Weitere Àhnliche Inhalte
Ăhnlich wie Tcl security testing services v0 03 kvs 180511 (20)
Mehr von Transition Consulting Limited, India (20)
KĂŒrzlich hochgeladen (20)
Tcl security testing services v0 03 kvs 180511
- 1. TCL Security Testing Services
Enterprise applications are the enterpriseâs new security perimeter. TCLâs Security Testing
focuses on detecting application vulnerabilities in order to ensure that only authorized users
are able to access the application and that authorized users are able to access and update
only the information to which they have been granted permission.
Applications require varying levels of security testing depending on the purpose of the
application, the application customer base and the data contained within the application
database. To address client security risk levels associated with unique applications, our
customers have the ability to pick and choose from any of the following service offerings and
customise.
Security Review and Assessment
Security Application Testing
Security Vulnerability Testing
Review and Assessment Overview
Perimeter Review
â Firewalls, Routers, RAS servers, Virtual Private Networks, Wireless LANS
Server Review
â OS hardening, S/W patch currency, active services review, account review
â All IPS visible to internet
Content Management Review
â Web traffic
â Email
â Antivirus / Malware Prevention and Remediation.
Technical Policy Review
â Passwords, Directories, Groups, Accounts
â Access Control
Authentication Review
â Effectiveness of current authentication
â PKI, tokens, smartcards
Intrusion Detection System Review
n
â ID Sensors, Analysis Stations, Burglar Alarms, HIDS and NIDS
â Log analysis and intrusion attempt reporting
Encryption Review.
â Packet encryption, file / data encryption, hard drive encryption
Application Testing
TCLâs Security Testing also verifies that the following application security requirements have
been met.
Uses our requirements based testing methodology
ments
â Develop Test Strategy, Plan and Cases/Scenarios
Application security controls like
â Data Confidentiality, Non Repudiation
â Communication Security and Data Integrity security
â Web Application Security
TCL Security Testing Services v0 Page 1 of 3 Commercial in Confidence
03 KVS 180511 © 2011
- 2. TCL Security Testing Services
Design/Requirement Impact
â tokenisation architecture, common PCI requirements
Coding standards
â shared variables across threads
Early penetration testing
â automated & manual
Security standards control
â governance of architecture & testing
Vulnerability testing
â inappropriate file permissions
Security compliance reporting
â PCI, DPA
â Sarbanes-Oxley
â Basel II
â Food and Drug Administration (FDA)
â NERC-CIP
â Health Insurance Portability and Accountability Act (HIPAA)
â Federal Information Security Management Act (FISMA)
â Gramm-Leach-Bliley Act (GLBA)
Bliley
â Payment Card Industry Data Security Standard (PCI DSS)
â ISO 27001 / 27002
Vulnerability Testing
Identify network security gaps
entify
Review results of gap analysis report and make recommendations
Implement recommendations.
Benefits
Authentication of a secure environment
Understanding of the current adherence to your Security Policy
TCL Security Testing Services v0 Page 2 of 3 Commercial in Confidence
03 KVS 180511 © 2011
- 3. TCL Security Testing Services
Awareness of potential inadequacies in security
Improvement of security through design and implementation of secure network
solutions
Protection from damages and financial losses from unwelcome network access
Key Deliverables
TCL security testing services delivers the following outputs:
âą Identification of application security vulnerabilities
âą Application security vulnerability reports
âą Remediation analysis
âą Recommendations to assist with the remediation of the vulnerabilities
Contact
K. V. Shashi Kiran
Shashi.kiran@tcl-asia.com
+91 98450 08696
End of Document
TCL Security Testing Services v0 Page 3 of 3 Commercial in Confidence
03 KVS 180511 © 2011