Re: pricing model for Pen-test

dave_at_immunitysec.com
Date: 11/14/03

  • Next message: Jimi Thompson: "Re: bluetooth pin-cracker"
    Date: 14 Nov 2003 10:55:08 -0000
    To: pen-test@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) In-Reply-To: <20031112204753.26518.qmail@sf-www3-symnsj.securityfocus.com>

    Any pricing based on a per-IP is bogus anyways. The client knows you are doing a time-based estimate. Just say "6 Class C assessment for 2 weeks is 10K" the same as a "1 Class C assessment for 2 weeks" . As long as you define the scope to basically be a nessus scan plus any extra time that you have goes into "verification" you have all the wiggle room you need. And pricing based on a time estimate is more honest, in my opinion, than tried to develop some complex price scaling algorithm based on scope. Your SOW should have the time limit explicitly in it.

    IMO,
    Dave Aitel
    Immunity, Inc.

    >From: <a55mnky@yahoo.com>
    >To: pen-test@securityfocus.com
    >Subject: pricing model for Pen-test
    >
    >
    >
    >We are responding to an RFP with very little detail - client has 6 class C networks. We have been given no information on how many hosts are live on each and/or how many services are offered on any hosts. Any suggestions on how to price the engagement - certainly there is a significant difference in effort between one web server per subnet and 100+ hosts with multiple services on each.
    >
    >Thnaks in advance.
    >
    >a55mnky
    >
    >---------------------------------------------------------------------------
    >Network with over 10,000 of the brightest minds in information security
    >at the largest, most highly-anticipated industry event of the year.
    >Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    >see demos from more than 250 industry vendors. If your job touches
    >security, you need to be here. Learn more or register at
    >http://www.securityfocus.com/sponsor/RSA_pen-test_031023
    >and use priority code SF4.
    >----------------------------------------------------------------------------
    >
    >

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_pen-test_031023
    and use priority code SF4.
    ----------------------------------------------------------------------------


  • Next message: Jimi Thompson: "Re: bluetooth pin-cracker"

    Relevant Pages

    • RE: New Trojan
      ... and discovered that there is an option to scan ADS, ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Incidents)
    • Foundry switch and VLAN hopping
      ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Pen-Test)
    • Re: Nmap output
      ... most highly-anticipated industry event of the year. ... Choose from over 200 class sessions and ... Network with over 10,000 of the brightest minds in information security ...
      (Pen-Test)
    • RE: New Trojan
      ... Subject: New Trojan ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
      (Incidents)
    • RE: Large increase in port 27347
      ... Network Administrator ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ... and use priority code SF4. ...
      (Incidents)