..

This design element requires flash & JavaScript to be enabled to play. Download the latest version of flash from Adobe.com.

Enterprise Application & Database Security

Regular testing of your network infrastructure and applications is a critical activity for ongoing assurance that your network remains safe, and that your investment in perimeter controls is yielding the expected return.

commissum provides a comprehensive range of internal and external network and application testing services, as well as cost-effective vulnerability assessments in between these detailed tests.

SAP & Oracle Security

commissum services encompass all aspects of enterprise application security, from initial requirements analysis, through design review, code security and implementation advice, to specialised security testing that is tailored specifically to the business application.

Large-scale enterprise applications such as SAP and Oracle are becoming standard for many organisations in the private and public sectors. As the backbone of financial, HR, supply chain, and customer relationship management, they provide the analytical functions and business information that is critical to running operations and remaining competitive.

These enterprise applications, in terms of cost of up-front investment and ongoing business continuity, are among the most critical of an organisation's corporate assets. However, from a security perspective, in many cases they are the weakest link.

A common perception is that security starts and ends with an application’s authorisation and authentication mechanisms. However, this is just scratching the surface of the security challenge in a large-scale deployment. Potential threats to integrity, availability and confidentiality are widespread. These threats reside at the infrastructure, database and application layers, in customisation, in the interfaces between systems, and in the files that exist on the file system.

These enterprise application issues are exacerbated by the following:

  • A lack of consistent, formally-published security best practice.
  • General lack of awareness of the potential issues.
  • Scarcity of knowledge and experience in enterprise application security.

In this uncertain environment, our consultants will work with you, bringing to bear their years of experience in enterprise application security within the public, private and defence sectors, to help you address the risks that you face.

Approach to enterprise application assurance

commissum’s Enterprise Application Assurance Services encompass all aspects of security from initial requirements analysis, through design review, bespoke code security and implementation advice, to specialised security testing that is tailored specifically towards each particular application.

Depending upon your requirements, commissum can provide services addressing:

  • Segregation of duties.
  • Authorisation and access control.
  • Auditing and monitoring.
  • Infrastructure security assessment.
  • Host OS hardening.
  • Database security.
  • Code review and development assurance.
  • Application security testing.
  • Training and mentoring.

Ideally, a client will engage the services of commissum’s specialists from the earliest phases of a project. It is significantly more cost-effective to design with best practice security in mind from the start. However, the knowledge and skills of the commissum team can be applied at all stages, particularly as independent assurance specialists forming part of the critical design review process.

Customer benefits of enterprise application assurance

commissum’s independent and objective advice provides clients with the following:

  • A concentrated pool of security-focused resource with specialist enterprise application security skills.
  • Objective, independent advice on enterprise application security and assurance.
  • Guidance on best practice control measures and corrective action required to improve security deployment and integrity.
  • Assurance that implementations are able to resist a range of attacks.
  • Benchmarking of outsourced implementations against appropriate and relevant industry-accepted practice.
  • Specialist skills and experience with enterprise application security in H.M. Government and the defence industry.
  • Specific experience and knowledge of working with the public sector to address the security challenges of enterprise applications in shared services environments.
  • Recommended hardened configurations for system components.

Get in touch with one of our security consultants today

  • No obligation
  • Expert advice
  • Tailored solutions
"We engaged with commissum for the first time this year and found them highly professional and a pleasure to do business with. We were particularly pleased with the report provided which was of excellent quality, with an appropriate level of detail and clarity in its recommendations. I would happily refer others to commissum.”

Mr Billy K, IT Director, National Law Firm

Latest News

country flags

UK cyber-security among the world's best in recent report

A new report collates the views of international cybersecurity experts to grade several countries according to the strength of their defence against Internet attacks.  The report, sponsored by the computer security company McAfee, ranks Israel, Finland and Sweden as the top-performing countries, with four and a half out of five ...
Tue 31 Jan, 2012 // Briony
SecurityLock

McAfee fixing spamming bug in anti-malware software

McAfee, the prominent anti-malware software firm, has been fixing a flaw discovered in its software that would allow a spammer to use an infected machine to send floods of spam emails.The flaw was found in McAfee’s “SaaS for Total Protection” cloud-based anti-malware software.  The flaw crucially depended on the software’s ...
Fri 27 Jan, 2012 // Briony
Online Threats

Beware! Ransomware Attacks Are On the Rise

Cloud security company Panda Security, have announced on their blog PandaLabs, that ransomware attacks are increasing. Not only are the attacks more common but also more sophisticated. Leaving personal and business users having to face new major threat in the coming year.What Is Ransomware?Ransomware is a type of malware, that ...
Tue 24 Jan, 2012 // Chris