Security testing

The ideal situation for the customer and ZION SECURITY is that security tests are executed during the development phase, together with functional testing and stress testing.

The main purpose of security testing is to identify the existence of security controls like authentication, authorization and input validation.

For example the risks for authentication and authorization include access to the system by an unauthorized user, theft of usernames or passwords and password cracking/dictionary attacks, and ability to bypass authentication or authentication logging.

All attacks and tests are executed manually. ZION SECURITY only uses automated tools for specific functions like brute-forcing ports, passwords, identifiers,...

Security tests are mostly focused on one single application and our security experts follow a certain methodology:

  1. Our security experts test and scan the application for vulnerabilities and leaks
  2. We insert reports and bugs in the customer's bugtracking system
  3. Our security experts retest the application
  4. Final report that will be discussed at length with the responsible person regarding these matters in the company

In a first meeting, the methodology will be discussed and can be adapted on customer demand.

Files

ZION SECURITY Services - Security Testing.pdf

 Interested?

Ask here for more information or an offer without obligation.