|
Service
|
Pricing Starting At
|
|
Comprehensive Penetration Test
|
$55,000
|
|
The Comprehensive Penetration Test is performed on a surprise basis. The intention is to thoroughly test the intrusion detection and response procedures to ensure that security breaches are quickly identified, investigated and contained. Our team also performs a full vulnerability assessment of the operating systems, databases, network devices, and the resident within the network.
Includes:
- Testing of IDS and IPS
- Internal Network Security Assessment
- Internet Review
- Web Application Security Assessment
- Dial-up Review
|
|
IT Security Baseline
|
$55,000
|
|
The IT Security Baseline is performed with the knowledge of the IT staff. It is similar to the Comprehensive Penetration Test except that the intrusion detection and response procedures are not tested. The first performance of this project sets the baseline, and subsequent tests enable the development of formal metrics to measure enhancements made between test cycles.
Includes:
- Internal Network Security Assessment
- Internet Review
- Web Application Security Assessment
- Dial-up Review
|
Network Vulnerability Assessment |
$50,000 |
|
The Network Vulnerability Assessment is a condensed, lower-cost alternative to both the Comprehensive Penetration Test and the IT Security Baseline. The assessment is performed with the knowledge of the IT staff. The network scope may be limited and does not include the testing of intrusion detection and response procedures.
|
|
Network Audit and Vulnerability Assessment
|
$62,500
|
|
|
Internet Review |
$15,000
|
|
The Internet Review is performed to identify vulnerabilities on the Internet-facing systems owned by the Client. The review also determines if an attacker can gain access to Client's corporate assets remotely from the Internet. This review is performed remotely from the Canaudit lab, and includes up to 65 labor hours of testing.
Process:
- Network Mapping
- Service Identification
- Manual Testing
- Automated Testing
- Verification of Identified Vulnerabilities
|
Dial-up Review |
$5,000
|
|
The Dial-up Review, also known as demon dialing or a war-dial, is performed by Canaudit against the Client’s phone network to identify, test, and exploit unsecured modems. External dial-up intrusion detection and response will be measured. Performed remotely from the Canaudit lab, this audit includes a review of up to 5,000 phone numbers. Additional numbers can be tested for an additional fee, no higher than Canaudit's standard rates. Testing is performed after Client's normal business hours to ensure no business disruption.
Process:
- Connect
- Identify
- Penetrate
|
Web Application Security Assessment |
$8,000
|
|
The Web Application Security Assessment tests the security of one web site. The assessment is conducted in two stages, the first performed without knowledge of the clients network or valid authentication credentials. The second stage is conducted with authentication information, provided by the Client, to identify issues that would otherwise not be apparent.
Specific Checks include, but are not limited to:
- Parameter Injection
- Command Execution
- Cross-Site Scripting
- SQL Injection
- Directory Enumeration
- Directory Traversal
- SSL Strength
- Path Manipulation
- Brute Force Authentication Attack
- Known Attacks
- Service Availability
|
|
Windows and AD Security Assessment
|
$25,000
|
|
UNIX Security Assessment (5 systems)
|
$20,000
|
|
Oracle Security Assessment (5 databases)
|
$25,000
|
|
Microsoft
SQL Assessment (10 databases)
|
$25,000
|
|
Application
Audit (Lawson, Cerner, etc.)
|
Pricing upon request
|
To request a proposal
or inquire about Canaudit's audit
and consulting services contact Tamra
at tamra@canaudit.com or
805.583.3723.
Canaudit assures the following value to each of our clients:
- The opportunity to learn auditing techniques from our staff as it applies to your environment.
- Documentation demonstrating any findings.
- An exit interview for onsite audits.
- Detailed audit report(s).
- Phone or email consultation after the audit services, at no additional cost.
|
|
Simi
Valley, CA
December 6-10, 2010
Discount Available
Until October 29th
VIEW DETAILS
|
|
|