{"id":33292,"date":"2025-05-02T15:40:53","date_gmt":"2025-05-02T15:40:53","guid":{"rendered":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/?page_id=33292"},"modified":"2025-06-16T20:43:23","modified_gmt":"2025-06-16T20:43:23","slug":"sow-vipre-vulnerability-and-penetration-testing-services","status":"publish","type":"page","link":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/","title":{"rendered":"Statement of Work for VIPRE Vulnerability and Penetration Testing Services"},"content":{"rendered":"<section class=\"wp-block-e25m-section bs-section bs-section-05aaf7e43dc7218cbcdcc13f1fde9e12a13e28f8 bs-section---default bs-section--terms-of-use-heading bs-section--section-bottom-radius\"><style>.bs-section.bs-section-05aaf7e43dc7218cbcdcc13f1fde9e12a13e28f8{ background-image: url(https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2022\/07\/bg-terms-scaled.webp);background-position: center center;background-size: cover;} <\/style><div class=\"container\">\n<div class=\"wp-block-e25m-row bs-row row  bs-row---default\">\n<div class=\"bs-column col-sm-12   bs-column-5f6574ebb29ac8d58ab608d2aff5b1bbe4f96332 bs-column---default\">\n<h1 class=\"wp-block-heading\" id=\"h-vipre-statement-of-work-for-vipre-vulnerability-and-penetration-testing-services\">VIPRE\u00ae Statement of Work for VIPRE Vulnerability and Penetration Testing Services<\/h1>\n\n\n\n<p>Last Modified: May 1, 2025<\/p>\n<\/div>\n<\/div>\n<\/div><\/section>\n\n\n\n<section id=\"expanded-accordion\" class=\"wp-block-e25m-section bs-section bs-section-093d840811ebed611f8aa39b490cbd240621be3e bs-section---default bs-section--section-bottom-radius bs-section--privacy-policy\"><div class=\"container\">\n<div class=\"wp-block-e25m-row bs-row row  bs-row---default\">\n<div class=\"bs-column col-sm-12   bs-column-5f6574ebb29ac8d58ab608d2aff5b1bbe4f96332 bs-column---default\">\n<div id=\"toc\" style=\"margin-bottom: 20px; padding: 10px; background: #f8f9fa; border: 1px solid #ddd;\">\n  <h3>Table of Contents<\/h3>\n<\/div>\n\n<script>\ndocument.addEventListener(\"DOMContentLoaded\", function () {\n  const headers = document.querySelectorAll(\".card-header\");\n  const tocContainer = document.getElementById('toc');\n  \n  const ul = document.createElement(\"ul\");\n  ul.style.listStyle = \"none\";\n  ul.style.padding = \"0\";\n  ul.style.margin = \"0\";\n\n  headers.forEach((header, index) => {\n    const text = header.textContent.trim();\n    const anchorId = `section-${index}`;\n    header.setAttribute(\"id\", anchorId);\n\n    const li = document.createElement(\"li\");\n    const a = document.createElement(\"a\");\n    a.href = \"javascript:void(0)\";\n    a.dataset.targetId = anchorId;\n    a.textContent = text;\n    li.appendChild(a);\n    ul.appendChild(li);\n  });\n\n  tocContainer.appendChild(ul);\n\n  \/\/ Smooth scroll without updating URL\n  tocContainer.querySelectorAll(\"a\").forEach(link => {\n    link.addEventListener(\"click\", function (e) {\n      e.preventDefault();\n      const targetId = this.dataset.targetId;\n      const target = document.getElementById(targetId);\n      if (target) {\n        window.scrollTo({\n          top: target.offsetTop + 630,\n          behavior: \"smooth\"\n        });\n      }\n    });\n  });\n});\n<\/script>\n<\/div>\n\n\n\n<div class=\"bs-column col-12  col-sm-0 col-md-0   bs-column-ae4a53db09289e353ef2a3157dddfbb1f8145dbe bs-column---default\"><div id=\"accordion_26655e1ad65b-container\" class=\"bs-advance-accordion bs-advance-accordion--content-right bs-advance-accordion---default bs-advance-accordion--common-terms\" data-attributes='{\"acSideChange\":\"right-float\",\"floatClassName\":\"right-panel-floating\",\"alwaysExpanded\":true,\"accordionClassNames\":[{\"value\":\"bs-advance-accordion---default\",\"label\":\"Default\"},{\"value\":\"bs-advance-accordion--common-terms\",\"label\":\"Common Terms\"}],\"accordionIndex\":1,\"defaultOpenIndex\":0,\"colBreakpoint\":576}'><div class=\"bs-advance-accordion__left-container\"><div class=\"bs-advance-accordion__left-content-panel show\" data-parent=\"#panel_9b567d580215\"><\/div><div class=\"bs-advance-accordion__left-content-panel\" data-parent=\"#panel_d1a96869b64c\"><\/div><div class=\"bs-advance-accordion__left-content-panel\" data-parent=\"#panel_5a99eb623038\"><\/div><div class=\"bs-advance-accordion__left-content-panel\" data-parent=\"#panel_d4d752275de3\"><\/div><div