An anonymous reader writes "I'm in charge of a web application that must be extremely secure. Users will be submitting highly sensitive information to each other using the site. Security must be world-class.
We believe we've built site in such a way that minimizes security risks and we've implemented numerous policies and procedures company-wide to increase security.
We'd like a third-party to perform exhaustive and ongoing security tests: automated tests, application testing, and more, to check for things like cross site scripting issues, Server misconfigurations, Form/hidden field manipulation, Command injection, Cookie poisoning, known platform vulnerabilities, etc.
What companies Slashdot readers recommend for these types of services?"
This discussion was created for logged-in users only, but now has been archived.
No new comments can be posted.
I work for either Cenzic, HP or IBM.(Alphabetical order) I support end users of application security testing software. If you decide to do it yourself be prepared to invest a lot of time educating yourself on firewalls, protocols, programming languages, web servers, databases and hacking. The application scanning tools will give you a starting point. Most of the top notch consulting firms will use 2 or 3 of the products to develop a base line that they will then manually attack.
All developers can writ
Do it yourself vs. hire someone. (Score:1)