|
DELIVERABLES S3 consultants have extensive security industry experience and utilise a variety of tools. These are combined to carefully compare the results before completing a comprehensive report, suitable for both technical and managerial levels. Technical issues are prioritised, explained and remedial action or workarounds covered. Human interpretation ensures that a client is provided with the best advice, presented in an easy to understand format.
TECHNOLOGY The Interrogate External service is based on manual testing, analysis and reporting, not just the running of proprietary system scanners followed by an automatically generated report. The following list details some of the categories that are tested:
- Information gathering possibilities
- Backdoors and mis-configuration
- HTTP and CGI abuses
- Firewall, filters and proxy vulnerabilities
- File Transfer Protocol abuses
- Authentication mechanism tests
- DNS and Bind checks
- Remote file access vulnerabilities
- Remote Procedure Call checks
- SMTP and Mail transfer vulnerabilities
- SNMP vulnerabilities
- Windows Service Pack and Hotfix checks
PREREQUISITES A client must provide the IP addresses and web URLs (if applicable) of the hosts that are to be tested. A contract must also be signed, authorising access to the client’s site, information records and other relevant material. Permission must be granted from all persons, including third parties, such as the client’s Internet Service Provider
PACKAGE Interrogate External can be purchased as a one-off ‘snapshot’, or as an annual contract. The annual service provides 4 quarterly engagements per annum, although the precise timing of tests can be tailored to fall in line with planned changes to IT systems security infrastructure. As standard the service covers 8 IP addresses. More IP addresses can be tested if required. Interrogate External can also include Denial of Service (DoS) attack vulnerability tests. However, these will only be performed with prior express approval because of the risk of service loss on live systems. Two additional modules are available to complement Interrogate External:
Optionally, a ‘Host Discovery’ procedure can be invoked before an Interrogate External, during which an IP address range is scanned for active devices. This enables the identification of hosts prior to selection of these devices for input to the full Interrogate External process.
- Web Application Testing Add-On
Optionally, a Interrogate External can be supplemented with the S3 Web Application Testing Add-On service. More details are available in the Web Application Audit datasheet.
Contact us for further information.
|