Penetration Test for Your Audit According to TISAX
ISA 6 of the VDA requires the performance of service-specific tests and/or penetration tests in the event of high protection requirements in the area of information security under point 5.2.6. In the case of very high protection requirements, IT systems and services must even be scanned regularly for vulnerabilities.
An internal penetration test in particular is often associated with high costs, which are often further increased by several testers on site, travel, accommodation and other costs. However, these costs are unnecessary, as almost all types of penetration test can be carried out remotely. Only if physical security, e.g. access control, is also to be tested is it necessary to be present on your premises. We have therefore developed specialized penetration test appliances for this purpose, which enable us to carry out a complete penetration test in your network without actually having to be on site.
Penetration Test Procedure
The procedure for a remote internal penetration test is as follows:
- we send you one or more appliances, depending on the scope of the penetration test
- you connect the appliance to your network, which receives an IP address from your network via DHCP
- you allow the appliance to use HTTPS, which automatically sets up a securely encrypted VPN tunnel to us
- we gain access to the system through the tunnel and can carry out the penetration test
- each appliance requires three IP addresses for full functionality with all attack options
- after completion of the test, you send the appliance back to us
- we create a detailed penetration test report to improve your information security and for your audit
The appliance allows us to perform port scans as well as vulnerability scans and even complex exploits against your systems.
For a complete vulnerability scan of your entire infrastructure, you can enable the IP addresses used by the appliance on your firewall. Alternatively, you can simply connect the appliance to your client network and check how far an attacker would get from there.
More Questions?
We would be happy to present our penetration tests and our approach to you in detail. We offer attractive fixed prices especially for SMEs that have to comply with TISAX.