Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
100 criteria
baselineProvide a percentage break down of how much of the engagement will be performed on your site, the organization's site, or remotely.
baselineDoes the platform provide continuous/automated breach-and-attack simulation (BAS) versus point-in-time manual penetration testing, and can both be run from the same platform?
baselineDescribe the attack technique library (MITRE ATT&CK coverage) — how many techniques/procedures are simulated, and how frequently is the library updated to reflect newly observed adversary TTPs?
baselineHow does the platform validate whether existing security controls (EDR, SIEM, firewall) actually detected or blocked each simulated attack, and is this validation automated or does it require manual log review?
baselineFor manual/human-led penetration testing, what are the tester qualifications (OSCP, OSCE, CREST, etc.), and can customers request specific testers or specializations (web app, cloud, red team)?
baselineDetail reporting depth for a completed engagement — does it include exploitation proof, business-risk framing, and prioritized remediation guidance, and what is the typical turnaround time from test completion to final report?
baselineDoes the platform support purple-team exercises where simulation results are used collaboratively with the defense team in real time, versus a black-box report delivered after the fact?
baselineExplain how remediation is verified — is there an automated re-test of the specific attack path after a fix is applied, and what is the typical cost/effort of a re-test compared to the original engagement?
baselineWhat is the safety/blast-radius model for automated BAS in production environments — are simulated attacks executed safely with no real payload/exploitation, or does the platform require a staging environment?
baselineIdentify by name all Key Personnel and describe their technical knowledge, experience, qualifications, education, and depth of expertise relevant to the requested services; submit resumes (max 2 pages each).
baselineProvide a description of recent experience providing related penetration-testing-as-a-service, with examples of projects and personnel including position types and assignment lengths.
baselineProvide a list of 2-3 current or recently completed contracts similar in scope, including client name, project title, period of performance, contract number/value, and primary/backup points of contact.
baselineIdentify tasks that will be performed by your Firm and tasks that will be performed by the organization's staff.
baselinePrepare recommendations to address vulnerabilities for IT Management systems and suggest IT Security best practices.
baselineSocial Engineering: phishing simulation campaigns, pretexting and vishing scenarios, and physical engineering.
baselineVendors should provide a range of testing and validation services; vendors must not only describe their approach but also provide evidence of their capability in each area (Penetration Testing, Red Team, Purple Team, BAS).
baselineDefine potential penetration testing scenarios with the ISO.
baselinePerform manual-first penetration testing across external, internal, cloud, and application environments.
baselinePlan and prepare for the penetration test results to include scripts and presentation materials and review with the ISO.
baselineEvaluate reports, methodologies, credentials, and references for the penetration testing engagement.
baselineFacilitate a 3-4 hour penetration test results session with 20-30 department leaders and IT professionals from the organization.
baselineDocument, within 30 days, penetration test results to include documented scenarios, evaluation of the port authority's response to scenarios, and documented well-done items and opportunities for improvement.
baselinePerform Red Team exercises that emulate real-world threat actors.
baselineProvide a case study of a previous adversary emulation engagement, including objectives, outcomes, and mapped tactics using the MITRE ATT&CK framework.
baselineProvide metrics from Red Team engagements (e.g., time-to-detect, dwell time, response effectiveness).
baselineProvide Red Team qualifications (e.g., GPEN, CRTP) of team members.
baselineFacilitate Purple Team sessions where offensive tactics, techniques, and procedures (TTPs) are executed while defenders tune detections in real time.
baselineDoes the platform offer cloud-native attack-path simulation specific to AWS/Azure/GCP misconfigurations and privilege-escalation chains, distinct from traditional network/endpoint attack simulation?
baselineDetail social-engineering and physical penetration testing scope — does the service include pretexting, tailgating/physical-access testing, or is the offering limited to purely technical/network attack simulation?
baselineHow does the platform or service specifically support compliance-mandated annual penetration tests (PCI DSS, SOC 2) — does it produce an attestation-ready report format auditors will accept, and has it been accepted by auditors for real customers?
baselineExplain the pricing model — per-engagement flat fee, subscription for continuous BAS, or hybrid — and provide a total cost comparison between a single annual manual pentest and a year of continuous automated simulation for a comparable environment.
baselineDoes the platform offer red-team-as-a-service with a continuous/retained engagement model (ongoing embedded adversary simulation) versus only discrete, scheduled engagements, and what does a typical retained-service SLA look like?
baselineHow deep is API and application-layer penetration testing specifically (business-logic flaws, broken authorization, not just OWASP Top 10 automated scanning) — are these manual, specialist-led tests or automated tooling relabeled as 'API pentesting'?
baselineDetail ransomware-specific attack simulation — does the platform simulate real-world ransomware TTPs (lateral movement, backup-deletion attempts, exfiltration-before-encryption) end-to-end, and can it validate whether backup/recovery controls would actually survive a simulated attack?
baselineHow does the platform integrate with the customer's existing vulnerability management program so that simulation-validated attack paths and scanner-identified vulnerabilities feed into a single combined risk view, rather than two disconnected reports?
baselineProvide a sample agenda or workshop outline for Purple Team exercises.
baselineProvide example Purple Team deliverables such as after-action reports, detection tuning documentation, or playbook updates.
baselineProvide client feedback or testimonials highlighting measurable improvements in detection or response from Purple Team engagements.
baselineProvide mapping of Purple Team tactics to MITRE ATT&CK for transparency.
baselineProvide a breach and attack simulation (BAS) platform or managed service to continuously validate controls.
baselineProvide screenshots or sample reports from the BAS platform.
baselineProvide proof of BAS integration with Security Information and Event Management (SIEM) systems and Security Orchestration, Automation, and Response (SOAR) platforms.
baselineProvide documentation showing how repeatable BAS testing is scheduled and validated.
baselineProvide metrics demonstrating BAS detection coverage and improvements over time.
baselineTest internet-facing assets (perimeter, VPN, remote access, web portals) for exploitable weaknesses (External Network Testing).
baselineAssess internal systems and segmentation for lateral movement opportunities and common misconfigurations (Internal Network Testing).
baselineAttempt to escalate privileges and move across systems to simulate real attacker behavior (Privilege Escalation & Lateral Movement).
baselineConduct simulated phishing and approved pretexting scenarios to assess user awareness and process controls (Social Engineering, optional/scoped).
