Title :
High-Level Methodology for Carrying out Combined Red and Blue Teams
Author_Institution :
Defence, Peace, Safety & Security (DPSS), Council for Sci. & Ind. Res. (CSIR), Tshwane, South Africa
Abstract :
Security audits and penetration testing exercises serve to determine the baseline of the security in a network/system and to identify possible avenues of exploitation. Red and Blue Team is the name given to the combined execution of these risk assessments that consist of various operational, managerial and technical activities. However, to successfully complete a combined Red and Blue Team Mission a number of principles play a significant role. This paper proposes a combined Red and Blue Team Methodology to guide the process of carrying out such security auditing and penetration testing tasks.
Keywords :
computer crime; risk management; high-level methodology; network security; penetration testing; risk assessments; security audits; Africa; Computer industry; Computer security; Councils; Electrical safety; Information security; Protection; Risk management; System testing; Technical activities; Red and Blue Team; audit; penetration testing; security;
Conference_Titel :
Computer and Electrical Engineering, 2009. ICCEE '09. Second International Conference on
Conference_Location :
Dubai
Print_ISBN :
978-1-4244-5365-8
Electronic_ISBN :
978-0-7695-3925-6
DOI :
10.1109/ICCEE.2009.177