Rhosys / soc2.fyi

SOC 2 should be easy to get done and it should be inexpensive. Here's everything you wanted to know.
https://soc2.fyi
Apache License 2.0
26 stars 5 forks source link

Add additional penetration testing info #6

Closed GlitchWitch closed 1 year ago

GlitchWitch commented 1 year ago

It was discussed to potentially add the following information to the pentration testing vendor table:

As requested in the mentioned discussion, this issue was created to discuss this further and consolidate some of this information.

I've done my best to compile a list of the first two points based on public information. This list is not authoritative and I encourage others to add to or modify it.

Company Testing Methodologies Retesting Timeframe Retesting Cost
Cobalt OWASP ASVS, OSSTMM 6-12 Months Free
Doyensec TBD TBD TBD
GlitchSecure OWASP ASVS 12 Months Free
Kobalt OWASP ASVS TBD 20% of cost
Rapid7 OWASP ASVS, OSSTMM, PTES TBD TBD

Sources:

wparad commented 1 year ago

I don't know if what I did was the best way to represent these, but this info has been included in the pen testers section: image

Thanks for doing this legwork.