Industry and Government

 

CREST
provides
“demonstrable assurance of the
processes and procedures of member
organisations and validates the
competence of information security testers”

Community Pages

Why use CREST

CREST works with industry by bringing a demonstrable level of expertise and professionalism to security and penetration testing, and through the provision of a recognised body for industry to express their security testing needs.

In hiring a CREST company, you can be confident that the work will be carried out by qualified individuals with up to date knowledge of the latest vulnerabilities and techniques used by real attackers, backed up by a company with appropriate methodologies for the secure storage and protection of your data.

In order to provide this, the CREST scheme is comprised of two tracks; company assessment and individual tester certification.  This provides two layers of assurance that your penetration testing provider is capable of understanding your unique security posture and providing up to date recommendations on security improvements.  The company assessment and membership provides assurance around methodologies, test hygiene and conduct.  Individual certifications provide assurance that the individuals carrying out the test have the appropriate experience and skill.

In providing a standards based organisation for penetration test providers, backed up by a technical certification track for individuals, CREST provides a provable level of assurance that a member organisation will provide the very highest standard of security testing.

Design by MARSH