In Depth
3 Ways Pen Testing Helps DLP (and 2 Ways It Doesn't)
Orbitz CISO Ed Bellis says penetration testing is a valuable tool in his data loss prevention arsenal. But it won't help him find everything
By Bill Brenner, Senior Editor
Orbitz's priority is to protect customers from those who would use the company's websites to infect the customer -- a tall order in itself, Bellis said.
Con: Doesn't Always Work
Bellis also noted that like any security tool, sometimes the pen test won't work completely. Sometime a test will fail to find a serious weakness, he said. But then that's why it should only be seen as one tool in a larger security arsenal.
"The key is to know what you're expecting to find with a pen test and set expectations accordingly," he said. "In the end, though, no security tool is 100 percent effective on its own."
Turning back to Chess' prediction that pen testing would die out, Bellis noted that certain security technologies are always being marked for death. There was Gartner's prediction in 2003 that IDS was dead (intrusion detection and prevention systems live on today), for example.
"None of these work completely, but none of these are completely worthless," he said.
Other stories by Bill Brenner
penetration testing
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



