Penetration testing
Term · Cybersecurity · MLC-T-CYB-003071
1. Testing used in vulnerability analysis for vulnerability assessment, trying to reveal vulnerabilities of the system based on the information about the system gathered during the relevant evaluation activities.
2. A method of testing where testers target individual binary components or the application as a whole to determine whether intra or intercomponent vulnerabilities can be exploited to compromise the application, its data, or its environment resources.
3. A test methodology in which assessors, typically working under specific constraints, attempt to circumvent or defeat the security features of a system.
4. A test methodology in which assessors, typically working under specific constraints, attempt to circumvent or defeat the security features of an information system.
5. A test methodology in which assessors, using all available documentation (e.g., system design, source code, manuals) and working under specific constraints, attempt to circumvent the security features of an information system.
6. Security testing in which evaluators mimic real-world attacks in an attempt to identify ways to circumvent the security features of an application, system, or network. Penetration testing often involves issuing real attacks on real systems and data, using the same tools and techniques used by actual attackers. Most penetration tests involve looking for combinations of vulnerabilities on a single system or multiple systems that can be used to gain more access than could be achieved through a single vulnerability.
7. Testing that verifies the extent to which a system, device or process resists active attempts to compromise its security.
8. A test methodology intended to circumvent the security function of a system.
Note: Penetration testing may leverage system documentation (e.g., system design, source code, manuals) and is conducted within specific constraints. Some penetration test methods use brute force techniques.
| Identifier | MLC-T-CYB-003071 |
|---|---|
| Field | Cybersecurity |
| References | NIST SP 800-160v1r1 from ISO/IEC 19989-3:2020; NIST SP 800-95 from DHS Security in the Software Lifecycle; NIST SP 800-12 Rev. 1 from NIST SP 800-53; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5; CNSSI 4009-2015 from NIST SP 800-53 Rev. 4; NIST SP 800-53 Rev. 4 [Superseded]; NIST SP 800-137 from NISTIR 7298; NIST SP 800-53A Rev. 4 [Superseded]; NIST SP 800-115; NIST SP 800-152; NIST SP 800-160 Vol. 1; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003071",
"term": "Penetration testing",
"field": "Cybersecurity",
"definition": "1. Testing used in vulnerability analysis for vulnerability assessment, trying to reveal vulnerabilities of the system based on the information about the system gathered during the relevant evaluation activities.\n\n2. A method of testing where testers target individual binary components or the application as a whole to determine whether intra or intercomponent vulnerabilities can be exploited to compromise the application, its data, or its environment resources.\n\n3. A test methodology in which assessors, typically working under specific constraints, attempt to circumvent or defeat the security features of a system.\n\n4. A test methodology in which assessors, typically working under specific constraints, attempt to circumvent or defeat the security features of an information system.\n\n5. A test methodology in which assessors, using all available documentation (e.g., system design, source code, manuals) and working under specific constraints, attempt to circumvent the security features of an information system.\n\n6. Security testing in which evaluators mimic real-world attacks in an attempt to identify ways to circumvent the security features of an application, system, or network. Penetration testing often involves issuing real attacks on real systems and data, using the same tools and techniques used by actual attackers. Most penetration tests involve looking for combinations of vulnerabilities on a single system or multiple systems that can be used to gain more access than could be achieved through a single vulnerability.\n\n7. Testing that verifies the extent to which a system, device or process resists active attempts to compromise its security.\n\n8. A test methodology intended to circumvent the security function of a system.\nNote: Penetration testing may leverage system documentation (e.g., system design, source code, manuals) and is conducted within specific constraints. Some penetration test methods use brute force techniques.",
"references": [
"NIST SP 800-160v1r1 from ISO/IEC 19989-3:2020",
"NIST SP 800-95 from DHS Security in the Software Lifecycle",
"NIST SP 800-12 Rev. 1 from NIST SP 800-53; NIST SP 800-53 Rev. 5; NIST SP 800-53A Rev. 5",
"CNSSI 4009-2015 from NIST SP 800-53 Rev. 4; NIST SP 800-53 Rev. 4 [Superseded]",
"NIST SP 800-137 from NISTIR 7298; NIST SP 800-53A Rev. 4 [Superseded]",
"NIST SP 800-115",
"NIST SP 800-152",
"NIST SP 800-160 Vol. 1",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/penetration-testing/"
}
Record 3,055 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.