Skip to main content
REF-SOL-005

Web Application Assessment

Evaluates the security and overall health of a web application on a recurring basis, catching regressions introduced by new releases before they reach production.

An open server chassis in a dark rack
Capabilities

What's inside.

Vulnerability Scanning

Automated scanning for SQL injection, cross-site scripting, and cross-site request forgery.

Code Review

Analysis of source code for security issues and best practices.

Configuration Review

Evaluation of server and network configuration against best practice.

Remediation Guidance

Recommendations on how to fix identified vulnerabilities.

Objectives

What the solution aims to do.

01

Identify security risks

Find the vulnerabilities and weaknesses in the web application that an attacker could exploit.

02

Improve security posture

Turn assessment results into guidance for reducing the risk of incidents and protecting sensitive data.

03

Compliance

Support regulatory requirements and industry standards including PCI DSS, HIPAA, and OWASP.

04

Enhance the development process

Surface the practices and the gaps in your software development process, not just in the running application.

05

Increase customer trust

Demonstrable commitment to security and privacy, which is what customers actually assess you on.

Deliverables

What you receive.

The exact set depends on the package selected, but a Web Application Assessment Solution typically includes the following.

Software: the tool itself, installed on your infrastructure or used as a cloud service
License: the terms of use, including user count, duration, and any restrictions
User documentation covering installation, configuration, and operation
Technical support for installation, configuration, and use
Consulting and training services to get more out of the tool
Regular updates, so the tool keeps pace with new vulnerabilities and threats
Scan reports summarizing the vulnerabilities and risks each scan identified
Customization to the needs of your organization
Integration with other security and IT tooling, such as vulnerability management and SIEM
FAQ

Common questions.

What does the assessment actually check?

Automated scanning for issues such as SQL injection, cross-site scripting, and cross-site request forgery, plus source code analysis and a review of server and network configuration against best practice.

Is this a one-off test?

No. It evaluates the security and overall health of a web application on a recurring basis, which is what catches regressions introduced by new releases before they reach production.

Do we get told how to fix what is found?

Yes. Remediation guidance covering how to resolve each identified vulnerability is part of the service, alongside the assessment reports detailing the risks.

Is it hosted by us or by you?

Either. The software tool can be deployed on-premises or in the cloud, supplied with a license agreement, user documentation, technical assistance, and continuous updates.

Ready to scope Web Application Assessment?

Request an Assessment
Request an Assessment Email Us