Browse Definitions :
Definition

social engineering penetration testing

Contributor(s): Matthew Haughn

Social engineering penetration testing is the practice of attempting typical social engineering scams on a company’s employees to ascertain the organization's level of vulnerability to that type of exploit.

Social engineering pen testing is designed to test employees' adherence to the security policies and practices defined by management. Testing should provide a company with information about how easily an intruder could convince employees to break security rules or divulge or provide access to sensitive information. The company should also get a better understanding of how successful their security training is and how the organization stacks up, security-wise, in comparison to their peers. 

Social engineering testing may be conducted as part of more comprehensive penetration tests (pen tests). Like ethical hacking methods, the tests themselves generally replicate the types of efforts that real-world intruders use.

Physical testing, for example, might involve a tester trying to enter a secured building at a time when many employees are entering, perhaps talking on a phone and carrying multiple items to see if someone just holds the door open rather than adhering to the approved procedure of letting the door close after them so any person following must use an employee card or badge for entry. 

Phishing exploits, a common social engineering method, are often used to test employee vulnerability. Testers might send an email purportedly from someone in management asking the employee to open an unexpected attachment, provide sensitive information or visit an unapproved website.

A tester might call employees pretending to be someone in IT, providing them with new passwords and telling them to change their current passwords to the new ones. 

See Valerie Thomas' presentation on social engineering pen testing:

 

This was last updated in January 2015

Continue Reading About social engineering penetration testing

Join the conversation

2 comments

Send me notifications when other members comment.

Please create a username to comment.

There's certainly not enough of this testing taking place today. Many people think their vulnerability scans using a free/open source vulnerability scanner is all that's needed. Those are often the people who end up here:
http://www.privacyrights.org/data-breach

Cancel
Do this. Do this A LOT. Do it regularly. I would even take the time to educate the C-suite folks about the importance of this. And make it tied to HR, bonuses, evaluations. If someone in your business is leaving the door open for thieves and data breaches, they should not be your employee. Test people and educate them.
Cancel

-ADS BY GOOGLE

File Extensions and File Formats

SearchCompliance

  • compliance audit

    A compliance audit is a comprehensive review of an organization's adherence to regulatory guidelines.

  • regulatory compliance

    Regulatory compliance is an organization's adherence to laws, regulations, guidelines and specifications relevant to its business...

  • Whistleblower Protection Act

    The Whistleblower Protection Act of 1989 is a law that protects federal government employees in the United States from ...

SearchSecurity

  • Transport Layer Security (TLS)

    Transport Layer Security (TLS) is a protocol that provides authentication, privacy, and data integrity between two communicating ...

  • van Eck phreaking

    Van Eck phreaking is a form of electronic eavesdropping that reverse engineers the electromagnetic fields (EM fields) produced by...

  • zero-trust model (zero trust network)

    The zero trust model is a security model used by IT professionals that requires strict identity and device verification ...

SearchHealthIT

SearchDisasterRecovery

  • cloud insurance

    Cloud insurance is any type of financial or data protection obtained by a cloud service provider. 

  • business continuity software

    Business continuity software is an application or suite designed to make business continuity planning/business continuity ...

  • business continuity policy

    Business continuity policy is the set of standards and guidelines an organization enforces to ensure resilience and proper risk ...

SearchStorage

  • solid-state storage

    Solid-state storage (SSS) is a type of computer storage media made from silicon microchips. SSS stores data electronically ...

  • persistent storage

    Persistent storage is any data storage device that retains data after power to that device is shut off. It is also sometimes ...

  • computational storage

    Computational storage is an information technology (IT) architecture in which data is processed at the storage device level to ...

Close