How to pick the right company for penetration testing?

From: Gideon Rasmussen, CISSP, CFSO, CFSA, SCSA (gideon@infostruct.net)
Date: Mon Jan 26 2004 - 21:02:50 EST


Andy,

You should investigate vulnerability scanning services. The leader in the space is Qualys (http://www.qualys.com). In general scanning services offer the following... You configure the service, it scans the IP addresses you assign and you download reports over https. The reports have an executive overview, specific details of each vulnerability, links to advisories and patches. The scans can be scheduled for time, date and/or interval (i.e. weekly, monthly, etc.). Quite good really.

I recommend that you sign up for a sample scan. You have nothing to loose.

Kind regards,

Gideon

Gideon T. Rasmussen
CISSP, CFSO, CFSA, SCSA
Boca Raton, FL
gideon@infostruct.net

-----Original Message-----
From: Andy Paton [mailto:aoyt78@dsl.pipex.com]
Sent: 25 January 2004 21:54
To: pen-test@securityfocus.com
Subject: How to pick the right company for penetration testing?

Hi Guys & Girls

I have a customer who would like to engage with a security partner for penetration testing service in the UK.

I'm in a position to recommend a company and would like to know, what credentials/information/references should I ask for from a company who offers such services.

Regards

AP

P.S. I don't mind obvious touting for business (I will only pick a UK company)

---------------------------------------------------------------------------
----------------------------------------------------------------------------

---------------------------------------------------------------------------
----------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:53:46 EDT