Case Project 1-1: Determining Legal Requirements for Penetration Testing
Alexander Rocco Corporation, a large real estate management company in Maui, Hawaii, has contracted your computer consulting company to perform a penetration test on its computer network. Penetration testers are hired to Source: Sawmill Figure 1-12 Source IP addresses of logged events Source: Sawmill Figure 1-13 Source cities of logged events attack an organization's network, determine what vulnerabilities are present, and provide recommendations for securing the company's information systems. The management company owns property that houses a five-star hotel, golf courses, tennis courts, and restaurants. Claudia Mae, the vice president, is your only contact at the company. To avoid undermining your tests, you will not be introduced to any IT staff or employees. Claudia wants to determine what you can find out about the company's network infrastructure, network topology, and vulnerabilities without any assistance from her or company personnel. Based on this information, write a report outlining the steps you should take before beginning the penetration tests. Research applicable state and federal laws, and reference them in your report.