Sizing Pentest

From: Leonardo Loro (leoloroat_private)
Date: Wed Jun 27 2001 - 22:48:59 PDT

  • Next message: Lucyga, Dierk - Munich: "RE: Pipeupsam Usage"

    Hi all,
    Which keypoints should be taken in account when sizing a pen test (for a
    financial institution that wants to check the vulnerabilities of their
    intranet systems vulnerability).  Should it be charged x hour? X server?
    X Deliverables? 
    Basically, they have 10 Sun 450e and 10 W2k servers on their intranet,
    and a PIX in to work as a FW in front of them.
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA) Service
    For more information on SecurityFocus' SIA service which automatically alerts you to 
    the latest security vulnerabilities please see:

    This archive was generated by hypermail 2b30 : Thu Jun 28 2001 - 15:59:37 PDT