Application Security Audit

In the fast growing world of application development, the threat of security vulnerabilities in application code is much
greater than with corporate networks. Applications that are poorly coded, incorrectly tested or
badly installed can put your organization at risk to much more than just information thieves, but
to hackers that will be able to exploit the weaknesses in the application code to gain access to your
network. Additionally, as more organizations look to
develop software internally for their core business functions, less attention is placed on security and more on functionality.
We have specialized services that works specifically with these risks. We are able to provide core services and understanding to your software development engineers, quality assurance testers and corporate management that all applications will be
thoroughly checked for security vulnerabilities and eliminated prior to implementation.
Our services start with an Application Code Review to analyze the source code for design and programming
flaws, use of vulnerable functions or program constructs to assure overall security in the application.
Our Application Security Audit identifies security vulnerabilities by reviewing and testing application
security controls. We specifically test for the ability to replay authentication data, exposure of any
sensitive data on servers, susceptibility to encryption breaking algorithms and the potential to exploit
inadequate input validation controls. We try to break your application to make sure that it can't be done.
Our Secure Application Engineering Support will allow our experts to collaborate with your development
team from the technical design stage to ensure correct security controls throughout the development process
for technical design, technology selection, implementation testing, deployment and performance tuning.
Database Vulnerability Assessment is a focused assessment using automated tools and methods to assess security
configurations and the settling of access controls, rights and permissions. As more applications become heavily
data driven, the importance of protecting those databases increases exponentially each day. Our assessment delves
into your database to identify possible vulnerabilities and risks in:
- User Management
- System Default settings
- Policies and Procedures
- Authentication Methods
- Use of Encryption
- System & Object Privileges
- Operating System Datafile Information
- Operating System Roles
- User Profiles
- Database Roles
- Distributed Database Features
- Auditing
- Backup & Recovery
- Parameter Files