Auditing the Internet, E - Business

PENETRATION TESTING

Levels of Penetration Testing

I. Security Posture Review

Purpose: High level view of what the system is doing.

Estimated Time to Complete: 1 day to gather information, 2 days to analyze and write report.

Estimated Costs: $5,000 - $10,000

Alternative: Phone Scan

Purpose: Identify modems and software running on PC's that answer.

Estimated Costs: $5,000 - $7,000

 

II. Security Scan (more detailed than Security Posture Review)

Purpose: Assess security posture without taking advantage of vulnerabilities to see what could be accessed.

Estimated Time to Complete: Varies, depending upon system design, etc.

Estimated Costs: $20,000 and higher

Alternative: Internal Audit staff could assist in running the security scan, thereby reducing costs.


III. Full Penetration Test

Purpose: Accomplish above objectives plus try to access system. Scope can also include "social engineering".

Estimate Time to Complete: Varies.

Estimated Costs: $40,000 - $50,000 (& possibly higher depending upon objective).

Contact us for additional information, including free, no obligation proposals.

Contact Us Home / About Us / Services / Newsletter

IT Audit / Pre-QAR / CIA / 1 Stop IA Shop / IA Manual

Audit Services Tel:615-790-9858 PO Box 681387, Franklin, TN 37068