On May 15, 2006, at 4:54 PM, TRODAT wrote:
This is a hot topic as of late where I work:

Once a system has gone into 'production' should testing, specifically security, be done on it if the system could be broken by the test itself?

What is your take on this issue and why?

Yes, although you should schedule possible intrusive or disruptive security/pentesting for an appropriate time where you can afford to recover from any problems which occur.

Most systems which fail under testing have sufficient issues that they fail under some naturally-occurring load conditions. Backups are your friends.


freebsd-questions@freebsd.org mailing list
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Reply via email to