CSIS 343 – Cyber security
Week 5
3rd November
Assignment 5: Penetration Testing Plan
Due Week 5 and worth 75 points
Imagine you are an ethical hacker and cybersecurity consultant hired by a financial institution to conduct
a penetration test of their network infrastructure and web applications. Your task is to develop a
comprehensive Penetration Testing Plan to assess the security of their systems and identify
vulnerabilities. Write a three to five-page paper in which you:
1. Introduction to Penetration Testing: Provide an introduction to penetration testing, explaining its
purpose and benefits, and why it's crucial for assessing and improving security.
2. Scope of Testing: Clearly define the scope of the penetration test, specifying which systems,
networks, and applications will be tested. Discuss any limitations or exclusions.
3. Testing Objectives: Define the objectives of the penetration test, emphasizing the need to identify
vulnerabilities, assess the organization's security posture, and recommend remediation actions.
4. Rules of Engagement: Establish rules of engagement for the test, including the time frame,
notification to system owners, and guidelines for avoiding disruption to business operations.
5. Testing Methodology: Explain the methodology and techniques that will be used during the
penetration test, including network scanning, vulnerability assessment, and exploitation.
6. Tools and Resources: Provide a list of tools and resources that will be used for testing, such as
vulnerability scanners, penetration testing frameworks, and documentation templates.
7. Testing Reporting: Describe the format and content of the penetration test report, including the
identification of vulnerabilities, risk assessments, and recommendations for remediation.
8. Remediation Recommendations: Explain how the organization should prioritize and address
identified vulnerabilities and weaknesses based on the severity and potential impact.
9. Post-Testing Actions: Outline post-testing actions, such as debriefing meetings, documentation of
lessons learned, and plans for follow-up testing.
10. Continuous Improvement: Suggest strategies for the organization to continuously improve its
security posture based on the results and findings of the penetration test.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all
sides; citations and references must follow APA or school-specific format. Check with your
professor for any additional instructions.
Include a cover page containing the title of the assignment, the student’s name, the professor’s
name, the course title, and the date. The cover page and the reference page are not included in
the required assignment page length.
The specific course learning outcomes associated with this assignment are:
Compare and contrast the methods of disaster recovery and business continuity.
Explain risk management in the context of information security.
Use technology and information resources to research issues in disaster recovery.
Write clearly and concisely about disaster recovery topics using proper writing mechanics and
technical style conventions.
Grading for this assignment will be based on answer quality, logic / organization of the paper, and
language and writing skills, using the following rubric.
Points: 50 Assignment 5: Penetration Testing Plan
Criteria Unacceptable
Below 60% F
Meets Minimum
Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Analyze
proper physical
access control
safeguards and
provide sound
recommendatio
ns to be
employed in the
registrar's
office.
Weight: 21%
Did not submit or
incompletely analyzed
proper physical access
control safeguards and
did not submit or
incompletely provided
sound recommendations
to be employed in the
registrar's office.
Insufficiently
analyzed proper
physical access
control safeguards
and insufficiently
provided sound
recommendations
to be employed in
the registrar's
office.
Partially9analyz
ed proper
physical access
control
safeguards and
partially9provid
ed sound
recommendatio
ns to be
employed in the
registrar's
office.
Satisfactorily
analyzed proper
physical access
control safeguards
and satisfactorily
provided sound
recommendations
to be employed in
the registrar's
office.
Thoroughly
analyzed proper
physical access
control safeguards
and thoroughly
provided sound
recommendations
to be employed in
the registrar's
office.