Our earlier blog outlined what is penetration testing and what it entails. However, performing a penetration test can be a costly and daunting task for your organisation, giving someone permission and on some occasions sensitive information, to hack into your networks and systems can be risky. Even if the intention is to improve your security measures and identify vulnerabilities, mistakes can occur during testing. Not all penetration testing companies work with the same standards, increasing the inherent risk in carrying out a test on your organisation. This is why making sure the company providing the penetration test is highly accredited is important to your organisation.
CREST accreditation is well established as a ‘stamp of approval’ for a high-quality penetration test, this article aims to shed light on the CREST accreditation and how it differentiates penetration testers.
CREST is an international not-for-profit accreditation and certification body, registered in the UK, which represents and supports the technical information security market. CREST provides internationally recognised accreditation for organisations and professional level certification for individuals who provide penetration testing and other services such as cyber incident response, threat intelligence and Security Operations Centre (SOC) services.
To achieve CREST accreditation, companies must undergo a rigorous assessment of business processes, data security and security testing methodologies. Each and every company that is a member of CREST is required to submit policies, processes and procedures relating to their chosen cybersecurity service to CREST so that they can carry out an assessment. Once a company gets CREST accredited their journey doesn’t stop there, they are required to maintain accreditation via an ongoing process, with member companies renewing their accreditation every year, including periodic reassessment to confirm they continue to meet CREST’s standards. Also each member company is required to commit to a binding and enforceable code of conduct, which also takes into consideration resolving complaints from clients.
By choosing a CREST accredited company for your penetration testing needs, your organisation is put into safe hands. CREST accreditation is designed to ensure that testing will be carried out with the highest legal, ethical and technical standards in mind. Companies that are CREST certified follow best practice when it comes to key areas during a penetration test such as reconnaissance, scanning, gaining access and maintaining access.
Here's how your organisation can gain value from the following benefits:
CREST registered or certified penetration testers are required to pass a number of complex exams to prove that their skill, knowledge and competence is up to the highest standard. CREST certifications such as the CREST Registered Penetration Tester (CRT) remain valid for three years from the exam date, so testers must re-sit them to stay current. CREST’s Registered examinations are aimed at candidates with at least 6,000 hours of relevant and frequent professional experience, and its Certified examinations at testers with around 10,000 hours.
Customers often ask organisations to demonstrate how safe and secure their data is in their possession. By getting a CREST accredited penetration tester you are assuring your customers that you are taking security seriously and ensuring that their data is being secured by globally accepted best practices. Your organisation may also benefit from the commercial advantage gained by working with CREST accredited penetration testers.
Many information security requirements like ISO 27001, NIST Framework or PCI DSS may specify directly or indirectly that a penetration test is required. For example, PCI DSS v4.0.1 requires regular internal and external penetration testing. In Australia, APRA’s CPS 234 requires regulated entities to test their information security controls through a systematic testing program, conducted by appropriately skilled and functionally independent specialists. Working with a CREST accredited provider gives you independent evidence of your testers’ skills and methodology, and can therefore help with your organisation’s compliance efforts.
The CREST accreditation is globally recognised and accepted, making it a valid certification no matter where your organisation is located in the world. This makes it easy to assure your overseas customers that you are certified and credible when it comes to information security. If you were to choose a company that wasn’t CREST certified, or one holding a certification recognised in only a single country, your overall outcomes and credibility may suffer.
The rate at which the threat landscape is evolving is so rapid that only the very best expertise can adapt to it. By choosing to enlist the services of a CREST accredited penetration tester, you are ensuring that their knowledge is up to date. As mentioned before, CREST accredited organisations renew their accreditation every year and CREST certified testers re-sit their exams periodically. CREST also gives its member companies access to events and community activity across the technical information assurance industry, including CRESTCon events held in Australia.
Looking to identify the vulnerabilities in your cybersecurity setup? StickmanCyber's penetration testing services for Australian organisations, accredited by CREST, comb through your systems, identify possible gaps, and prepare a comprehensive list of action items to mitigate risks.
Ready to proactively take charge of your cybersecurity? Book a penetration test today!
CREST accreditation applies to companies: CREST assesses a provider’s policies, processes and procedures for a specific service, such as penetration testing, before approving its membership. CREST certification applies to individuals, who must pass CREST’s professional examinations, such as the CRT or the CREST Certified Tester exams. For the strongest assurance, look for an accredited company whose testers also hold current CREST certifications.
CREST lists its accredited member companies on the CREST Marketplace, where you can browse providers by service, such as security testing. Confirm that penetration testing is within the provider’s accreditation, not just another service, and ask which CREST certifications the testers on your engagement hold. Our list of questions to ask your penetration testing vendor can help you compare providers.
No Australian law makes CREST accreditation mandatory for every penetration test. However, some requirements set expectations about who does the testing. APRA’s CPS 234, for example, requires regulated entities to ensure their information security controls are tested by appropriately skilled and functionally independent specialists. Engaging a CREST accredited provider is one way to show that your testers meet an independently assessed standard.
CREST’s penetration testing pathway starts with the entry-level CREST Practitioner Security Analyst (CPSA) exam. A valid CPSA is the prerequisite for the CREST Registered Penetration Tester (CRT). At the advanced level, the CREST Certified Tester exams cover infrastructure (CCT INF) and applications (CCT APP), and combine written papers with a hands-on practical assessment.
There is no single schedule for every organisation. PCI DSS v4.0.1 requires internal and external penetration testing at least once every 12 months and after any significant upgrade or change. For APRA-regulated entities, CPS 234 requires the nature and frequency of testing to reflect factors such as changes in vulnerabilities and threats, and the criticality of the information assets involved.
CREST accreditation is renewed every year. CREST describes this annual renewal as lighter touch than the initial assessment, and it includes periodic reassessment to confirm the company still meets CREST’s standards. Member companies also sign CREST’s binding company code of conduct annually, while individual certifications such as the CRT remain valid for three years from the exam date.