Solved

What should we pay for Vulnerabilty Testing???

Posted on 2007-11-27
3
311 Views
Last Modified: 2010-05-18
Hello we are a small financial institution and are in need of basic vulnerability testing (NOT INTRUSION or external) just Vulnerability testing from the inside. We have to have this, so please don't try to tell what other options I have. We are getting a wide range of prices and services and I am not sure what we should be paying for this. We have 25 TOTAL nodes, and have been quoted from 100-200/per node plus software usage fees. Flat fees from $3500-7500. Hourly fees etc etc.
Can anyone clarify this for us? We are Windows XP running Server 2003 with 3 locations.
Thank you
0
Comment
Question by:final4fever
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 18

Accepted Solution

by:
PowerIT earned 200 total points
ID: 20364183
This is probably more of an economics question then a security question, but I'll still try to formulate an answer.
First, you should not pay more then it's worth to you. But also not much less, or quality will suffer.
I have the feeling that you are legally obliged to do this, so it will be hard to set a maximum value, because if you don't then you are probably out of business.
So then the price will also be influenced by current market demand. You know, supply and demand.
IF I do a quick calculation using avarage tarifs I know about and needed time then I would say: $4.375 + travelling costs for the 3 locations.
Mind you: this is an avarage. Where you are located can also vary the pricing: in some area's consultancy (and the labour hours) is more expensive then in others. Hiring in London or NYC will be more expensive then lets say ... Kiev.

Hope this helps.

J.

0
 
LVL 7

Expert Comment

by:nttranbao
ID: 20364355
You may want to use nessus ( www.nessus.org) to scan the system yourself, and see the explanation for each vulnerability found.
0
 
LVL 18

Expert Comment

by:PowerIT
ID: 20364401
I doubt that doing a vulnerability assessment by a non (certified) security professional who can not accurately interpret the results will be sufficient as a required audit for a financial institution.

J.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Unable to get rid of Trojans in Windows 7 19 147
Eset Smart Securties ARP poisoning attack 3 91
exchange 2010 Dag failed 3 67
Frequency of Windows Server updates 27 140
Smart phones, smart watches, Bluetooth-connected devices—the IoT is all around us. In this article, we take a look at the security implications of our highly connected world.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question