All penetration tests / DigiD Assessment

DigiD Assessment

Make the security of your DigiD environment demonstrable.

We examine the technical security of the agreed DigiD web environment. Substantiated findings and remediation advice help you prepare for and support the assessment.

Technical testing for your assessment

Three questions we answer

  • Which elements are included in the technical testing?
  • Which vulnerabilities need remediation?
  • What evidence does the auditor involved need?

When is this relevant?

Coordinate technical testing and the audit in good time.

A DigiD environment often consists of multiple components and suppliers. Agreeing in advance on what needs testing helps align the results and remediation work with the assessment process.

  • You are preparing for a DigiD security assessment.
  • The web environment, hosting or administration configuration is changing.
  • The auditor involved requires technical evidence.
  • You want previously identified vulnerabilities retested.

The assessment

What do we assess?

Your environment and assessment question determine the content. We agree in advance which elements we will examine.

01

Assessment boundaries and dependencies

With the parties involved, we determine which application components and infrastructure require technical testing. We document which suppliers and administrators are needed during testing.

02

Web application and access

We examine the agreed web functions, sessions and access controls. We test whether data and actions are accessible beyond the intended user permissions.

03

Technical environment

Within the defined scope, we assess and test accessible services, configuration and relevant administration interfaces. Potential vulnerabilities are verified through targeted testing.

04

Evidence and remediation

We report the findings with technical evidence and advice. With the parties involved, we agree on which remediation measures and any retests are needed for the next stage.

Defining the scope together

A scope that fits your question.

We agree the technical scope and reporting requirements in advance with you, the suppliers and the RE auditor involved. The proposal describes the work SECWATCH will carry out.

What do we agree in advance?

  • Applications, URLs, infrastructure and relevant suppliers.
  • The assessment requirements and schedule.
  • Test accounts, test data and testing arrangements.
  • Reporting, remediation period and any retest.

The formal DigiD assessment and assessment report are the responsibility of an RE auditor. Our technical testing provides supporting evidence; we agree in advance how the work fits together.

The result

Insight you can act on.

01

Technically substantiated findings

A description of the assessment, the vulnerabilities found and the supporting evidence.

02

Targeted remediation work

Practical advice that developers, administrators and suppliers can use to implement improvements.

03

Coordination for the next stage

Clarity about the scope examined, remaining points for attention and any retests.

Our approach

From the initial question to follow-up.

01

Coordinating with those involved

We define the scope, technical assessment questions and reporting requirements.

02

Technical testing

We carry out the agreed checks and discuss serious findings immediately.

03

Reporting and remediation

You receive the evidence and coordinate remediation with the parties involved.

04

Supporting the next stage

An agreed retest can verify remediation and provide additional information for the process.

Frequently asked questions

What you need to know in advance.

Is this penetration test the complete DigiD assessment?

The formal assessment report is prepared by an RE auditor. We coordinate the technical testing and evidence needed and document our work in the proposal.

Can you work with our auditor and supplier?

We agree the technical scope, required access and reporting requirements with the parties involved. This allows everyone to plan their part of the process.

When should we schedule the technical testing?

Allow time for testing, remediation and, if necessary, a retest. We coordinate the specific schedule with the assessment process and your suppliers' availability.

Does a completed penetration test guarantee a positive assessment?

The formal assessment judgement rests with the RE auditor and covers the full set of applicable requirements. Our report describes the technical testing carried out and the findings within that scope.

Discuss your situation

Bring your technical testing and assessment together.

Tell us where you are in the process. Together, we determine what technical evidence is needed.