Our Penetration Test Program Assessment evaluates program activities and documentation to identify areas for improvement.
The foundation of the assessment is ‘NIST SP 800-115, Technical Guide to Information Security Testing and Assessment’. Remaining practices have been developed by Gideon Rasmussen based on 20+ years of cybersecurity experience within corporate and military organizations.
Areas of focus include:
Deliverables include an assessment report and a slide deck presented to executive leadership.
Fees and Payment
The assessment is billed at a flat rate. The engagement begins once the Statement of Work and Contract are signed and upon receipt of the first of three equal payments.
SOW and Contract Execution
First Assessment Interview
Delivery of Draft Report
Custom assessments may be conducted based on the needs of the client. Here are examples:
|Application Security||Vendors and Service Providers||Cybersecurity Program||Ransomware|
|Business Process Risk||Incident Response||Line of Business Risk||FMEA Process Risk|
|Security Operations Center (SOC)||Fraud Prevention||Insider Threat||Security Awareness Program|
|Mergers and Acquisitions||Infrastructure Security||Zero Trust Security Model||Threat Landscape and Controls|
|Cyber Exercise Program||Penetration Test Program||Cybersecurity Function|