VAPT
Vulnerability Assessment and Penetration Testing - aims to assess the level to which systems and configuration are in compliance with the customer’s security policy, Penetration Testing explores the weakness and vulnerabilities evident to both external and internal attacks.
The IT network will be assessed against known criteria of network vulnerabilities and tested to simulate failure scenarios.
The client can choose to test their internet facing system from three perspectives
- Black Box – An external Hacker’s eye view.
- Grey Box – An internal or external person having some knowledge of the IT network.
- White Box – An internal hacker’s eye view.
Testing is done by experienced information security professionals. Management and technical report highlighting the vulnerabilities, penetrations tests results and the associated impacts are provided to estimate the qualitative risks.
On closure of vulnerabilities by the client a re-scan is carried out to ascertain closure of critical and high risk impacts.
All the findings that are observed during the vulnerability assessment and penetration testing process need to be documented, along with the recommendations, in order to produce the testing report to the management for suitable actions.