Application Code Review
Halock's Secure Application Architects, Developers and Analysts secure
your .NET and J2EE applications, leveraging best-in-class security
practices and expert application development practices integrated with
the Microsoft .NET application framework and the J2EE framework. Our
approach, combined with the framework(s) , expands upon
security to include multiple layers of security for the Web application.
Security begins at inception and remains to be an integrated component
of each phase through transition. By using the latest techniques and
tools, Halock builds secure and compliant portals, data warehouses,
e-commerce sites, intranet sites and extranet sites. Halock can also
provide turn-key applications, security testing on pre-production
applications or provide you with specialized security experts to embed
into your team for optimal security.
Software applications (custom or purchased) provide access to the core
assets and processes within the organization. Halock will review your
organization's SDLC at each stage of the life cycle to ensure that
unnecessary risks are not introduced into the business and that best
practices are being followed. Phases of the SDLC specifically focusing
on requirements, analysis and design, development, quality assurance,
testing, deployment, operations, and Management are reviewed.
Working collaboratively with your organization development staff, Halock
will review custom application code and associated development processes
to ensure risks are being appropriate mitigated.
On-Demand Vulnerability Scanning:
Allows for unlimited scanning of Internet IP addresses to enable
ongoing compliance with PCI quarterly vulnerability scanning
requirement. Online filing allows for automatic notification to
acquiring bank once compliance is achieved.

PCI Compliance Management Portal:
An online portal designed to facilitate PCI compliance efforts and to
assist in managing all work efforts related to acheiving PCI compliance.
Portal includes PCI related news articles with expert analysis, a
comprehensive PCI knowledgebase, downloadable tools and templates, and
more.
