Vulnerability Scan
Description
Renowned institutes, such as the Hasso Plattner Institute, report that more security vulnerabilities have been identified in recent years than ever before. The demand for cybersecurity is steadily rising!
We recognized this trend early on and takes responsibility for the security of your data across all levels of managed hosting. Our data centers have held ISO 27001 certification—the international standard for information security—for years.
We ensure comprehensive data protection today through best-practice configuration settings and established lifecycle processes for operating systems and installed services.
In addition, we offer optional security packages to protect your setup against further attack vectors. The "Security Vulnerability Mitigation" package establishes the framework for patch management of software that is not part of the standard operating system distribution—typically third-party software installed at your request. It also provides the necessary documentation for PCI-DSS compliance.
Vulnerability scanning identifies potential security issues that have arisen over time due to system changes—such as those resulting from your specific modification requests. As the operator of your virtual infrastructure, only we can offer you cost-effective external and internal vulnerability scans. With internal, cross-platform scans performed within our infrastructure, you incur no additional costs for renting the infrastructure typically required for such scans.
We possess the in-house technical expertise to understand and interpret scan results. We are intimately familiar with your setup and can provide recommendations for enhancing its security following a vulnerability scan. Security vulnerability mitigation is a key component of our strategy to ensure greater security for the data you entrust to us. It is particularly important that these analyses are repeated regularly and at frequent intervals, given the rapid pace of change in modern software utilizing CI/CD pipelines.
Our goals for this service
- To offer a comprehensive suite of relevant services from a single source.
- To enable you to show PCI-DSS compliance through internal scans.
- To minimize attack vectors and enhance the security of your setup and data.
- To ensure compliance with legal requirements.
- To complete our portfolio of security-related services for you.
What you can expect from our service
- One scan per month.
- Identification of all IP addresses and hostnames within the PVC platform requiring a scan.
- Execution of the vulnerability scan.
- Provision of a detailed scan report.
- Technical expertise to evaluate your scan results.
- Active mitigation of potential risks.
- Participation in CAB/EC (Change Advisory Board/Emergency Committee) meetings.
- Support from certified Information Security Officers (ISOs).
- Close collaboration with our security team.
Standard Offer
Our standard offer is designed for companies that wish to check their setup for security vulnerabilities on a monthly basis and require a report to evaluate themselves. We perform scans from three different vantage points: (1) externally from the Internet, (2) from within the OpenStack Cloud, and (3) from within the our Cloud PVC. All systems with a public IP address are checked. You receive a detailed report of the results. Based on this, you define the necessary measures, which our DevOps team then implements via our ticketing system.
The monthly price includes:
- All infrastructure required to conduct the scans
- Execution of the scan
- Documentation of the results
Premium Offering
Our premium offering is designed for companies with high security requirements for their setup that need support with implementation. We perform scans from four different points: (1) externally from the Internet, (2) from within the OpenStack Cloud, and (3) from our Cloud PVC. All systems with a public IP address are checked during this process. Additionally, (4) we log into systems with a public IP address via SSH to conduct internal system checks. We analyze your scan results, provide expert advice, and—upon request—participate in CAB/EC (Change Advisory Board/Emergency Committee) meetings. Working together with you, our security engineers define measures to prevent the exploitation of security vulnerabilities or to remediate them. The service manager then supports you in implementing these measures or carries them out on your behalf. Finally, follow-up scans confirm the effectiveness of the measures taken.
The monthly price also includes:
- One hour of security engineer time.
- One hour of service manager time.
- Setup of SSH access required to perform the scans.
- Documentation of results in XML format.
- Also available to customers on OpenStack Cloud or users of MetaKube.
Important Information
We offers security vulnerability mitigation as part of its managed hosting services. You can find further information and details about our managed hosting services on our website