|
|
|
| |
|
 |
|
Application Security Assessments
As the adoption of web based technology becomes more pervasive it has now become a business necessity to have and maintain a web presence. The proliferation of web applications has also extended into the enterprise, replacing traditional client server applications as the desired platform for support of core business processes. This also means that vulnerabilities that used to only apply to external websites or e-commerce sites can just as easily be used by an internal attacker against your ERP systems.
On the Internet these applications may be used for very different purposes, from content to commerce, but the reality is, regardless of the purpose, your website is very likely the first place that an attacker will profile when assessing your company for points of exposure.
To ensure the security of your website and the data processed by your web applications, it is imperative that frequent web application security testing is part of your system development and ongoing maintenance lifecycle. There are primarily two methods used by organizations to achieve a reasonable level of comfort that their sites and applications are secure. The first method is referred to as a Dynamic Security Assessment (DSA). DSA's are performed by an experienced web security professional and are intended to interact with the application as an unauthenticated or authenticated user in order to identify vulnerabilities in the application that may arise during user interaction. The second method is referred to as a Static Security Assessment (SSA). SSA's involve an experienced web security professional reviewing the code supporting the application to identify insecure programming practices that may express themselves as vulnerabilities in the application during use.
Secure DNA's team of web application security professionals include experienced developers, security assessment specialists, and database experts who have reviewed the security of applications for major companies and government agencies across the U.S. and Asia. All team members have extensive experience in the areas of web application and database design and more importantly, they have specialized experience in assessing these designs for security flaws. Whether you require static assessment of your code base as part of your product development lifecycle, dynamic testing of your production application, or specialized training for your web-developers or security team - Secure DNA's web application security team can assist you.
|
|
Hawaii Web Application Security
|