Carrying Out a DigiD Pentest: Tozetta Ethical Hacking's Approach
A DigiD pentest is a mandatory part of the NOREA DigiD Assessment guidelines. Read more here about DigiD pentest requirements.
Cyber security is essential and increasingly features in various standards and guidelines. This also applies to organizations that have implemented DigiD connections within their solutions. During a DigiD assessment, a penetration test is a mandatory component, also known as a "DigiD pentest". In this blog, we discuss the value of a pentest and what to pay attention to when carrying out a pentest as part of a DigiD Assessment.
Tozetta is a leading player in the field of ethical hacking and pentesting. With our expertise, advanced tools, and extensive experience in DigiD pentests, we help organizations fulfill this component. Pentesting remains a small part of a full DigiD assessment; we take into account the pentest requirements from the NOREA Guide for a DigiD Assessment.
The value of a pentest
Whether it's ISO 27001, NEN 7510, or a DigiD Assessment, pentesting often comes back in the guidelines of various cyber security-related standards. The reason is that it tests software and systems dynamically and independently for vulnerabilities. What else does carrying out a pentest add value with?
- By proactively exposing vulnerabilities, you reduce the risk of potential damage
- Insight into vulnerabilities: undiscovered security gaps in web applications and networks are exposed
- Independent and offensive perspective: an external party tests security measures the way an actual attacker would
Whether it's mandatory or not, a penetration test is always worth considering for various cyber security questions. That's exactly why it comes back so often in various cyber security-related standards and guidelines.
DigiD Pentest requirements
A DigiD penetration test must be carried out at least annually, and after significant changes such as a new version of the application or a migration of systems. The test environment used by the ethical hackers must be representative of the production environment, and both evidence of findings and compliance with standards must be properly documented. This last part is something Tozetta fully takes off your hands during a DigiD pentest.
Want more information about this approach? Check out our DigiD Pentest page >>
Scope of a DigiD penetration test
The test focuses on three main areas: the web application, the web server and infrastructure, and the network segment in which DigiD runs. Within the web application, input and output validation, data reliability, and privacy protection are tested. For the web server and infrastructure, hardening guidelines and configuration management are examined. The network segment is examined for vulnerabilities and security flaws.
Reporting requirements
The reporting requirements for a pentest are precisely described in the DigiD assessment guidelines. The report format is often more extensive, and more is documented, than with a "standard" pentest. For example, a DigiD pentest report includes a detailed description of vulnerabilities, the methodologies used, and concrete recommendations.
Why carry out a pentest with Tozetta?
Tozetta aims to distinguish itself within the ethical hacking market with a specific focus on offensive testing. Many parties carry out pentests alongside other work. Because of our focus, we're the specialist, and fully independent. As such, Tozetta doesn't sell cyber security or IT solutions, unlike other IT or security firms that also carry out pentests (with accompanying advice).
Interactive vulnerability portal
Thanks to our focus, Tozetta has developed the vulnerability portal "Tozetta Reports", where vulnerabilities are displayed. We facilitate informing about and resolving these vulnerabilities with our clients in an interactive way. This unique form of reporting provides clients with more insight and enables closer collaboration between Tozetta and the end client.
Demonstrable expertise within the ethical hacking world
Tozetta has extensive experience carrying out DigiD pentests. Our ethical hackers are highly qualified and hold certifications from Offensive Security (OffSec.com). Besides being our experts' profession, ethical hacking is also their passion.
This is evident from their participation in various ethical hacking competitions, including "Hack the Hague". Tozetta even managed to take first place in this competition. Hack the Hague is a prestigious hacking competition where ethical hackers identify vulnerabilities in the systems of the municipality of The Hague. Read more about our win here.
Continuous insight into vulnerabilities
According to various guidelines, it's desirable to gain "continuous insight into vulnerabilities within software and systems". Besides a standalone DigiD pentest, you can also opt for Tozetta's "Hacking as a Service" subscription. Besides frequent pentesting, Tozetta offers a vulnerability monitor that scans daily for vulnerabilities on the internal network or the web application.
More info? Get in touch with Tozetta.