Receive our weekly newsletter

First name:
Surname:
E-mail:
Thursday 1st May 2008

CREST anybody?

Courtesy:http://www.crest-approved.org/Pages/AboutUs.html

Neither the toothpaste, nor the Centre for Renewable Erergy Systems Technoloyg at Loughborough Universit (http://www.lboro.ac.uk/crest/ ) CREST or the Council of Registered Ethical Security Testers has been launched to create standards and qualification for penetration testing of computer systems. Already an established and widely accepted method of assuring information security. the commercial IT security industry has until now been largely free of standards and professional qualifications. These factors inspired a number of the leading providers of penetration testing services to collaborate and today launch the industry association, CREST

 CREST  Council chairman, Paul Doherty says “Despite the widespread use of penetration testing, there has historically been a definite lack of agreed commercial standards and practices. We formed CREST with a number of other providers in order to supply a high level of standard to companies who engage with security testers.”  
 
The organisation's stated aim is “to represent the information security testing industry and offer a provable level of assurance as to the competency of organisations and individuals within those organisations”. This is achieved by publishing and ensuring standards of service from member companies, and providing professional development through technical qualifications for individuals.

Since the start of 2008,  CREST has been running certification examinations  and currently offers two certification tracks: infrastructure testing and web application testing.
 
“CREST is a great example of industry getting together for the purpose of raising standards and establishing best practice. There is a real need for consistency and assurance of quality in the security testing industry, and the standards and processes which CREST has established will be of real benefit to organisations which use security testing services for penetration testing and ethical hacking,”   add s Dr David King, Head of Information Risk Management at Aviva & chair of the Information Security Awareness Forum.
 
CREST Chairs and Advisory Committee:
Paul Docherty – Chair
Mark Raeburn – Chair of Operations Committee
Paul Vlissidis – Deputy Chair of Operations Committee
Alex Church – Chair of Technical Committee
Dominic Beecher – Deputy Chair of Technical Committee
Paul Midian – Chair of Standards Committee
Martin Law – Deputy Chair of Standards Committee.
Mark Stanhope – Chair of Advisory Panel (Lloyds TSB)
David King – Member of Advisory Panel (Aviva)
James Wood – Member of Advisory Panel (NHS)

Source: http://www.crest-approved.org/Pages/AboutUs.html

Designed and maintained by Beachshore Design