VeriSign Security Review
In December of 2007, VeriSign Inc., a leading provider of consulting service
and managed security solution was engaged by Centricom to perform an assessment of POLi 2, the
new payments application platform developed by Centricom
Technical testing was conducted from a common point on the Internet using access privileges normally
granted to parties with access to the Centricom environment. Testing was conducted by qualified, experienced
VeriSign staff and included the use of industry standard software tools as well as manual techniques.
VeriSign's application testing was designed to test Centricom ’s systems for known security vulnerabilities,
and to determine the extent to which those systems are vulnerable to an attack. In addition to the technical
testing, VeriSign performed an architecture assessment and reviewed key practices surrounding software
development and subsequent use of POLi application.
Having reviewed the application code and conducting a series of penetration tests, VeriSign found that Centricom
have identified and addressed the common threats to web based applications through adopting secure coding practices
and deployment of a hardened application delivery infrastructure that is well secured against typical security
breaches. At the time of the audit, vulnerabilities that can lead to a systems compromise were not detected.
For more information on POLi contact us.