|
The e-services
security audit target consists of complex applications
that function as e-business systems. In general
such applications are tested from the external
perspective. Detack GmbH has built a selection
of typical e-services security auditing modules,
based on previous projects performed for clients
active in different areas:
e-Banking
The e-Banking
services audit module is customized for the complete
coverage of typical online banking applications
at the application layer. Included by default
in the scope of auditing are PIN / TAN (including
iTAN / mTAN), HBCI, BTX (also with newer interfaces),
common web-based systems, mobile banking. By customizing
the audit module, any type of online banking system
can be supported. The auditing is performed from
all available perspectives (e.g. simulating that
the potential attacker would be a client, another
bank, employee, contractor, etc.). Detack has
built additional security auditing modules in
order to cover specific e-banking security aspects,
such as "phishing" and more generically,
attacks targeting the clients.
Applicable Detack
Security Audit Modules:
e-Banking Services Audit
/ Anonymous Perspective
e-Banking Services Audit / Anonymous & User
Perspectives
Fake Services Audit for e-Banking
Client System Audit
e-Trading
/ e-Insurance / e-Commerce / Generic e-Business
Similarly with
the e-Banking services target, the selected auditing
covers the particular aspects of the online trading,
online insurance and e-commerce platforms. The
audit modules can be customized in order to cover
practically any possible type of online services
both internal and external ones.
Applicable Detack
Security Audit Modules:
e-Business Services Audit
/ Anonymous Perspective
e-Business Services Audit / Anonymous & User
Perspectives
Fake Services Audit for e-Business
e-Government
Detack provides
for the particular area of e-Government the same
functional services as for other complex application
environments, customized to fit the target selection,
with the addition of structuring the procedures
and reporting as required by governmental regulations
(federal / local state legal and procedural requirements).
Applicable Detack
Security Audit Modules:
e-Government Services Audit
/ Anonymous Perspective
e-Government Services Audit / Anonymous &
User Perspectives
|