baselineRecord validated findings with proof-of-concept details and reproduction steps (Evidence & Exploitation Documentation).
baselineProvide fix validation support and a retest option for high/critical findings (Remediation Guidance & Retest, optional/scoped).
baselineComplete pricing information (Attachment 1 - Bid Sheet), proposing alternative pricing for the PTaaS approach, fully loaded including wages, overhead, G&A, taxes, and profit.
baselineDeliver a Penetration Test Report (PDF/Word) covering scope, methods, validated findings, exploited vectors, and recommended remediations, including an estimate of hours to remediate the findings.
baselineProvide details of the cybersecurity professionals who will be involved in the engagement, including qualifications, certifications (e.g., CISSP, CEH, OSCP), and experience (Team Qualifications).
baselineProvide periodic penetration testing of the housing finance agency's public-facing web applications with a report and debriefing upon completion.
baselineProvide a clear outline of the approach and methodology for both the Cybersecurity Risk Assessment and Penetration Test, including tools, techniques, and standards followed (e.g., NIST, OWASP).
baselineProvide periodic penetration testing of the housing finance agency's Wi-Fi with a report and debriefing upon completion.
baselineProvide a Penetration-Testing-as-a-Service (PTaaS) offering that allows the organization to dynamically request testing, coordinate execution, and receive results through a centralized platform, minimizing manual processes and focusing on automation, efficiency, and the most relevant threats.
baselineProvide Internal and External Network Vulnerability Assessment & Penetration Testing, and Web Application Penetration Testing.
baselineDescribe capabilities for performing the services, including personnel resources and management capabilities, and how subcontractors or partners are used and how rates are determined when using subcontractors.
baselineIndicate the location of the office(s) from which the work on this engagement is to be performed.
baselinePerform authorized external network penetration testing of the public-facing perimeter of all the municipality's locations, including all externally reachable municipality-owned IP addresses, internet-facing services, web applications, remote access portals, VPN endpoints, and externally hosted services, including reconnaissance, service/version enumeration, vulnerability identification, authenticated and unauthenticated exploitation attempts, password attacks against exposed authentication interfaces, and manual validation of all findings (automated scanning alone is not permissible).
baselinePerform authorized internal network penetration testing of two isolated internal environments (the main municipal facility and the Police Department), simulating a threat actor with internal network access, including network discovery, vulnerability identification, lateral movement, privilege escalation, credential harvesting, Active Directory enumeration and attack path analysis, with manual validation of all findings.
baselineDeploy a separate, hardened, encrypted-at-rest testing appliance to each isolated internal environment for parallel testing; appliances shall be uniquely identified and removed or sanitized at the conclusion of the engagement.
baselinePerform authorized social engineering testing of municipal personnel, including email phishing campaigns against an agreed-upon population, sophisticated enough to simulate an adversary-in-the-middle (AiTM) attack.
baselineCoordinate testing windows with municipal IT staff and, for Police Department systems, with the Chief of Police or designee; provide weekly updates during active testing and immediately notify the municipality of any critical finding presenting an active risk to operations or public safety.
baselineObtain municipal approval before proceeding with validation of any finding that could disrupt municipal operations.
baselineDeliver a written final report including an executive summary for a non-technical audience, detailed technical findings with risk ratings/evidence/remediation recommendations, an attack narrative, a social engineering results summary (click rates and credential capture rates by group), and a prioritized remediation roadmap, with all findings scored using CVSS or an equivalent standard.
baselineMaintain and deliver an engagement log documenting date/time of each attack performed (with emphasis on successful attacks) to allow the municipality to correlate testing activity against its security monitoring and alerting systems.
baselineBe available to present findings to municipal staff and, if requested, to the governing board in executive session.
baselineStore all engagement data in encrypted form, not transmit municipal data to any third party, not use municipal data for marketing/case studies/AI-ML training, and securely destroy all engagement data no later than 30 days after final report acceptance except where retention is required by law.
baselineBe willing and ready to sign a non-disclosure agreement.
baselineConfer with municipal IT staff and the Police Department on penetration testing matters as requested during the contract term.
baselineAcknowledge that the anticipated services described can be provided and indicate any relevant additional services the firm would offer.
baselineDemonstrate a minimum of five (5) years of experience providing network penetration testing services, with documented experience serving municipal, public sector, or law enforcement clients.
baselineDemonstrate experience performing external, internal, and social engineering penetration testing engagements of comparable scope.
baselineDemonstrate familiarity with industry-recognized testing methodologies (e.g., PTES).
baselineIdentify staffing qualifications, including the proposed engagement lead.
baselineProvide a methodology overview and sample (redacted) deliverables demonstrating minimum requirements.
baselineProvide a sample (redacted) penetration testing report demonstrating the firm's reporting format and quality.
baselineConfirm the firm has the legal authority and technical capability to perform network penetration testing services and shall comply with applicable laws, including the Computer Fraud and Abuse Act, applicable state computer crime statutes, and the FBI CJIS Security Policy where applicable.
baselineConduct white-box testing for both a Cybersecurity Risk Assessment and a Penetration Test across eight of the housing authority's locations and fourteen departments, covering 10+ cloud applications, 2 web applications, AD, endpoints, and on-premises equipment for 500+ devices, targeting 350+ users, including phishing, vishing, smishing, and physical pretexting.
baselinePropose an approach for testing mission systems and applications in pre-production/production-like test environments for vulnerabilities, design anti-patterns, resistance to DoS/DDoS, and common coding and configuration errors, with options for tailoring scope, retesting remediated findings, and focused ad hoc tests.
baselinePerform Ethical Hacking testing including internal network scanning, port scanning, system fingerprinting, services probing, exploit research, manual vulnerability/configuration testing and verification, application layer testing, firewall/ACL testing, privilege escalation, password strength testing, network equipment and database security controls testing, and internal network scanning for known trojans.
baselinePerform Web Application testing including injection, broken authentication/session management, XSS, insecure direct object references, security misconfiguration, sensitive data exposure, missing function-level access control, CSRF, use of components with known vulnerabilities, unvalidated redirects/forwards, API/web services testing, session hijacking (MITM/sniffing/sidejacking), and malicious file upload.
baselinePerform application code testing for user session management including input validation of login fields, cookie security, lockouts, and user session integrity.
baselineTest across all major user types for each system (anonymous, external, internal non-privileged, internal privileged users) as recommended by the organization based on access levels.
