KRITERA / CASES

TS 13638-aligned penetration test for a public healthcare body

Network, web and authorization layers of critical healthcare systems were assessed in one scope.

Approach

A scope, threat model, manual validation, remediation and retest chain was applied.

Scope

  • Architecture and data flow
  • Identity and authorization
  • Manual security testing

Outputs

  • Executive summary
  • Technical evidence set
  • Remediation and retest plan

Outcome

The organization could manage technical risks and governance decisions in one closure plan.