A penetration test is only useful if developers can act on the result. A long PDF of scanner output does not help anyone ship a fix. Here is what a development team should expect from a vulnerability assessment and penetration test (VAPT), based on how the security team at Affix Center in Mumbai runs these engagements.
What gets tested
- Infrastructure, applications and APIs, not only the public website
- Secure configuration reviews of the systems the app runs on
- Controlled penetration testing, so production is not put at risk
What you should get back
- A risk-ranked report, so the team knows what to fix first
- Remediation steps for each finding
- Both an executive report and a technical report, because managers and developers need different detail
- A retest after the fixes, to confirm they worked
Controls worth building in before the test
- A secure development lifecycle
- Authentication and authorisation on every API
- Encryption at rest and in transit
- Role-based access, with audit and compliance traceability
How often
Run VAPT at least once a year, and again after any major change to an application or to infrastructure.
If your organisation faces NIC or CERT-In empanelled security audits, plan time to fix the observations those audits raise. That work usually lands on the development team.
More detail on scope and process: Cyber Security and VAPT services by Affix Center
Written by the team at Affix Center, an IT services company in Lower Parel, Mumbai.
Top comments (1)
tr.ee/dev-to