|
While Detack
offers today complete coverage of the IT security
services field, most notable are the areas of
security auditing, security consulting, and more
recently, performance consulting. The security
auditing and consulting areas make up for the
vast majority of Detack clients.
Detack offers
mostly customized services, tailored for the specific
needs of a particular client. The following subsections
contain a selection of brief descriptions of most
common Detack GmbH services, resulting from the
projects performed in the interval from the year
2000 to 2010.
Most of the Detack GmbH projects are in the security auditing segment. Detack covers all the aspects of IT security auditing: from basic penetration testing to advanced application layer auditing and up to the organizational level - IT security policy assessments, security guidelines evaluation and management level consulting.
One essential aspect of all the Detack security auditing services is that the entire vulnerability detection and research are done manually by the Detack auditors manually in order to fully understand and evaluate the security implications. Detack only performs manual security auditing because only by this it can offer the quality of service required by its clients.
It is recommended that the clients use the commercially available automated testing tools and services and detect and resolve any known and published safety flaws prior to ordering the Detack auditing services in order to obtain the most efficient cost / benefit ratio. This recommendation is valid for the typical scenario of test targets such as networks, servers, services and applications; however, in case of user perspective testing, specific product and / or application auditing and other customized auditing services (such as IT security policy and guidelines analysis or review), the prior testing for known safety flaws is not necessary.
The core Detack security auditing services are modularly structured, depending on the target type, complexity, perspective and layer. The security auditing modules reflect the most common scenarios founded on previous Detack projects that have been performed for its clients. They are listed in the following subsections, grouped by different views, to provide general orientation. The actual security audit service for a particular client is always customized and fine tuned for the requirements determined by the particular perspectives and targets or sets of targets intended for analysis.
The Detack GmbH security audit modules can be grouped by different views to permit a selection based on requirements. The most used "view" is the one that groups the modules depending on the test target type. The test targets have been extensively extended by various projects including multiple system and application audits performed for clients active in different domains. For specialized auditing these audit modules are combined together or extended to offer the best coverage for the customers' needs and requirements.
|