 |
Vulnerability assessment
|
|
Many growing businesses lack the expertise and tools required to adequately address today’s security challenges. However, hiring additional IT personnel is often out of the question, and many consulting services are too expensive and time - consuming for a limited budget and staff. Doing nothing is not a viable option, either. Vulnerabilities left unaddressed in IT environments can potentially lead to revenue loss from business disruptions; compromised data; stolen inventory, intellectual capital and other resources; and eroded market leadership and competitive advantage.
Helping clients protect their information assets is a business imperative for IBM. IBM vulnerability assessment is designed to provide your growing business with a reliable, affordable starting point for reducing IT security risks and protecting confidential information. IBM professionals use a multifaceted, time-based approach composed of innovative methods and tools to help identify vulnerabilities in select network, computing components and in standard IT processes - and provide documented recommendations for how to deal with them proactively.
As part of the solution engagement, IBM’s "ethical hackers" simulate security attacks by mimicking the tactics hackers commonly use at each layer:
- Blind application, which simulates an attack on an application requiring no user privileges.
- Sideways application escalation, wherein we simulate an attack in which one user with account privileges accesses accounts of other users with similar privileges.
- Vertical application escalation, which simulates an attack in which one user with account privileges elevates his access-rights level to that of a more privileged user, such as an administrator
|
|
 |
- Test your IT security using proven methods like Blind application, sideways application escalation and vertical application escalation
- Prioritize security improvements to enable efficient resource allocation
- Boost the return on your security investments
- Improve your ability to comply with regulatory requirements
|
|
|
 |
|
|