More on the Search for Low-Hanging Fruit: Improving Security and Privacy with Penetration Testing

by Bryan Miller

Since my article appeared in the August issue of Cutter IT Journal (see "In Search of Low-Hanging Fruit: Improving Security and Privacy with Penetration Testing," Vol. 22, No. 8), I have talked with several clients and read other articles that have cited additional reasons for not properly auditing the security of networks and applications. In an August 2009 article [1], security researcher and blogger Jeremiah Grossman lists several reasons companies give for not performing adequate application testing. Some of these include the following:

Password Protected Cutter Consortium clients, please log in:


This document is available to Cutter Consortium Resource Center clients only. Retrieve your password.
If you would like further information about how to become a client, please contact us at +1 781 648 8700 or sales@cutter.com, or you can Request Guest Access.
More on the Search for Low-Hanging Fruit: Improving Security and Privacy with Penetration Testing21 October 2009