Description
Vulnerability assessments, which gauge potential security issues, usually consist of two steps. First, we check for weaknesses in the defined systems. This involves a technical evaluation process (vulnerability scan) where we actively explore the target system looking for known security gaps. Our preferred tool is Nessus, one of the top-rated vulnerability scanners. The scanner analyses your application and operating system software, and draws from a database to identify whether the software components contain any potential security gaps. The Nessus database is constantly updated in line with current findings.
The regular reports that Nessus produces show only a snapshot of potential security gaps. Given that our customers have different requirements and environments, the risks inherent in any gaps discovered will also be different. The second step in a vulnerability assessment is for our experienced security experts to evaluate the Nessus reports, and to then produce concrete suggestions for next steps. Typically, the customer requests an evaluation of Nessus reports as and where necessary. It is also possible to request a vulnerability assessment to take place at regular intervals.