baselineOffer optional Social Engineering Testing (phishing, vishing, smishing, and AI emulation/simulation) supporting three corporate-level campaigns annually, and publish an annual Social Engineering Assessment Report with recommendations, outcomes, and key risks.
baselineOffer optional Physical Environment Testing including Wi-Fi penetration testing of corporate and guest networks, and physical access testing (tailgating, guest verification/monitoring, access to controlled rooms) at the organization's headquarters.
baselineHold a Contract Kick-Off Meeting no later than 10 workdays after contract award to introduce teams and coordinate technical planning.
baselineDevelop and submit an Onboarding Plan for all Contractor personnel, test accounts, tools, and coordination of support by the organization's teams within 10 business days of contract award.
baselineDevelop and submit a draft and final Core System Penetration Test Plan for each of up to 20 systems, with Contractor responsible for coordinating access and readiness to commence testing on schedule.
baselinePublish a draft and final Core System Penetration Test Report for each system tested, summarizing all findings rated by severity, with sources, reproduction instructions, and coverage of each significant finding, within 10 business days after test conclusion.
baselineEmail the organization's product manager within 1 business day of discovering a Critical or High severity finding, with draft details and reproduction instructions (Significant Alert of Finding).
baselineCoordinate with the organization to document opportunities, threats, techniques, approaches, and audiences for three annual social engineering tests (Social Engineering Annual Strategy) within 45 calendar days of contract award and annually thereafter.
baselineProvide monthly Ad Hoc Penetration Test reports covering all ad hoc tests accomplished, planned, in-progress, or canceled, for remediation verification or targeted vulnerability/fraud-risk testing requested by the organization.
baselineProvide a weekly status report by email consolidating activities performed and planned, and a formal monthly status report of major activities/accomplishments for the organization's leadership.
baselineDevelop a 60-day Transition Out Plan before end of the period of performance, including knowledge transfer and offboarding of all Contractor personnel, test accounts, and tools.
baselineDevelop a proposed comprehensive Deliverables Schedule incorporating all deliverables, presented for the organization's approval and reviewed at least monthly.
baselineProvide detailed information about proposed Key Personnel (Contract Engagement Manager plus additional engineers/consultants/IT leads) who will be written into the contract by name.
baselineProvide an in-depth discussion of technical approach to providing the described services, including a clear statement of whether performance will comply with all RFP requirements.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFPProvide a percentage break down of how much of the engagement will be performed on your site, the organization's site, or remotely.
RFIDoes the platform provide continuous/automated breach-and-attack simulation (BAS) versus point-in-time manual penetration testing, and can both be run from the same platform?Answer key — what a strong answer shows
Clarify whether this is a BAS platform, a pen-testing service, or genuinely both — many vendors market as one but deliver only the other.
RFPDescribe the attack technique library (MITRE ATT&CK coverage) — how many techniques/procedures are simulated, and how frequently is the library updated to reflect newly observed adversary TTPs?Answer key — what a strong answer shows
Look for a specific ATT&CK coverage count and update cadence, not a vague 'comprehensive coverage' claim.
RFIHow does the platform validate whether existing security controls (EDR, SIEM, firewall) actually detected or blocked each simulated attack, and is this validation automated or does it require manual log review?Answer key — what a strong answer shows
Strong answers describe automated control-validation feedback rather than requiring the customer to manually cross-reference logs.
RFIFor manual/human-led penetration testing, what are the tester qualifications (OSCP, OSCE, CREST, etc.), and can customers request specific testers or specializations (web app, cloud, red team)?Answer key — what a strong answer shows
Look for named certifications and the ability to request specialized testers, not a generic 'certified testers' claim.
RFPDetail reporting depth for a completed engagement — does it include exploitation proof, business-risk framing, and prioritized remediation guidance, and what is the typical turnaround time from test completion to final report?
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Answer key — what a strong answer shows
Strong answers state a specific turnaround time and describe business-risk framing beyond a raw vulnerability list.
RFIDoes the platform support purple-team exercises where simulation results are used collaboratively with the defense team in real time, versus a black-box report delivered after the fact?Answer key — what a strong answer shows
Real-time collaborative purple-teaming is a materially different, often more valuable, engagement model than after-the-fact reporting.
RFPExplain how remediation is verified — is there an automated re-test of the specific attack path after a fix is applied, and what is the typical cost/effort of a re-test compared to the original engagement?Answer key — what a strong answer shows
Look for an efficient re-test mechanism (ideally automated for BAS, or discounted for manual pen tests) rather than requiring a full new engagement.
RFIWhat is the safety/blast-radius model for automated BAS in production environments — are simulated attacks executed safely with no real payload/exploitation, or does the platform require a staging environment?Answer key — what a strong answer shows
Strong answers explain concretely how production safety is guaranteed rather than asserting 'safe for production' without detail.
RFPIdentify by name all Key Personnel and describe their technical knowledge, experience, qualifications, education, and depth of expertise relevant to the requested services; submit resumes (max 2 pages each).
RFPProvide a description of recent experience providing related penetration-testing-as-a-service, with examples of projects and personnel including position types and assignment lengths.
RFPProvide a list of 2-3 current or recently completed contracts similar in scope, including client name, project title, period of performance, contract number/value, and primary/backup points of contact.
RFPIdentify tasks that will be performed by your Firm and tasks that will be performed by the organization's staff.
RFPPrepare recommendations to address vulnerabilities for IT Management systems and suggest IT Security best practices.
RFPSocial Engineering: phishing simulation campaigns, pretexting and vishing scenarios, and physical engineering.
RFPVendors should provide a range of testing and validation services; vendors must not only describe their approach but also provide evidence of their capability in each area (Penetration Testing, Red Team, Purple Team, BAS).
RFPDefine potential penetration testing scenarios with the ISO.
RFPPerform manual-first penetration testing across external, internal, cloud, and application environments.
RFPPlan and prepare for the penetration test results to include scripts and presentation materials and review with the ISO.
RFPEvaluate reports, methodologies, credentials, and references for the penetration testing engagement.
RFPFacilitate a 3-4 hour penetration test results session with 20-30 department leaders and IT professionals from the organization.
RFPDocument, within 30 days, penetration test results to include documented scenarios, evaluation of the port authority's response to scenarios, and documented well-done items and opportunities for improvement.
RFPPerform Red Team exercises that emulate real-world threat actors.
