Chapter 22
Ten Deadly Mistakes
IN THIS CHAPTER
Avoiding the wrong choices
Preventing security disasters
Making the wrong choices in your security testing can wreak havoc on your work and possibly even your career. In this chapter, I discuss ten potential pitfalls to be keenly aware of when performing your security assessment work.
Not Getting Approval
Getting documented approval in advance, such as via email or a formal contract for your security testing efforts — whether it’s from management or your client — is a must. Outside of laws on the books that might affect your testing, it’s your “Get Out of Jail Free” card.
Assuming That You Can Find All Vulnerabilities
So many security vulnerabilities exist — known and unknown — that you cannot possibly find them all during your testing. Don’t make any guarantees that you’ll find all the security vulnerabilities in a system. You’ll be starting something that you can’t finish.
Stick to the following ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access
Allow no exceptions — especially when you’re an outsider doing work for clients. Make sure to get a signed copy of this document to file near your general and professional liability insurance policies to ensure that you’re protected.