|
Nobody
is completely safe - if your host is doing something useful, an attack is
possible. The basic equation in information security is Usability
Vs. Security - the more useful the object, the more insecure it usually is.
The more services your host provides, the easier it is to find a security hole
in one of those services. The great challenge is finding those holes and being
aware of the risks.
HighSecure
Assessment
tries to address exact this issue. The modules of Assessment practice meet
various security assessment needs from awareness to extensive penetration and
ethical hacking.
Typical
HighSecure Assessment process:
HighSecure
Specialists are committed to the challenge of finding, or helping you find, the
'weak spots' in your security design. In the constant changing world of
security, we'll keep you updated with the latest security holes and tools
available in the world.
Discovery Highband will first
identify all hosts in your network that are visible from the Internet, such as
web, mail or file servers, firewalls, routers, switches etc. It then discovers
the services that each machine offers, the type of Operating system and the
versions of each publicly accessible application.
Exploitation/Analysis.
Each service and application discovered in phase
one is cross-referenced to an extensive database to generate a list of potential
vulnerabilities. For example, if a machine is running Windows and offering web
service, a list of Microsoft IIS vulnerability checks is enabled.
Our security experts monitor vendor security bulletins, security
organization announcements and "black hat" hacking sites to keep the
vulnerability database as current as possible, and your network as secure as it
can be.
Reporting.
Detailed and easy-to-read reports containing High
Risk, Medium Risk and Low Risk will given along with the remedies to the
concerned officers. The detail plan can be worked to take care of the
vulnerabilities.
Further to the Reporting step of Assessment, if
client finds risks to be high and wants to install comprehensive security
solution, they can opt for other HighSecure services in areas of Policy and
Implementation.
|