oriented applications.
Secure the "Next-Gen SOA Infrastructure" & "Bringing SOA Value Patterns to Life" whitepapers here

» Visit the Power Center
Increase performance with eco-technology innovations
Simplify your infrastructure and unify management, while lowering power and cooling costs of your datacenter.
» Maximum flexibility with powerful blade technolgy
» Bring new services and applications online faster
» Lower energy use and cost

Up close and personal with a merger

Blog thumbnail

What can you get for 13.9 billion buckaroos? For Hewlett-Packard, US$13.9 billion would allow you to buy your way into becoming the second biggest IT services company in the industry...... by Eileen Yu

Read more »