RFPProvide a case study of a previous adversary emulation engagement, including objectives, outcomes, and mapped tactics using the MITRE ATT&CK framework.
RFPProvide metrics from Red Team engagements (e.g., time-to-detect, dwell time, response effectiveness).
RFPProvide Red Team qualifications (e.g., GPEN, CRTP) of team members.
RFPFacilitate Purple Team sessions where offensive tactics, techniques, and procedures (TTPs) are executed while defenders tune detections in real time.
RFIDoes the platform offer cloud-native attack-path simulation specific to AWS/Azure/GCP misconfigurations and privilege-escalation chains, distinct from traditional network/endpoint attack simulation?Answer key — what a strong answer shows
Cloud-specific attack-path simulation (e.g., simulating an IAM privilege-escalation chain) is a materially different and increasingly important capability from traditional on-prem BAS — ask for it explicitly rather than assuming general BAS coverage extends to cloud.
RFPDetail social-engineering and physical penetration testing scope — does the service include pretexting, tailgating/physical-access testing, or is the offering limited to purely technical/network attack simulation?Answer key — what a strong answer shows
Strong answers are explicit about whether social-engineering and physical testing are included, add-on, or entirely out of scope — this is a common gap between marketing claims and actual service scope.
RFIHow does the platform or service specifically support compliance-mandated annual penetration tests (PCI DSS, SOC 2) — does it produce an attestation-ready report format auditors will accept, and has it been accepted by auditors for real customers?Answer key — what a strong answer shows
Look for a concrete track record of auditor-accepted reports, not just a claim of 'compliance-ready' formatting — ask for a customer reference where the report was actually used to pass an audit.
RFPExplain the pricing model — per-engagement flat fee, subscription for continuous BAS, or hybrid — and provide a total cost comparison between a single annual manual pentest and a year of continuous automated simulation for a comparable environment.Answer key — what a strong answer shows
Strong answers give a real cost comparison; a vendor unable to frame their pricing against the traditional annual-pentest alternative is avoiding a legitimate buyer question about ROI.
RFIDoes the platform offer red-team-as-a-service with a continuous/retained engagement model (ongoing embedded adversary simulation) versus only discrete, scheduled engagements, and what does a typical retained-service SLA look like?Answer key — what a strong answer shows
A continuous retained red-team model provides materially different (and more expensive) value than periodic point-in-time engagements — the answer should make the distinction and pricing implications clear.
RFIHow deep is API and application-layer penetration testing specifically (business-logic flaws, broken authorization, not just OWASP Top 10 automated scanning) — are these manual, specialist-led tests or automated tooling relabeled as 'API pentesting'?Answer key — what a strong answer shows
Manual, business-logic-focused testing catches materially different vulnerabilities than automated scanning — press on whether 'API pentesting' means real manual testing or just an automated scanner with a pentest label.
RFPDetail ransomware-specific attack simulation — does the platform simulate real-world ransomware TTPs (lateral movement, backup-deletion attempts, exfiltration-before-encryption) end-to-end, and can it validate whether backup/recovery controls would actually survive a simulated attack?Answer key — what a strong answer shows
End-to-end ransomware simulation that tests backup/recovery resilience (not just initial-access detection) is a materially more complete validation than a generic 'ransomware module' that only tests endpoint detection.
RFIHow does the platform integrate with the customer's existing vulnerability management program so that simulation-validated attack paths and scanner-identified vulnerabilities feed into a single combined risk view, rather than two disconnected reports?Answer key — what a strong answer shows
A genuinely combined risk view (validated exploitability from BAS/pentest cross-referenced with VM scanner findings) is materially more actionable than two separate tools producing two separate, unreconciled reports.
RFPProvide a sample agenda or workshop outline for Purple Team exercises.
RFPProvide example Purple Team deliverables such as after-action reports, detection tuning documentation, or playbook updates.
RFPProvide client feedback or testimonials highlighting measurable improvements in detection or response from Purple Team engagements.
RFPProvide mapping of Purple Team tactics to MITRE ATT&CK for transparency.
RFPProvide a breach and attack simulation (BAS) platform or managed service to continuously validate controls.
RFPProvide screenshots or sample reports from the BAS platform.
RFPProvide proof of BAS integration with Security Information and Event Management (SIEM) systems and Security Orchestration, Automation, and Response (SOAR) platforms.
RFPProvide documentation showing how repeatable BAS testing is scheduled and validated.
RFPProvide metrics demonstrating BAS detection coverage and improvements over time.
RFPTest internet-facing assets (perimeter, VPN, remote access, web portals) for exploitable weaknesses (External Network Testing).
RFPAssess internal systems and segmentation for lateral movement opportunities and common misconfigurations (Internal Network Testing).
RFPAttempt to escalate privileges and move across systems to simulate real attacker behavior (Privilege Escalation & Lateral Movement).
RFPConduct simulated phishing and approved pretexting scenarios to assess user awareness and process controls (Social Engineering, optional/scoped).
RFPRecord validated findings with proof-of-concept details and reproduction steps (Evidence & Exploitation Documentation).
RFPProvide fix validation support and a retest option for high/critical findings (Remediation Guidance & Retest, optional/scoped).
RFPComplete pricing information (Attachment 1 - Bid Sheet), proposing alternative pricing for the PTaaS approach, fully loaded including wages, overhead, G&A, taxes, and profit.
RFPDeliver a Penetration Test Report (PDF/Word) covering scope, methods, validated findings, exploited vectors, and recommended remediations, including an estimate of hours to remediate the findings.
RFPProvide details of the cybersecurity professionals who will be involved in the engagement, including qualifications, certifications (e.g., CISSP, CEH, OSCP), and experience (Team Qualifications).
RFPProvide periodic penetration testing of the housing finance agency's public-facing web applications with a report and debriefing upon completion.
RFPProvide a clear outline of the approach and methodology for both the Cybersecurity Risk Assessment and Penetration Test, including tools, techniques, and standards followed (e.g., NIST, OWASP).
RFPProvide periodic penetration testing of the housing finance agency's Wi-Fi with a report and debriefing upon completion.
RFPProvide a Penetration-Testing-as-a-Service (PTaaS) offering that allows the organization to dynamically request testing, coordinate execution, and receive results through a centralized platform, minimizing manual processes and focusing on automation, efficiency, and the most relevant threats.
RFPProvide Internal and External Network Vulnerability Assessment & Penetration Testing, and Web Application Penetration Testing.
