<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Tag security assessment</title>
    <link>http://blog.clearnetsec.com/articles/tag/securityassessment</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>Informative survey from Jeremiah Grossman</title>
      <description>&lt;a href="http://jeremiahgrossman.blogspot.com/2006/10/web-application-security-professionals.html"&gt;http://jeremiahgrossman.blogspot.com/2006/10/web-application-security-professionals.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;p&gt;
What caught my eye was #3.  71% responded they &lt;b&gt;&lt;i&gt;never&lt;/b&gt;&lt;/i&gt; "use a commercial web application vulnerability scanner during security assessments".
&lt;/p&gt;
&lt;p&gt;
That surprised me for a couple of reasons:&lt;br /&gt;
&lt;blockquote&gt;
1.  Clients frequently request the use of a commercial scanner&lt;br /&gt;
2.  Many of the larger security services firms we deal with (i.e. give us projects) not only have a enterprise type license for one or more commercial tools but also require their use when doing a security assessment on their behalf.  
&lt;/blockquote&gt;
&lt;/p&gt;


</description>
      <pubDate>Tue, 17 Oct 2006 14:59:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:b6f10037-b524-4b34-bccd-7ccc99fc3f86</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2006/10/17/informative-survey-from-jeremiah-grossman</link>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>security assessment</category>
      <category>survey</category>
    </item>
  </channel>
</rss>
