<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://website.isecpartners.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>iSEC Partners - </title>
 <link>http://website.isecpartners.com/application_security_services_java_net_win32_etc</link>
 <description></description>
 <language>en</language>
<item>
 <title>Application and Product Penetration Testing</title>
 <link>http://website.isecpartners.com/application_and_product_penetration_testing</link>
 <description> &lt;ul&gt;
&lt;li&gt;Identification of security weaknesses through penetration testing with or without code review&lt;/li&gt;
&lt;li&gt;Demonstration of weaknesses as needed to validate findings&lt;/li&gt;
&lt;li&gt;Simplified architecture review and threat modeling&lt;/li&gt;
&lt;li&gt;Characterization of the impact of a successful attack&lt;/li&gt;
&lt;li&gt;Recommend solutions for addressing weaknesses&lt;/li&gt;
&lt;li&gt;The application, protocol, or implementation&#039;s security posture is reported&lt;/li&gt;
&lt;li&gt;Upon request, a public facing document explaining the test methodology and results can be provided&lt;/li&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 20:26:00 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">32 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Application Design Review</title>
 <link>http://website.isecpartners.com/application_design_review</link>
 <description> &lt;ul&gt;
&lt;li&gt;Conduct a review of a system&#039;s design&lt;/li&gt;
&lt;li&gt;Identify security implications of the design&lt;/li&gt;
&lt;li&gt;Perform threat modeling&lt;/li&gt;
&lt;li&gt;Perform a gap analysis between the design and industry best practices&lt;/li&gt;
&lt;li&gt;Enumerate conflicts between business requirements and security considerations so informed trade offs are made&lt;/li&gt;
&lt;li&gt;Recommend solutions for addressing security weaknesses&lt;/li&gt;
&lt;li&gt;Can be conducted prior to implementation, or once in production&lt;/li&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Thu, 27 Jul 2006 22:15:19 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">44 at http://website.isecpartners.com</guid>
</item>
<item>
 <title>Application Code Review</title>
 <link>http://website.isecpartners.com/application_code_review</link>
 <description> &lt;ul&gt;
&lt;li&gt;Examine sensitive areas of software code&lt;/li&gt;
&lt;li&gt;Identify security flaws including: race conditions, overflows, character set conversion problems, logical errors, bad assumptions, key management flaws, and cryptographic mistakes&lt;/li&gt;
&lt;li&gt;Recommend specific fixes and general coding practice improvements appropriate to the Client&#039;s environment&lt;/li&gt;
&lt;li&gt;Lead groups of developer through code review exercises to enhance the Client&#039;s ability to audit code&lt;/li&gt;
&lt;li&gt;Upon request, a public facing document explaining the test methodology and results can be provided&lt;/li&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Fri, 28 Jul 2006 00:44:08 -0700</pubDate>
 <dc:creator>sarva</dc:creator>
 <guid isPermaLink="false">57 at http://website.isecpartners.com</guid>
</item>
</channel>
</rss>
