<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itworld.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>penetration testing</title>
 <link>http://www.itworld.com/penetration-testing</link>
 <description></description>
 <language>xx</language>
<item>
 <title>Why Pen Testing Is Central to State&#039;s App Security</title>
 <link>http://www.itworld.com/security/78688/why-pen-testing-is-central-states-app-security</link>
 <description>Fortify Co-Founder and Chief Scientist Brian Chess made a stir last year when he predicted -- incorrectly, so far -- that penetration testing would be a dead art in 2009. Among those who shrugged off the suggestion was Robert Maley, CISO for the Commonwealth of Pennsylvania.
</description>
 <comments>http://www.itworld.com/security/78688/why-pen-testing-is-central-states-app-security#comments</comments>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/interview">Interview</category>
 <category domain="http://www.itworld.com/penetration-testing">penetration testing</category>
 <pubDate>Wed, 23 Sep 2009 20:35:30 -0400</pubDate>
 <dc:creator>ITworld staff</dc:creator>
 <guid isPermaLink="false">78688 at http://www.itworld.com</guid>
</item>
<item>
 <title>3 Ways Penetration Testing Helps DLP (and 2 Ways It Doesn&#039;t)</title>
 <link>http://www.itworld.com/security/65853/3-ways-penetration-testing-helps-dlp-and-2-ways-it-doesnt</link>
 <description>Penetration testing&#039;s future has been caught in heated debate recently, sparked by Fortify Co-Founder and Chief Scientist Brian Chess&#039; prediction that the practice would die off this year. Many IT security practitioners rose to pen testing&#039;s defense, calling it an indispensible tool for uncovering data breach attempts from inside and outside the organization. The truth is somewhere in the middle.
</description>
 <comments>http://www.itworld.com/security/65853/3-ways-penetration-testing-helps-dlp-and-2-ways-it-doesnt#comments</comments>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/feature">Feature</category>
 <category domain="http://www.itworld.com/data-protection">data protection</category>
 <category domain="http://www.itworld.com/penetration-testing">penetration testing</category>
 <pubDate>Mon, 06 Apr 2009 09:35:28 -0400</pubDate>
 <dc:creator>ITworld staff</dc:creator>
 <guid isPermaLink="false">65853 at http://www.itworld.com</guid>
</item>
<item>
 <title>Fuzzing and Product Security</title>
 <link>http://www.itworld.com/security/64502/fuzzing-and-product-security</link>
 <description>Finally, some real data on the usage of fuzzing is emerging. Who is using fuzzing? How do people see fuzzing being used in the product security process? Forrester has included questions regarding use of fuzzing in to their questionnaire that they send to key industry CIOs, CSOs and CISOs. Security companies such as Cigital are publishing their findings. I have talked with these organizations and will be discussing my findings in this blog and the upcoming webinar.
</description>
 <comments>http://www.itworld.com/security/64502/fuzzing-and-product-security#comments</comments>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/best-practice">Best practice</category>
 <category domain="http://www.itworld.com/analyst">analyst</category>
 <category domain="http://www.itworld.com/fuzzing">fuzzing</category>
 <category domain="http://www.itworld.com/penetration-testing">penetration testing</category>
 <category domain="http://www.itworld.com/qa">QA</category>
 <category domain="http://www.itworld.com/research">research</category>
 <category domain="http://www.itworld.com/security-testing">security testing</category>
 <pubDate>Wed, 18 Mar 2009 04:40:30 -0400</pubDate>
 <dc:creator>Ari Takanen</dc:creator>
 <guid isPermaLink="false">64502 at http://www.itworld.com</guid>
</item>
<item>
 <title>Penetration Testing: Dead in 2009</title>
 <link>http://www.itworld.com/security/59316/penetration-testing-dead-2009</link>
 <description>Penetration testing: Security experts mention it all the time as one of the essential tools of defense-in-depth. Companies have raked in the dough selling the service and the tools for years. But is it possible that penetration testing -- the art of probing company networks in search of exploitable security holes that can then be fixed -- is an idea whose time is about to expire?
</description>
 <comments>http://www.itworld.com/security/59316/penetration-testing-dead-2009#comments</comments>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/feature">Feature</category>
 <category domain="http://www.itworld.com/defense-depth">defense in depth</category>
 <category domain="http://www.itworld.com/penetration-testing">penetration testing</category>
 <pubDate>Tue, 16 Dec 2008 14:05:44 -0500</pubDate>
 <dc:creator>ITworld staff</dc:creator>
 <guid isPermaLink="false">59316 at http://www.itworld.com</guid>
</item>
</channel>
</rss>
