Risk assessments usually are scoped to meet a delvierable as specified by regulatory standards, or performed to ensure that your environment stays secure.
To meet regulatory guidelines, a security assessment or penetration test of your external facing website is usually required on a monthly, quarterly, or yearly basis. Raxis can help you with meeting PCI, SOX, HIPAA, or other regulatory standards. Based on your requirements, Raxis will build a cutomized assessment package to fully and completely cover all assests as specified as in scope.
Please note that the results summarized in the Raxis testing document are based upon a collection of technical methodologies and manual tests interacting at a single point in time with technology that is continually changing and becoming ever more complex. Any projection to the future based upon the findings contained within the final document is subject to the risk that, because of change, they may no longer portray the system or environment in existence at that time. The information gathered is subject to inherent limitations and, accordingly, weaknesses, errors or irregularities that may occur and not be detected.
| Feature |
Security Assessment
|
Penetration Test
|
|---|---|---|
| Easy to use 100% online request form and online tracking |
X
|
X
|
| Project tracking through online website |
X
|
X
|
| Vulnerability scan using industry leading tools |
X
|
X
|
| Manual validation to remove false-positives |
X
|
X
|
| No DoS attacks to reduce risk of failures |
X
|
X
|
| Target analysis and manual exploit of system |
|
X
|
| Manually attempt full system compromise |
|
X
|
| Attempt to remove or insert data into database |
|
X
|
| Report with recommended fix for each issue |
X
|
X
|
| Detailed report with screenshots |
X
|
X
|