Security Testing Services
Security testing services: Testing follows a standardized security model and adheres to recognized frameworks and standards such as CC, OWASP (including ASVS and LLM), WASC, NIST, and, where applicable, ISO IEC 27001, ISO IEC 27002, and EAL specifications. The scope includes defining the security requirement level, reviewing security architecture and centralized controls at process and IT system levels. Clear and prioritized change proposals are prepared to rectify identified security deficiencies. Testing targets IT systems, interfaces, integrations, cloud environments (IaaS, PaaS, SaaS), identity and access management (IAM) solutions, mobile applications, and, if necessary, IT system complexes related to medical devices. Content may include: commissioning inspections, security assessments, quantum readiness assessments, recurring vulnerability scans and vulnerability management, penetration testing (including web, mobile, infrastructure, and API tests, and red team exercises if needed), simulation of denial-of-service attacks to an agreed extent, review of configurations and security settings (baseline compliance), assessment of software component and dependency security (supply chain), and tasks for planning, execution, management, and maintenance of tests. For AI and LLM solutions, testing specifically covers: risks related to input and prompt manipulation (prompt injection), data leakage risks and information disclosure through models, risks of model misuse and circumvention, security of access rights, interfaces, and integrations, and connections of AI systems to other IT systems. Execution is conducted according to agreed procedures, including test scope, scheduling, approved testing methods, special arrangements for tests in production environments, incident management, and secure data handling. Documentation must include at least a test plan, interim reports, test results with descriptions, and a final report with conclusions. Reporting must include clear risk classification (critical, high, medium, low), impact assessment, and concrete corrective recommendations, as well as a summary and a technical detailed description of findings and testing methods. The service may also include the development and implementation of continuous security testing models and the integration of testing into the software development lifecycle (DevSecOps). The provider must adhere to the client's security and data protection requirements and consider the specific characteristics of the social and healthcare operating environment, including requirements related to patient data processing.
Never miss a tender again
We send you 3 current matches that fit your company.
Tender documents
- Portal — LOT-0000NON-RESTRICTED-DOCUMENT
- TED HTML — 476317-2026HTML
- TED PDF — 476317-2026PDF
- TED XML — 476317-2026XML
Unlock documents for free
Enter your email address. If you confirm, we will also send you 3 similar tenders.