


|
 |
Analysis and Audits
Analysis and scans can be used to get in depth knowledge of the security status quo of an application, as a regular
approach to reduce risks imposed by vulnerabilities or as an official compliance check based on specific requirements
(audit).
For all scenarios mentioned, we use a combination of automatic scans with appropriate tools and manual analysis of
the source code. The scope of an analysis is defined in advance together with the customer.
Known vulnerabilities of commercial and open source standard software, misconfigurations, outdated software versions
or missing security patches are main areas of interests for a security audit. Another focus is on individually
developed software and applications. In depth analysis and tool based scans allow full coverage even for large and
complex applications to identify possible vulnerabilities.
Analysis results are double checked with responsible specialists of the customers for verification and to define
optimization recommendations.
Every analysis and audit includes a detailed documentation of results and optimization recommendations
(see Consulting Services).
|
 |
|