RFPDescribe capabilities for performing the services, including personnel resources and management capabilities, and how subcontractors or partners are used and how rates are determined when using subcontractors.
RFPIndicate the location of the office(s) from which the work on this engagement is to be performed.
RFPPerform authorized external network penetration testing of the public-facing perimeter of all the municipality's locations, including all externally reachable municipality-owned IP addresses, internet-facing services, web applications, remote access portals, VPN endpoints, and externally hosted services, including reconnaissance, service/version enumeration, vulnerability identification, authenticated and unauthenticated exploitation attempts, password attacks against exposed authentication interfaces, and manual validation of all findings (automated scanning alone is not permissible).
RFPPerform authorized internal network penetration testing of two isolated internal environments (the main municipal facility and the Police Department), simulating a threat actor with internal network access, including network discovery, vulnerability identification, lateral movement, privilege escalation, credential harvesting, Active Directory enumeration and attack path analysis, with manual validation of all findings.
RFPDeploy a separate, hardened, encrypted-at-rest testing appliance to each isolated internal environment for parallel testing; appliances shall be uniquely identified and removed or sanitized at the conclusion of the engagement.
RFPPerform authorized social engineering testing of municipal personnel, including email phishing campaigns against an agreed-upon population, sophisticated enough to simulate an adversary-in-the-middle (AiTM) attack.
RFPCoordinate testing windows with municipal IT staff and, for Police Department systems, with the Chief of Police or designee; provide weekly updates during active testing and immediately notify the municipality of any critical finding presenting an active risk to operations or public safety.
RFPObtain municipal approval before proceeding with validation of any finding that could disrupt municipal operations.
RFPDeliver a written final report including an executive summary for a non-technical audience, detailed technical findings with risk ratings/evidence/remediation recommendations, an attack narrative, a social engineering results summary (click rates and credential capture rates by group), and a prioritized remediation roadmap, with all findings scored using CVSS or an equivalent standard.
RFPMaintain and deliver an engagement log documenting date/time of each attack performed (with emphasis on successful attacks) to allow the municipality to correlate testing activity against its security monitoring and alerting systems.
RFPBe available to present findings to municipal staff and, if requested, to the governing board in executive session.
RFPStore all engagement data in encrypted form, not transmit municipal data to any third party, not use municipal data for marketing/case studies/AI-ML training, and securely destroy all engagement data no later than 30 days after final report acceptance except where retention is required by law.
RFPBe willing and ready to sign a non-disclosure agreement.
RFPConfer with municipal IT staff and the Police Department on penetration testing matters as requested during the contract term.
RFPAcknowledge that the anticipated services described can be provided and indicate any relevant additional services the firm would offer.
RFPDemonstrate a minimum of five (5) years of experience providing network penetration testing services, with documented experience serving municipal, public sector, or law enforcement clients.
RFPDemonstrate experience performing external, internal, and social engineering penetration testing engagements of comparable scope.
RFPDemonstrate familiarity with industry-recognized testing methodologies (e.g., PTES).
RFPIdentify staffing qualifications, including the proposed engagement lead.
RFPProvide a methodology overview and sample (redacted) deliverables demonstrating minimum requirements.
RFPProvide a sample (redacted) penetration testing report demonstrating the firm's reporting format and quality.
RFPConfirm the firm has the legal authority and technical capability to perform network penetration testing services and shall comply with applicable laws, including the Computer Fraud and Abuse Act, applicable state computer crime statutes, and the FBI CJIS Security Policy where applicable.
RFPConduct white-box testing for both a Cybersecurity Risk Assessment and a Penetration Test across eight of the housing authority's locations and fourteen departments, covering 10+ cloud applications, 2 web applications, AD, endpoints, and on-premises equipment for 500+ devices, targeting 350+ users, including phishing, vishing, smishing, and physical pretexting.
RFPPropose an approach for testing mission systems and applications in pre-production/production-like test environments for vulnerabilities, design anti-patterns, resistance to DoS/DDoS, and common coding and configuration errors, with options for tailoring scope, retesting remediated findings, and focused ad hoc tests.
RFPPerform Ethical Hacking testing including internal network scanning, port scanning, system fingerprinting, services probing, exploit research, manual vulnerability/configuration testing and verification, application layer testing, firewall/ACL testing, privilege escalation, password strength testing, network equipment and database security controls testing, and internal network scanning for known trojans.
RFPPerform Web Application testing including injection, broken authentication/session management, XSS, insecure direct object references, security misconfiguration, sensitive data exposure, missing function-level access control, CSRF, use of components with known vulnerabilities, unvalidated redirects/forwards, API/web services testing, session hijacking (MITM/sniffing/sidejacking), and malicious file upload.
RFPPerform application code testing for user session management including input validation of login fields, cookie security, lockouts, and user session integrity.
RFPTest across all major user types for each system (anonymous, external, internal non-privileged, internal privileged users) as recommended by the organization based on access levels.
RFPOffer optional Social Engineering Testing (phishing, vishing, smishing, and AI emulation/simulation) supporting three corporate-level campaigns annually, and publish an annual Social Engineering Assessment Report with recommendations, outcomes, and key risks.
RFPOffer optional Physical Environment Testing including Wi-Fi penetration testing of corporate and guest networks, and physical access testing (tailgating, guest verification/monitoring, access to controlled rooms) at the organization's headquarters.
RFPHold a Contract Kick-Off Meeting no later than 10 workdays after contract award to introduce teams and coordinate technical planning.
RFPDevelop and submit an Onboarding Plan for all Contractor personnel, test accounts, tools, and coordination of support by the organization's teams within 10 business days of contract award.
RFPDevelop and submit a draft and final Core System Penetration Test Plan for each of up to 20 systems, with Contractor responsible for coordinating access and readiness to commence testing on schedule.
RFPPublish a draft and final Core System Penetration Test Report for each system tested, summarizing all findings rated by severity, with sources, reproduction instructions, and coverage of each significant finding, within 10 business days after test conclusion.
RFPEmail the organization's product manager within 1 business day of discovering a Critical or High severity finding, with draft details and reproduction instructions (Significant Alert of Finding).
RFPCoordinate with the organization to document opportunities, threats, techniques, approaches, and audiences for three annual social engineering tests (Social Engineering Annual Strategy) within 45 calendar days of contract award and annually thereafter.
