With an ever growing reliance on complex applications and the need for a highly available online presence, flaws in security can hurt the operational abiltyability of your business. Whether it be an application that has been developed over many years, growing in complexity or a eCommerce site. K-ISS can help you pin point any vulnerabilities and work with you sure these up,
New threats are developed on a daily basis, K-ISS will constantly refine their methodology to react to these. Our techniques will be inclusive of the following fundamental areas:
1. Authentication
2. Forceful browsing
3. SQL Script injection
4. Cross-site scripting
5. News group searches
6. Session management
7. Known software vulnerabilities
These tests analyse and identify any security gaps in applications,bespoke applications, bespoke and off the shelf, that are running any eCommerce or online services. Applications which have been developed over many years grow in complexity and have to be tested by experienced consultants and the use of automated tools is not adequate on its on.
K-ISS will work with your organization to manually review and test your source code to identify vulnerabilities. We then provide detailed documentation of location and nature of each problem we find. Once we provide that documentation, we will advise your developers on how to address the immediate problem and how to avoid similar problems in the future.
Since software development is an ongoing process, K-ISS recommends that code auditing should sit inline with your organization’s development lifecycle. This would include setting up regular audit intervals for each product stage such as alpha, beta, release-candidate, etc. Not only will Information Security Solutions review your organizations source code but we will also identify vulnerable points in the design, such as backward compatibility issues, that may result in a security compromise.
K-ISS will work closely with your development teams to help ensure your applications are hardened to the fullest extent possible against attack based on analysis of any relevant risks or threats. Information Security Solutions Security will also strive to help your organization address any complex application security challenges you deem necessary.
© Kavuri Information Security Solutions 2010 | Privacy Policy | Disclaimer