Currently, issues of security of information systems of critical information infrastructure facilities are becoming relevant. At the same time, the current tasks of an information security (IS) audit of critical information infrastructure objects, as a rule, come down to checking them for compliance with IS requirements. However, with this approach to auditing, the resistance of these objects to real attacks by intruders often remains unclear. To test this resistance, objects are subjected to a testing procedure, namely penetration testing. The goal is a comparative analysis of existing foreign and domestic penetration testing methods and standards. The elements of novelty of the work are the identified features, advantages, disadvantages and scope of applicability of existing standards and methods of penetration testing. This article will review the OpenVAS vulnerability scanner. Readers will become familiar with the basic and advanced functions of the program; its settings depend on the functions and capabilities.
Read full abstract