RFPProvide monthly Ad Hoc Penetration Test reports covering all ad hoc tests accomplished, planned, in-progress, or canceled, for remediation verification or targeted vulnerability/fraud-risk testing requested by the organization.
RFPProvide a weekly status report by email consolidating activities performed and planned, and a formal monthly status report of major activities/accomplishments for the organization's leadership.
RFPDevelop a 60-day Transition Out Plan before end of the period of performance, including knowledge transfer and offboarding of all Contractor personnel, test accounts, and tools.
RFPDevelop a proposed comprehensive Deliverables Schedule incorporating all deliverables, presented for the organization's approval and reviewed at least monthly.
RFPProvide detailed information about proposed Key Personnel (Contract Engagement Manager plus additional engineers/consultants/IT leads) who will be written into the contract by name.
RFPProvide an in-depth discussion of technical approach to providing the described services, including a clear statement of whether performance will comply with all RFP requirements.
RFPProvide an in-depth overview of the proposed use of Artificial Intelligence in the technical approach, describing how and in what circumstances AI will be used to perform the services, with separate pricing for scenarios with and without AI use.
RFPThe Bidder should perform periodic Information Security assessments, IT Security audits, Vulnerability Assessment and Penetration Testing (VAPT), and other applicable security assessments for the application and underlying hosting infrastructure, and remediate all identified audit observations and security gaps within timelines specified in the financial institution's IT Audit Policy.
RFPFulfill all requirements as defined by PCI DSS v4.0 for external penetration tests which are to be conducted annually (per PCI DSS sections 11.3 and 11.4).
RFPTesting must be based on industry-accepted penetration testing approaches (for example, NIST SP800-115).
RFPTesting must include coverage for the entire Card Holder Data Environment (CDE) perimeter and critical systems, and testing from both inside and outside the network.
RFPTesting must include validation of segmentation and scope-reduction controls, confirming they are operational and effective and isolate all out-of-scope systems from systems in the CDE, performed at least annually and after any changes to segmentation controls/methods.
RFPApplication-layer penetration tests must include, at a minimum, the vulnerabilities listed in Requirement 6.4 of the PCI DSS standard.
RFPNetwork-layer penetration tests must include components that support network functions as well as operating systems.
RFPTesting must include review and consideration of threats and vulnerabilities experienced in the last 12 months, and specify retention of penetration testing results and remediation activities results.
RFPReporting should include specific recommendations on how to eliminate or remediate any vulnerability or issue discovered, and each finding should provide enough detail on exactly how it was discovered so that internal red teams can repeat the test to ensure the vulnerability has been remediated.
RFPInclude with your quotation two (2) references from similar services.
RFPProvide client references specific to the services required (evaluation criteria).
RFPFor a physical device used as a hardware/scanning node: it must only communicate via secure channels to pen testers, the testing organization must guarantee data will be destroyed before it is shipped back, it must have a physical Ethernet port, and it must be configurable for a static IP either in advance or remotely.
RFPPlease describe areas or processes, not included in the scope of this engagement, that your firm may examine in order to provide more complete and thorough services.
RFPExternal Network Penetration Testing: Assess the perimeter defenses of the hosts and services exposed to the Internet. Conduct a Firewall Assessment.
RFPInternal Network Penetration Testing: Assess the security of internal private networks and hosts to determine what a malicious individual could potentially compromise within the various networks of the organization.
RFPOrganization Websites Penetration Testing: Assess vulnerabilities within the website or web applications software.
RFPWireless Security Scanning: Assess the adequacy of wireless network infrastructure security from unauthorized access to the organization's wireless network.
RFPSocial Engineering: Assess vulnerabilities to various types of Phishing attacks. Determine adequacy of physical access security and protocols.
RFPReporting Requirements: Based on penetration testing and scanning results, provide a comprehensive technical, detailed, Executive Summary and Report of vulnerabilities, by level of risk, with recommended correlated remediation, and best practices for software solutions to remediate the vulnerabilities identified.
RFPSpecial Requests: Ad-hoc penetration requests may be necessary in conjunction with specific infrastructure projects being completed at future dates. Describe your ability to respond to ad hoc requests.
RFPAddress the various tasks, services, and deliverables outlined in the Scope of Work and describe the specific approach that will be taken in performing each task or service or providing each deliverable.
RFPDescribe how Respondent has the necessary staffing and bandwidth to take on this engagement.
RFPDescribe any deliverables or services, not included in the Scope of Work, that your Firm would suggest be provided in order to provide more complete and thorough services.
RFPWhat combination of Pen testing, scanning, and vulnerability assessment tools will be used for this project? Identify possible impact of Pen testing on the organization's system Infrastructure.
RFPProvide a timetable for each Penetration testing task including estimated hours and completion dates.
RFPProvide billing by type of Penetration test along with hourly rates.
RFPState any special considerations with respect to billing or payment of fees and expenses that Respondent offers and that you believe would differentiate your Firm from other proposals and make your Firm's services more cost effective to the Fund.
RFPThe organization expects the lowest rate charged by Respondent for its governmental and non-profit clients. If for any reason Respondent is unwilling or unable to charge the lowest rate, please explain why.
RFPConfirm that the billing rate will be fixed for the term of this engagement.
RFPBriefly describe Respondent's background, history, and ownership structure, including any parent, affiliated or subsidiary company, and any business partners.
RFPProvide the size of the Firm including number of offices and number of full-time employees. Identify the key personnel proposed for the engagement, emphasizing specific experience on contracts similar in scope. Describe position, current responsibilities, areas of expertise, experience, education, professional designations, and memberships.
RFPProvide the number of years that the Firm and any identified individuals have been providing the services requested in this RFP.
RFPProvide details on your Firm's employee benefit industry experience/expertise and financial institution experience/expertise.
RFPIndicate the number and nature of part-time professional staff to be employed in this engagement.
RFPWill your Firm use outside contractors (subcontractors) for this engagement? If so, what confidentiality agreement is in place to protect sensitive information from disclosure? What allocation of the scope of services will be assigned to outside contractors (subcontractors)?
RFPIndicate Respondent's due diligence process in hiring, evaluating, and monitoring its staff and contractors, as applicable.
RFPList any known professional or personal relationships Respondent or its employees or contractors may have with individual Board members and/or staff of the organization.
RFPIdentify any potential or actual conflicts of interest you have in providing services to the organization. State whether you have ever provided services to the organization, its affiliated municipal government, its affiliated board of education, its affiliated employee union, or related public-sector entities.
