pen-test
[Top] [All Lists]

Re: Pen-testing - pricing model

To: pen-test@securityfocus.com, Chris Stromblad <chris@fragzone.se>
Subject: Re: Pen-testing - pricing model
From: <sami.ghourabi@icn.com.tn>
Date: Fri, 01 Dec 2006 21:56:57 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Reply-to: sami.ghourabi@icn.com.tn
Resent-date: Fri, 1 Dec 2006 14:17:31 -0700 (MST)
Resent-from: pen-test-return-1078483086@securityfocus.com
Resent-message-id: <20061201211731.1FB902380A8@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
I would try to evaluate necessary time to do the job and charge XX dinars (or
dollars) per 8 hours day

On Thu Nov 30 10:59 , Chris Stromblad  sent:

>Hi list,
>
>Those of you who work with this professionally, what sort of pricing 
>model do you use? How do you assess what should be charged for the test? 
>Considering the fact that there are many types of pen-tests and all have 
>different scope. I'm having a hard time figuring out if the prices that 
>has been given to me are reasonable.
>
>Say I were to give you one of the following scenarios, what would you 
>charge (roughly):
>
>1. "Black box with shades of gray", 2 /24 networks, not all devices are 
>active. External scan.
>
>2. Internal scan, only devices
>
>3. Internal scan, procedures, physical security and devices
>
>I know this question is somewhat difficult to answer, because there is 
>no correct answer, but any advice is welcome.
>
>Cheers,
>Chris
>
>
>------------------------------------------------------------------------
>This List Sponsored by: Cenzic
>
>Need to secure your web apps?
>Cenzic Hailstorm finds vulnerabilities fast.
>Click the link to buy it, try it or download Hailstorm for FREE.
>http://www.cenzic.com/products_services/download_hailstorm.php\?camp=701600000008bOW
>------------------------------------------------------------------------
>



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>