Our web application security assessment service simulates a real-world attack, identifying security issues within your organisations web applications, website and web services such as REST and SOAP API’s. Identified security issues are documented in a severity ordered report with clear recommendation instructions, allowing your organisation to fix and secure identified security issues. Fixing the identified security proactively will help prevent your web applications becoming compromised, potentially breaching sensitive and personal information which could lead to brand damage.
Our website security assessment services are carried out by experienced, certified security consultants. A web application audit will help your organisation:
Web application security assessment also known as a website security assessment is a point-in-time security audit of a website (web app) that provides a deep dive analyses identifying any security issues within the web application. Unlike our penetration testing service, a web application security assessment focuses specifically on identifying security issues and vulnerabilities within the web application and the web server configuration.
The following issues are assessed during a web application security assessment:
We providing a clear easy to understand report with recommendations and fix instructions, allowing your team to resolve discovered security issues.
Performing a website security audit will enable your organisation to identify and fix potential vulnerabilities and security issues within your web applications or web servers.
Web application assessments combines both automated vulnerability scans and advanced manual web application security to ensure all areas of your web applications are assessed. Our assessment use industry-approved methodologies, and our consultants are both CREST & OSCP certified.
Web applications are inherently insecure, while the industry has made significant improvements in recent years with the adoption of open source frameworks mistakes are still common and a number backends are now often insecurely exposed, a reflection of this is insecure API access being recently added to the OWASP 2017 top 10. Assessment covers all areas of the OWASP top 10 and test your host or cloud providers security control to help ensure your applications are secure and not vulnerable to attack.
Modern web applications typically use frameworks with API backends and are essentially front ends for users that send requests to a backend SOAP or REST API also known as a RESTful web service. Incorrectly secured API’s are easy to exploit and endpoints that do not have the correct controls in place to rate limit malicious users are particularly susceptible to automated attacks.
Aptive provide website security assessments, which we treat as the same service as a web app security audit. Our in-depth web app security audits use an OWASP based methodology where all areas of the OWASP top 10 are assessed.
Our internal web app security audit methodology is based on the OWASP ASVS framework (Open Web Application Security Project).
Aptive provide a clear easy to understand report that provide an executive summary narrative, a technical summary, graphs that clearly display the discovered vulnerabilities and the assigned severity. Each web app security issue has a CVSSv3.0 assigned score, business impact, summary, technical description, evidence and our recommendation for remediation or mitigation.
In addition to the report we provide a remediation plan spreadsheet for your team to work through during the remediation phase of the assessment. During the remediation phase of the assessment we are available for any questions or clarification that you may require, by email or phone.
After the remediation work has been completed by your team, we provide free retesting for all discovered web app security issues.
If any high or critical severity issues are discovered during the web application security assessment, we will notify you immediately.
Type | Starting Price | Description |
---|---|---|
Web Application 1 | Contact Us | Assessment covers 25 static/dynamic pages or tabs, 2 user role authorisation testing (1 authenticated + anonymous). 1 x file upload function and all areas of the OWASP testing methodology and is assessed manually by a consultant who holds the CREST certified Web Application Tester (CCT) certification. |
Web Application 2 | Contact Us | Assessment covers 50 static/dynamic pages or tabs, 4 user role authorisation testing. 3 x file upload function and all areas of the OWASP testing methodology and is assessed manually by a consultant who holds the CREST certified Web Application Tester (CCT) certification. |
The OWASP top 10 are listed below:
In short the OWASP top 10 represents the top 10 most critical web application security issues and vulnerabilities.
Scoping
Working with you to identify all systems / applications that need testing.
Web App Testing
completed by our CREST accredited team, this process uses a large range of attack methodologies.
Reporting
Delivering a clear easy to understand severity ordered report, detailing identified issues and associated remediation steps.
Debrief
Further explanation and demonstrations of vulnerabilities / exploits.
Re-testing
Free re-testing is included with all our services, helping your business reduce security risks.
Execute a real-world attack and understand the level of risk that exists at a single moment in time.
Complement your automated scanning to better identify and validate all security vulnerabilities.
Provide management with an understanding of the level of risk introduced by the web application.
Plan a cost-effective and targeted mitigation approach from idenitified security issues.
Various standards such as ISO27001 and PCI DSS require a website security testing.
Create a foundation for future decisions regarding information security strategy and resource allocation.