Ethical hackers get industry association
Published: 24 Apr 2008 11:09 BST
An industry association has been created for ethical hackers, in a bid to reassure buyers of systems and applications that such products have been sufficiently tested.
The Council of Registered Ethical Security Testers (Crest) made its public debut on Wednesday at the Infosecurity Europe conference in London. The aim of the council is to standardise ethical penetration testing and provide professional qualifications for the testers.
Read this
Infosecurity Europe 2008: Special report
All the latest news and blogs from the security industry's biggest UK event...
"Penetration testing is a widely accepted method of assuring information security and has become an integral part of many organisations' operational and technology risk management programs," said Crest chair Paul Docherty. "Yet despite the widespread use of penetration testing, there has historically been a definite lack of agreed commercial standards and practices. We formed Crest with a number of other providers in order to supply a high level of standard to companies who engage with security testers."
Crest's advisory panel includes representatives from insurance group Aviva, Lloyds TSB and the NHS. Aviva's David King said the organisation would "provide an industry standard to allow the purchasing community to have confidence [in the products they are buying]".
Member companies are part of the new Crest trade body, which will govern the Crest professional body that provides for individuals who are not employed by the member companies, in areas such as exams.
Crest is running certification examinations in two streams: infrastructure testing and web-application testing. Testers can either apply for certification at the corporate level, which costs £7,000, or on a standalone level as a "Crest associate", which will cost them £1,600 to sit the exam.
- Blog: Social networking and portability
- ICO: Data-protection spot checks due this year
- Infosecurity Europe 2008: Preview
- Security breaches down, says IT security report
- Facebook admits to increased attacks by spammers
- Security industry gears up for biggest UK event
- Vendors urged to take responsibility for security
- Media lobbying 'watered down' data-misuse laws
- HMRC data loss blamed on targets
- Former White House adviser talks mobile threats
- Security expert voices virtualisation concerns
- Lord: No proof any data was lost from HMRC
























