Enhancing Software Quality
Customers | Contact Us | Inquiry
Menu

Security Testing Services

As enterprises progress to shift most of their business transactions online, security problems are becoming even more severe. The consequences of a single breach in security can spoil an enterprise's reputation and credibility. Recognizing this heightened risk, the industry has coalesced around the Open Web Application Security Project (OWASP), a robust framework for security testing.

Indium insists Security Testing has to be a feature that is fully integrated throughout the Software Development Life Cycle (SDLC) and delivery process.

Lately, many critical software applications/products have incorporated security measures against all malicious threats in their system.

We at Indium offer an effective solution to manage your security risks at an attractive cost point. Indium has a proven methodology that enables our customers to:

  • Conduct web application security audit (aligned to OWASP standards) of their business critical applications
  • Vulnerability scanning – leveraging testing tools for identifying inherent vulnerabilities in applications
  • Integrating security testing and risk analysis within the application life cycle
  • Extensive use of open source and commercial testing tools with ready to use jump start kits
  • Delivering these services in a catalog pricing model of engagement

The key objectives of Indium’s Offshore Web Application Security Testing offerings include:

  • Certification of releases/patches as per security standards
  • Create a unified process and model for web application security testing and risk modeling
  • Create and upgrade a repository of re-use-able test artifacts
  • Leverage the jump-start kits for rapid time-to-market

The key service offerings of Indium’s Offshore Web Application Security Testing includes:

  • Vulnerability scanning and auditing
  • Security Compliance Certification of releases/patches
  • A Security testing shop floor for providing an integrated approach for all applications security testing

Typical web application attacks:

Tools Used
Security Testing Tools
IBM Rational App Scanner, HP WebInspect, HTTP Watch
Opensource Tools
Web Scarab, NetCraft, TamperData, NMap, Webcode, Nessus