RFPIdentify all public sector, ERISA fund, or financial institution clients who have terminated their working relationship with you in the past five (5) years and provide a brief statement of the reason(s) for the termination, with client contact information.
RFPIt is expected that the selected firm will have adequate quality control procedures in place to guarantee the accuracy of the work performed. Please describe your quality assurance procedures.
RFPProvide a sample contract/engagement letter for the services proposed by your Firm.
RFPPlease provide three references who are clients for whom you have performed work similar to that requested in this RFP. Include the reference name, title, entity, address, telephone number, email address, and description of the services provided.
RFPPlease provide any information relative to your Firm's minority Firm affiliations or minority Firm participation in the engagement, and a MWDBE breakdown for your Firm, including any MWDBE subcontractors/subvendors intended for use on this contract (name, role, expected payments/percentage utilization).
RFPDisclose, separately: any entity that is a parent of, or owns a controlling interest in, the Respondent; any entity that is a subsidiary of the Respondent; any persons/entities with an ownership or distributive income share in the Respondent in excess of 7.5%; and any persons who serve as executive officers of the Respondent, including their titles.
RFPDisclose any direct or indirect payments in excess of $1,000/calendar year within the prior five years made to any community or not-for-profit organization relating to public education by the Respondent, its executive officers, parent entity, or major shareholders, and any formal involvement with such organizations.
RFPDisclose any direct or indirect financial support in excess of $1,000/calendar year within the prior five years, or formal involvement, by the Respondent or its principals with organizations whose central purpose is influencing budgetary/fiscal, education, or retirement security policy (a named list of such organizations is provided in the RFP).
RFPDisclose any direct or indirect financial relationships, transactions, or consulting agreements with any affiliated public education governing body entered into within the prior five (5) calendar years.
RFPDisclose the names and addresses of any subcontractors and the expected amount and/or percentage of money each will receive under the agreement.
RFPDisclose the total number of Respondent's staff and the percentage who are a minority person, a female, or a person with a disability, using the EEOC chart available on the organization's website.
RFPDisclose the number of current consulting/professional/artistic-services contracts Respondent has with minority-owned, female-owned, or disability-owned businesses, or businesses where more than 50% of contracted services are performed by such persons.
RFPTest external infrastructure for known vulnerabilities and misconfigurations, exploiting identified vulnerabilities where feasible to demonstrate security risks.
RFPReview DNS configurations for exposure of sensitive information.
RFPTest API endpoints (if applicable) for vulnerabilities such as broken authentication, excessive data exposure, and insufficient rate limiting.
RFPConduct a comprehensive security assessment without causing Denial of Service (DoS) unless explicitly requested.
RFPScan and assess internal network devices (firewalls, routers, servers, web applications, and endpoints) for vulnerabilities, and conduct network penetration testing to identify attack pathways.
RFPTest for weak authentication, misconfigurations, and known vulnerabilities across common protocols (SMTP, FTP, SSH, RDP, SMB, NetBIOS, RPC, etc.).
RFPEvaluate risks associated with default credentials, weak passwords, and credential stuffing attacks; assess the feasibility of privilege escalation and lateral movement within the network.
RFPRemediation Support: The Vendor must provide consultation and guidance on remediation efforts as needed.
RFPRetest: The vendor will retest findings upon notification from the institution of correction, for up to four weeks post-test, to validate remediation efforts.
RFPDemonstrate experience in penetration testing for higher education or government institutions.
RFPHold certifications such as OSCP, OSCE, CISSP, or equivalent.
RFPMust carry cybersecurity insurance and liability coverage to mitigate risks associated with testing (proof required with submission).
RFPProvide examples of past penetration testing reports (redacted as necessary) to assess the quality and clarity of reporting.
RFPMust provide details of quality assurance processes and project management approach.
RFPAll personnel conducting penetration testing must be U.S. citizens and capable of meeting export control and Controlled Unclassified Information (CUI) regulations. FedRAMP certification is not required for this engagement.
RFPThe vendor must provide detailed pricing for all services outlined in the SOW, as well as pricing for any additional testing services they offer that individual institutions may choose to purchase (including pricing for a webapp test).
RFPProvide the qualifications, skills, and expertise of the vendor team that will work on the process.
RFPConduct external and internal vulnerability testing and threat assessment.
RFPPerform testing including but not limited to Blackbox, Whitebox and Graybox testing to detect conditions that indicate any security vulnerability in an application in its running state (interfaces, requests, responses, scripting, data injection, buffer overflows, sessions, authentication, etc.).
RFPConduct penetration tests to identify exploitable flaws and measure the severity of each application and database identified in this RFP, including exploiting vulnerabilities to determine whether unauthorized access or other malicious activity is possible.
RFPProvide application penetration testing services including authentication process testing, automated fuzzing, development of test datasets and harnesses, encryption usage testing, manual/automatic code review for sensitive information, input validation and transaction testing, and user session/cookie/lockout testing.
RFPPerform application penetration test services on mobile applications as requested.
RFPIdentify vulnerabilities in and exploit client-side software, such as web browsers, media players, document editing programs, etc.
RFPFinalize the penetration testing requirements (scope) for the design of test cases; prepare a testing strategy; develop a detailed project schedule and work plan.
RFPSubmit the report for penetration testing with details of vulnerabilities found, and obtain final sign-off on the test report by respective IT Management.
RFPProvide an executive summary of no more than five pages, providing an overview of bidder's organizational structure, history, services, market position, unique qualifications, strategic alliances, etc.
RFPProvide at least three (3) references for clients for whom the bidder has performed services similar to those being requested in this RFP.
RFPProvide the most recent year's annual reports, or comparable document, including detailed current profit and loss, assets and liabilities, and other relevant financial data; submit Attachment B: Vendor History Questionnaire.
RFPConfirm that bidder has all necessary business licenses, professional certifications or other credentials to perform the services, and that bidder, if a corporation, is in good standing and qualified to conduct business in the applicable jurisdiction.
RFPPreferred: possess certifications such as CISSP, CISM, ISACA, SANS/GIAC, CCIE Security, CCSM, CISSP-ISSEP, CISSP-ISSAP, F5-CTS ASM, GIAC Certified Penetration Tester, MCSE Data Platform, and experience creating security vulnerability exploits using JavaScript/SQL, authoring web application assessment methodologies, and developing information security policies/roadmaps.
