Vulnerability assessments identify and quantify vulnerabilities in a system. While these assessments don’t cover the breadth of scenario and logic-based testing of a full-blown penetration test, they do provide a hacker’s-eye view of an organization’s network security.
Many vulnerability assessments only include the use of automated network scanning tools. These tools can be quite thorough, but often produce “false positives” and “false negatives” that create additional work for IT staff. For the most effective results, these tools should be used by a security expert who can provide “Hand Validation” of the vulnerabilities that are discovered. Hand validation uses other tools and techniques to go beyond the automated scan to determine if the vulnerability exists. Only then, will an organization be able to focus on the truly high-risk vulnerabilities and have a prioritized roadmap for remediating those vulnerabilities.
The Vigilar Vulnerability Assessment and Validation service goes beyond a typical single-tool automated scan. Vigilar security experts provide cross validation and hand validation of vulnerabilities, then takes the process of threat and vulnerability assessment one step further by identifying the root cause behind system vulnerabilities on the internal critical systems (when possible). Without identifying the root cause, vulnerabilities will often reappear. By identifying the root cause, mitigating steps can be taken to address the vulnerability, as well as numerous other potential vulnerabilities. At the end of the assessment, Vigilar provides comprehensive deliverables.
Depending on the customer’s requirements, Vigilar can provide vulnerability assessments, from either an external or internal perspective.
Vulnerability Assessment and Validation Service - External — Scans Internet-facing systems for potential vulnerabilities, eliminates false positives and details confirmed vulnerabilities in terms of risk and any recommended remediation steps.
Vulnerability Assessment and Validation Service - Internal — Scans systems or network ranges defined by the customer for potential vulnerabilities, eliminates false positives and details confirmed vulnerabilities in terms of risk are and any potential remediation steps that should be taken.
Once the assessment is complete, the client receives a detailed set of reports plus a thorough review of these reports led by Vigilar security experts. These reports consist of: