Frameworks e metodologias que guiam nossas operações ofensivas e defensivas.
FIPS 140-3
Security requirements for cryptographic modules
- •Assessment of cryptographic primitives and implementations
- •Key protection inside the module and resistance to extraction
- •Authentication, integrity and self-test
- •Criteria to accept or reject an implementation
NIST SP 800-57
Recommendations for key management
- •Lifecycle: generation, distribution, use, rotation and destruction
- •Lifetime and cryptographic strength per protection horizon
- •Separation of duties and custody
- •Assessment of HSM and secret storage
OWASP FSTM
Firmware Security Testing Methodology
- •Nine stages, from obtaining the firmware to exploitation
- •Extraction and file system analysis
- •Partial and full emulation for controlled execution
- •Dynamic analysis and binary review
IEC 62443
Security for industrial automation systems
- •Zones, conduits and segmentation of OT environments
- •Security levels defined per critical process
- •Requirements for supplier, integrator and operator
- •Applied to industry, energy and infrastructure
PTES
Penetration Testing Execution Standard
- •Pre-engagement and rules of engagement
- •Intelligence gathering and threat modelling
- •Vulnerability analysis and exploitation
- •Post-exploitation and executive/technical reporting
OWASP
Open Web Application Security Project
- •Reference for web application security
- •Top 10 most critical vulnerabilities
- •Testing methodology for applications and APIs
- •Secure development guides
MITRE ATT&CK
Adversarial Tactics, Techniques, and Common Knowledge
- •Mapping of tactics and techniques used by real adversaries
- •14 tactics covering the full attack lifecycle
- •Identification of gaps in detection and response
- •Basis for threat intelligence and adversary emulation