RFPThe vendor will create, manage, and communicate a project plan that includes tasks, milestones, deliverables, and associated dates.
RFPThe vendor will work with the client to identify information critical to execute the project.
RFPThe vendor will assess in-scope systems based on the test methodology; an Initial Pentest Report will be issued within 5 business days after the initial round of internal and external testing is complete, with Critical and High-level vulnerabilities communicated in the initial reports.
RFPThe vendor will re-assess in-scope systems that have had a Critical or High-level vulnerability remediated by the client since completion of initial testing. Retesting will begin within 30 days of client's notification that mitigation is complete, with final reports issued within 10 business days of retest completion.
RFPIdentify the anticipated key personnel to be assigned to manage and complete the project along with relevant biographical information/background, applicable experience in handling matters of a similar nature, and capabilities/competencies to successfully complete this project.
RFPDescribe strategy for initial meeting with the client's project team for purposes of setting project expectations and overall goals of the engagement.
RFPDescribe the proposed test methodology for internal and external testing.
RFPDescribe experience and strengths in security assessments and penetration testing.
RFPDescribe any parameters and/or limitation considerations in the analysis or production of considerations in this report.
RFPProvide at least three (3) client references including business name, address, phone number and person to contact regarding similar work performed.
RFPDescribe methods for interacting and communicating with clients in order to keep client informed of the current status of the project.
RFPProvide a schedule of performance including milestone dates of deliverables, a detailed cost estimate of the fees to perform the project, and a proposed outline of Pentest Reports.
RFPConduct comprehensive penetration testing services for our technology infrastructure and main office facility, identifying security vulnerabilities, assessing current security posture, and providing actionable recommendations to strengthen defenses.
RFPConduct adversary simulation exercises (Red Team Assessment) against the organization to assess the ability to detect, respond to, and defend against sophisticated, multi-vector attacks that simulate real-world threat actor TTPs, conducted covertly with limited organizational knowledge.
RFPExternal Network Testing scope: Internet-facing infrastructure, web applications and APIs, email and DNS infrastructure, remote access solutions (VPN, RDP, etc.), and wireless infrastructure.
RFPInternal Network Testing scope: internal network segmentation and access controls, Active Directory and authentication systems, internal applications and databases, and lateral movement/privilege escalation scenarios.
RFPApplication Security Testing (Pension Platform): web application penetration testing (OWASP Top 10), API security assessment, and authentication/authorization mechanisms.
RFPPhysical Security: entry & perimeter testing, internal access assessment, device and network access, and security operations/response evaluation (guard response time, visitor management effectiveness, surveillance coverage).
RFPPropose realistic Red Team attack scenarios aligned with actual threat actors, with Primary (Crown Jewel) Objectives such as access to employer/member/financial/PII databases, compromise of the pension platform, domain admin or enterprise-wide credential access, and cloud environment (MS O365) access.
RFPSecondary Red Team objectives: establish persistent access and maintain stealth, lateral movement across network segments/geographic boundaries, privilege escalation to critical administrative roles, exfiltration of sensitive data without detection, and bypassing of security controls (EDR, SIEM, DLP, MFA).
RFPDescribe testing methodology, including frameworks/standards followed (e.g., PTES, OWASP, NIST), testing approach (black box, gray box, white box), tools and techniques employed, vulnerability verification/exploitation procedures, and communication protocols during testing.
RFPDemonstrate advanced operational security capabilities, including custom tooling and proprietary techniques (not exclusively relying on public frameworks), OPSEC practices to avoid premature detection, threat actor emulation based on MITRE ATT&CK, anti-forensics/artifact minimization techniques, and ability to operate covertly for extended engagements.
RFPMeet minimum/preferred qualifications: minimum 5 years conducting penetration testing and red team operations; team certifications (OSCP, GPEN, CEH, GWAPT, or advanced OSEE/OSCE/GXPN); demonstrable APT simulation/adversary emulation experience; custom tool development capability (not solely Cobalt Strike/Metasploit); published security research or CVE discoveries.
RFPProvide a brief history of the Firm including the year organized and ownership structure, and indicate any anticipated changes (near term or long term) in Firm ownership or structure.
RFPProvide an overview of the Firm's organization, including the number of people in key positions and services offered, and the number of years the Firm has provided the services outlined in the Scope of Services section.
RFPProvide a brief description of any unique qualifications of the Firm, including consulting specialties, strengths, and limitations, with examples of 'value-added' advice and problem-solving capability for clients.
RFPProvide a list of public pension plans the Firm has worked with over the past five (5) years and the nature of each contract.
RFPList the Firm's office locations and the main functional roles of each, indicating the primary location of the team that would cover the organization's services.
RFPProvide an organization chart that depicts the structure of the consulting group and identifies the key personnel and other people who will be involved in providing services to the organization.
RFPProvide a comprehensive narrative statement illustrating an understanding of the requirements of the engagement, including a description of deliverables, a detailed work plan identifying major tasks, a proposed project timeline, and procedures to ensure the organization receives satisfactory products/services.
RFPWith reference to items listed under Scope of Services, describe the services your Firm proposes to provide to the organization, including a list of key personnel assigned to the project, their roles, and resumes detailing training, work experience with public pension plans, and certifications/designations.
RFPProvide a list of at least three organizations that may be used as references for the Firm's work related to the requirements in this RFP, with dates of service, contact info, and description of work performed.
RFPProvide the name, address, phone number, contact name and title of any pension plan clients that have terminated the Firm's services over the past three years, with an explanation of the circumstances involving the termination.
RFPDescribe how fees are determined for your Firm's services, including the proposed fee for services, treatment of out-of-pocket disbursements, alternative fee structures, and any special billing considerations that would differentiate the Firm.
RFPFor SaaS solutions, describe how you price the service — by size of application, contract period, or pricing tiers for lightweight fully automated tests versus more complex testing requiring manual intervention. Do you provide penetration testing (which includes testing outside of the application under test)?
RFPDo you perform penetration testing? Has an external firm performed penetration testing?
RFIDoes the vendor conduct any recurring vulnerability or penetration testing?
RFIVendor shall conduct vulnerability assessments against all Vendor internet-facing information systems on a regular basis, and shall perform penetration tests on all Vendor web applications and services used to provide services to the agency, in accordance with standard methodologies, no less often than annually.