Penetration Testing, Compliance & Cybersecurity Review query

VikasY
Kilo Contributor

Q1: I read the article on HiPortal around what ServiceNow doesn't allow to do in penetration testing like no network layer testing, no DDoS etc. However, we may hire someone externally to do the pen testing on one of our sub prod instances, but would like to know what layers we can test in terms of PEN Testing?

Q2: Are there any restrictions on running vulnerability scans on prod or uat instances?

Q3: MID Servers etc. that are on prem - ServiceNow shouldn't have any problem with running pen testing on those servers, right?

Q4: ServiceNow probably does their own pen testing and/or vulnerability scans - how can we request a copy for our security team to review?

5 REPLIES 5

rossalex
Kilo Explorer

Think for a second about how much information is in your smartphone. A hacker attack is a real chaos for any device. Personal photos, long-collected news and emails, a banking application, valuable business information, your location. What if someone other than you gets access to this information? Unfortunately, when it comes to cybersecurity, we still feel too confident, and this leads to a record number of attacks that each of us is exposed to. Especially smartphone owners. I believe you need to learn more about jealouscomputers.com since this is very important!