Security
Assessment Service
An External Access Assessment investigates the accessibility and vulnerability
of client hosts and / or networks from the Internet. This initial security
assessment is performed remotely and consists of the following components:
Assessment Scope
In the assessment scope phase of the project, a Friendware Security
Consultant will evaluate the client environment in order to determine the
components host and or networks that need to be tested. The consultant
will take in to account host and network performance impacts, data safety
integrity, and assessment scheduling considerations.
Target
Determination
Friendware Security Consultants will perform a determination of target
hosts and or networks to be included in the assessment. This can include
hosts on external internal, access, and service networks. Target hosts
may also include security devices firewalls, routers, web servers, Database
Servers, FTP servers, MAIL servers, DNS servers, etc.
Public Information Research
The assessment includes research on the client's domain names to determine
whether excessive information is used that could compromise or bypass security
posture is being divulged. This information may lead to additional hosts
that should be considered targets to be included in the assessment.
Host Service Scan
The host service scan function of the assessment performs a scan of
all Internet accessible Services on target hosts. The results may be used
to identify vulnerabilities, unnecessary services or services that should
not be accessible from the Internet. If there is a security device that
is protecting the target host or network, the results of this scan will
be limited by the filtering performed by the security device. In this way,
the scan provides an indirect indication of the security device's effectiveness.
Service Vulnerability Scan
After the Host Service Scan, a Friendware Security Consultant will
provide an evaluation of the services that are accessible from the Internet.
The evaluation will look for known security vulnerabilities on the target
hosts. These vulnerabilities include potential abuses and exploits that
may provide un authorized privileged access or cause disruption to services
otherwise normally used protocols.
Scan Reports & Interpretation
The Friendware Security Security Consultant will provide the client
with the following
assessment reports:
-
Detailed and summary results of all
assessment components
-
References to further service and
vulnerability information
-
Recommendations on improving the security
of the assessed hosts and or networks
The results, their causes and impact will be explained and specific recommendations
will be discussed with the client. Page
2
1 800-404-8560

|
|