<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://website.isecpartners.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>iSEC Partners - </title>
 <link>http://website.isecpartners.com/isr_independent_security_report</link>
 <description></description>
 <language>en</language>
<item>
 <title>Publicly Available Independent Security Reports</title>
 <link>http://website.isecpartners.com/publicly_available_independent_security_reports</link>
 <description> &lt;p&gt;&lt;a href=&quot;/files/Juniper_IVE_iSR_v5.pdf&quot;&gt;Juniper Networks&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;/files/iSR-Japanese.pdf&quot;&gt;Juniper Networks (Japanese version)&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;/files/iSEC_Macromedia_Activation_White_Paper.pdf&quot;&gt;Macromedia&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;/files/WebEx_OnDemandTraceReport.pdf&quot;&gt;WebEx Communications&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Companies often have functionality that needs to be established as consistent with industry standards.  Others may have security features that need to be highlighted as differentiators in their industry. Almost all businesses need to verify to their auditors and customers that an independent security assessment has been performed.&lt;/p&gt;
&lt;p&gt;However, budgets and schedules rarely support a comprehensive security review of an entire product or service. To this end, iSEC Partners has developed a methodology for conducting ongoing security assessments that are focused on:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Creating an Independent Security Report (iSR) that highlights the validation testing of “security assertions”&lt;/li&gt;
&lt;li&gt;Assessing high-risk components&lt;/li&gt;
&lt;li&gt;Conducting tests that address questions raised in most vendor security questionnaires&lt;/li&gt;
&lt;li&gt;Creating a process for ongoing security QA while satiating the needs of security, product development and marketing teams&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;iSEC Partners’ Security Assurance Program is an iterative process that provides a practical view of what a motivated attacker might accomplish. iSEC Partners conducts assessments that model specific threat scenarios, identify vulnerabilities, and enumerate exploitation possibilities. While the testing methodology is flexible, each assessment includes – at a minimum – the following processes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Documentation review&lt;/li&gt;
&lt;li&gt;Developer interviews&lt;/li&gt;
&lt;li&gt;Threat modeling&lt;/li&gt;
&lt;li&gt;Design review of new features and functions&lt;/li&gt;
&lt;li&gt;Active testing of mutually agreed upon features and functions&lt;/li&gt;
&lt;li&gt;Review of changes made to fix vulnerabilities identified in previous releases&lt;/li&gt;
&lt;li&gt;Manual and automated penetration testing&lt;/li&gt;
&lt;li&gt;Code review (where necessary for validation)&lt;/li&gt;
&lt;li&gt;Validation testing of “security assertions” for inclusion in the Independent Security Report (iSR)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;iSEC Partners’ iSR provides high-level information about the ongoing process to improve security and more specific information about tests conducted against specific features. iSEC Partners believes the independent review of security assertions provides the following benefits:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Customers and prospective customers benefit from validation of specific assertions made by the product and visibility into the ongoing security assessment process&lt;/li&gt;
&lt;li&gt;Our Clients receive the iSR that can be used proactively in their sales processes. They also benefit from consistent and recurring recommendations for improving the security of their product. This predictable and consistent review is much more efficiently folded into the development process than ad hoc security reviews conducted when budgets allow and customers demand.&lt;/li&gt;
&lt;li&gt;Venture Companies and individual investors benefit from the knowledge that the company and product they have invested in - or are evaluating for funding – have an ongoing security assessment process&lt;/li&gt;
&lt;/ul&gt;
&lt;br class=&quot;clear&quot; /&gt;</description>
 <pubDate>Tue, 01 May 2007 04:21:01 -0700</pubDate>
 <dc:creator>anastasia</dc:creator>
 <guid isPermaLink="false">216 at http://website.isecpartners.com</guid>
</item>
</channel>
</rss>
