Leading service provider turns to Covestic for Web application and host security assessment business challenge.
BUSINESS CHALLENGE
A leading service provider was in the process of rapidly expanding into new markets. They used a Web
portal to market and sign up new customers, and wanted to analyze their security configuration before
opening up more markets. In addition, the site was being used to process and transfer sensitive personal
information for customer accounts. The company was growing rapidly and lacked internal staff to
properly test the Web server and its applications.
COVESTIC'S SOLUTION
Covestic was asked to perform an application security architecture assessment. The client's Web portal
host and application configuration were assessed for vulnerabilities. Not only were security
vulnerabilities identified, but a failure in their load balancing capability for the portal
was also uncovered. Covestic recommended a reconfiguration of the Web portal and the remediation
of the security vulnerabilities.
PROJECT RESULTS
By identifying key security vulnerabilities in the company's Web application architecture and proposing
the steps necessary for remediation, Covestic enabled the company to secure the Web portal as well as
design more secure Web host and application configurations. Since this portal is the company's primary
vehicle for signing up new customers and servicing existing ones, the assessment has helped the company
ensure that their business operations are not easily disrupted or compromised. In addition, while in the
process of performing the security assessment, Covestic identified a serious availability issue and
alerted the client to the problem.
THE COVESTIC ADVANTAGE
Covestic's experienced team was able to help the service provider quickly address serious concerns.
Their technical staff now has a strong understanding of how to properly secure a Web portal before it
is placed into a production environment. They also now recognize the value of an ongoing security
effort in protecting critical business assets.
We understand that security and risk management must support business functions. This approach
allows executives to understand the value of security. Conversely, it helps security technologists
align their effort with business needs.
|