-
-
» Penetration Testing
-
» Security Policy & Procedure
-
» Social Engineering
-
» VoIP Security
-
» Vulnerability Assessments
-
» Web Application
-
» Web Application Penetration
-
Audit Services
» PCI Data Security Standard
-
» Equifax Audits
-
» PCI Gap Analysis
-
» Quarterly PCI Scanning
-
» PCI Onsite Audit
-
» PCI Management Program
-
Vigilar’s Web Application Assessment Service
Vigilar’s Web Application Assessment uncovers hidden vulnerabilities in Web application components and provide the deep analysis that uncovers hidden weaknesses as data moves from database to server to the Internet, and back again. Vigilar’s comprehensive, easy-to-understand reports detail what was found, how those potential weaknesses might impact business, and provide recommendations for how best to remediate the threats.
The Web Application Assessment Service Process
After removing the false positives, the tester performs a risk review to assign the appropriate risk level to each of the vulnerabilities discovered during testing. The risk level is determined by evaluating the probability that the vulnerability could be exploited along what data or systems could be compromised by a malicious hacker if the vulnerability was exploited. Remediation recommendations are provided for each vulnerability, including Vigilar Best Practices on effectively remediating the identified vulnerabilities.
After removing the false positives, the tester performs a risk review to assign the appropriate risk level to each of the vulnerabilities discovered during testing. The risk level is determined by evaluating the probability that the vulnerability could be exploited along what data or systems could be compromised by a malicious hacker if the vulnerability was exploited. Remediation recommendations are provided for each vulnerability, including Vigilar Best Practices on effectively remediating the identified vulnerabilities.
Common examples of Web Application security vulnerabilities identified during assessments include:
-
SQL Injection
-
Cross-Site Scripting (XSS)
-
Client-Side Pricing
-
Parameter Injection
-
Directory Traversal
-
Buffer Overflow
Once the assessment is complete, the client receives a detailed set of deliverables, plus a thorough review of these reports, led by the Vigilar assessment team. These deliverables consist of:
-
Report—focuses on providing customer with the following key objectives:
-
An Executive Summary that summarizes security exposures discovered in the assessment and the potential impact upon the organization
-
A Management Report that details operational issues related to Web application vulnerabilities that were discovered
-
A Technical Report that details the identity and location of vulnerabilities
-
A Solutions Recommendation Report that helps staff begin the process of prioritizing remediation efforts, with strong emphasis on reducing the greatest risks to the enterprise first
-
PCI Compliance Summary describing how this assessment maps to specific sections of PCI in regards to Web Application security
-
Emergency Notification upon discovery of any critical vulnerability
-
Technical Conference Call to review vulnerabilities with support staff and the appropriate changes that should be made to remediate
Web Application Assessment Service Features
-
Comprehensive review of Web application components using automated tools as well as hand validation by Vigilar security experts
-
Tiered levels of service for businesses of varying sizes
-
A complete set of reports that address the needs of both senior managers and technical staff
-
Guidance for prioritizing and fixing discovered vulnerabilities
Web Application Assessment Service Benefits
-
Delivers rapid, accurate and non-invasive discovery of the security weaknesses in Web applications
-
Provides comprehensive assessments without requiring the purchase of hardware, software or staff
-
Assigns a risk level to Web application vulnerabilities to help structure and simplify remediation efforts
-
Integrates business and technical concerns associated with Web application vulnerabilities for faster, more productive remediation efforts
-