MOREnet's Remote Vulnerability Assessment implements a three-step process.
- Preliminary
MOREnet's Security Team will contact the customer and discuss the general parameters of the assessment, including the system(s) to be reviewed (architecture, operating system, etc.), the types of testing to be conducted and the schedule for the assessment. MOREnet will make every effort to minimize the assessment's impact on customer systems.
- Analysis
MOREnet Security will conduct vulnerability tests to identify possible problem areas including common vulnerabilities and device or server misconfigurations. MOREnet Security will only fully compromise a system at the customer's request. Customers may also request system-impacting tests such as current denial of service attacks and known exploits. These tests may allow security personnel to better evaluate how the tested systems may respond to real-world attacks and how any internal security measures (including any installed intrusion detection systems) function. Common operating systems and server applications residing on the customer network will also be tested for vulnerabilities and response to attacks.
- Recommendations
MOREnet Security will provide written documentation of the tests it conducted, the test results and recommendations the customer may wish to follow to better secure its network against possible risks.