From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,200 courses taught by industry experts.

Bug bounty

Bug bounty

- [Instructor] Bug bounty programs provide a formal process that allows organizations to open their systems to inspection by security researchers in a controlled environment that encourages attackers to report vulnerabilities in a responsible fashion. Organizations deploying a bug bounty program typically do so with the assistance of a vendor who specializes in the design, implementation, and operation of these programs. The reality of operating internet connected systems is that attackers will probe them on a virtually continuous basis. Just take a look at the logs of web servers, firewalls, and other devices with public exposure, and you'll see evidence of these continuing attacks. Some of these attacks may be targeted reconnaissance against your organization, but the vast majority are simply automated scanning tools, searching the internet for vulnerable systems. These automated scans are launched by opportunistic attackers who are simply seeking out a vulnerable target that they…

Contents