Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 340
  • Last Modified:

What should we pay for Vulnerabilty Testing???

Hello we are a small financial institution and are in need of basic vulnerability testing (NOT INTRUSION or external) just Vulnerability testing from the inside. We have to have this, so please don't try to tell what other options I have. We are getting a wide range of prices and services and I am not sure what we should be paying for this. We have 25 TOTAL nodes, and have been quoted from 100-200/per node plus software usage fees. Flat fees from $3500-7500. Hourly fees etc etc.
Can anyone clarify this for us? We are Windows XP running Server 2003 with 3 locations.
Thank you
0
final4fever
Asked:
final4fever
  • 2
1 Solution
 
PowerITCommented:
This is probably more of an economics question then a security question, but I'll still try to formulate an answer.
First, you should not pay more then it's worth to you. But also not much less, or quality will suffer.
I have the feeling that you are legally obliged to do this, so it will be hard to set a maximum value, because if you don't then you are probably out of business.
So then the price will also be influenced by current market demand. You know, supply and demand.
IF I do a quick calculation using avarage tarifs I know about and needed time then I would say: $4.375 + travelling costs for the 3 locations.
Mind you: this is an avarage. Where you are located can also vary the pricing: in some area's consultancy (and the labour hours) is more expensive then in others. Hiring in London or NYC will be more expensive then lets say ... Kiev.

Hope this helps.

J.

0
 
nttranbaoCommented:
You may want to use nessus ( www.nessus.org) to scan the system yourself, and see the explanation for each vulnerability found.
0
 
PowerITCommented:
I doubt that doing a vulnerability assessment by a non (certified) security professional who can not accurately interpret the results will be sufficient as a required audit for a financial institution.

J.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now