Security Testing

Print E-mail
Arsin, a SemanticSpace company, provides security testing services for mission critical business applications. We closely collaborate with our customers throughout the development lifecycle and apply industry standard security testing practices in order to identify and eliminate significant security risks.
Arsin will carry out extensive manual and automated vulnerability checks to identify potential information security threats in an application, and to determine the risk index of the application level as well network level.  We perform product security testing to identify what might make the application crash or behave differently, such as tampering with the license mechanism or editing any registry entries.  We also test the application for compliance with standards like PCI and OWASP. 
We offer a wide variety of security testing services for Web Application Security, Network Security, Operational Security, Physical Security, Product Security, Security Source Code Review and Physical Security.
Security Testing
Web Application SecurityFocusing on the security of web applications is essential for organizations today, given that they are particularly vulnerable to attacks:
  • Hackers are targeting confidential information (account numbers, credit card numbers, personal identities, etc.) within applications with the intent to steal and monetize this data.
  • Applications are vulnerable to various attacks because application developers have not employed strict secure coding practices. The most common attacks are SQL Injection and Cross Site Scripting (XSS) attacks.
  • To date, the Open Web Application Security Project (OWASP: www.owasp.org) has identified over 70 different attack types and authors a list referred to as the OWASP Top 10. The Web Application Security Consortium (WASC: www.webappsec.org) has classified 24 different attack types.
We can provide a detailed assessment of your entire Web application to identify potential vulnerabilities.  Services are offered as black-box or white-box methods of testing.
Source Code Review
With the realities of secure coding practices not always being followed and security assessments not identifying all vulnerabilities, a source code review provides that deeper level review to ensure that any critical vulnerabilities are identified. 
Product Security Any software, before being released in the market or deployed across the enterprise, needs to be thoroughly checked for security risks.  A security breach can significantly impact an organization's reputation and cost the company in fines and fees.  
Network Security We take a proactive approach for the secure management of computer networks to ensure optimal productivity and efficiency while reducing the probability of downtime or catastrophic network failure. We will conduct a comprehensive network security assessment service combining automated network scanning and security assessment techniques, with hands-on vulnerability qualification and reporting. We assess any IP network, whether your requirement is to ensure the security of publicly accessible networks, or assessment of internal networks.
We perform checks against Arsin's vulnerability database of 18000 vulnerabilities.  We will identify and demonstrate any security weaknesses even after you have applied a patch management solution.
Operation Security An Information Security Policy plays a vital role in helping to implement and enforce your company's information security goals/objectives for confidentiality, integrity & availability.  A policy will help to:
  • Protect people & information
  • Define roles and responsibilities organization wide
  • Provide the guidelines to respond to any security incidents
  • Ensure the compliance to various security standards such as ISO 27001, HIPPA, PCI / Data Security Standard

Share
 


Copyright © 2012 SemanticSpace Technologies Limited. All Rights Reserved.