class=\"bs-advance-accordion__left-content-panel\" data-parent=\"#panel_6072b40c209e\"><\/div><div class=\"bs-advance-accordion__left-content-panel\" data-parent=\"#panel_4c617d5565c7\"><\/div><div class=\"bs-advance-accordion__left-content-panel\" data-parent=\"#panel_93e0e5942d87\"><\/div><div class=\"bs-advance-accordion__left-content-panel\" data-parent=\"#panel_a3f88e0b2333\"><\/div><div class=\"bs-advance-accordion__left-content-panel\" data-parent=\"#panel_b33d9ae88464\"><\/div><div class=\"bs-advance-accordion__left-content-panel\" data-parent=\"#panel_6fab03c45140\"><\/div><\/div> <div class=\"bs-advance-accordion__right-container\">\n<p><\/p>\n  <div id=\"accordion_26655e1ad65b\"><div class=\"card\">  <button class=\"card-header accordion__block__btn expand-fixed\" id=\"panel_d1a96869b64c_header\"\n        data-toggle=\"collapse\"\n        data-target=\"#panel_d1a96869b64c\"\n        aria-expanded=\"false\"\n        aria-controls=\"panel_d1a96869b64c\" role=\"button\" aria-role=\"button\"><span><strong><strong>1. Executive Summary<\/strong><\/strong><\/button><div\n                    id=\"panel_d1a96869b64c\"\n                    class=\"collapse  expand-fixed\"\n                    \n                    data-parent=\"#accordion_26655e1ad65b\"\n                ><div class=\"card-body\">\n<p>This SOW is entered into between you (referred to as you, your or Customer) and VIPRE Security Group, Inc. (referred to as VIPRE). VIPRE is offering comprehensive Vulnerability and Penetration Testing services through three distinct packages, each designed to meet diverse security assessment needs. <strong>Customers will select one of the following packages based on their specific requirements and desired scope of assessment.<\/strong> This engagement employs a structured approach to evaluate the Customer\u2019s digital infrastructure, simulate real-world cyber threats where applicable, and deliver actionable insights for bolstering overall security. VIPRE\u2019s services are aligned with industry standards and regulatory requirements, ensuring robust defenses against potential cyberattacks.&nbsp;<\/p>\n\n<p>The following are the available service packages, each with an expanding scope:&nbsp;<\/p>\n\n<ul>\n<li><strong>Package 1: Vulnerability Assessment.<\/strong> This foundational package focuses on identifying and validating security weaknesses within the client&#8217;s domain and up to 50 specified IP addresses. It utilizes automated scanning techniques complemented by expert manual validation to provide a targeted understanding of known vulnerabilities.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Package 2: Penetration Testing.<\/strong> Building upon the Vulnerability Assessment, this package extends the security evaluation to include thorough network penetration testing and a cloud security configuration review. This review involves performing misconfiguration scanning and security benchmarking against industry best practices to identify potential weaknesses in the client&#8217;s cloud account setup.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Package 3: Penetration Testing 360.<\/strong> This most comprehensive offering encompasses all the elements of Packages 1 and 2, further incorporating in-depth web application penetration testing. This holistic approach provides a 360-degree view of the organization&#8217;s security posture, identifying vulnerabilities across its entire attack surface \u2013 from infrastructure to applications.&nbsp;<\/li>\n<\/ul>\n\n<p>Depending on the <strong>selected package<\/strong>, VIPRE will combine automated scanning with expert-driven manual testing and configuration reviews to uncover vulnerabilities across networks, applications, cloud environments, and endpoints. By leveraging globally recognized frameworks such as OWASP, NIST, PTES, and OSSTMM, VIPRE ensures a thorough security assessment aligned with industry standard practices.&nbsp;<\/p>\n\n<p>VIPRE will adhere to agreed-upon testing timelines and deliver reports outlining discovered vulnerabilities and configuration issues, along with prioritized and actionable remediation recommendations based on the <strong>chosen service<\/strong>.&nbsp;<\/p>\n      <\/div>  <\/div><\/div><div class=\"card\">  <button class=\"card-header accordion__block__btn expand-fixed\" id=\"panel_5a99eb623038_header\"\n        data-toggle=\"collapse\"\n        data-target=\"#panel_5a99eb623038\"\n        aria-expanded=\"false\"\n        aria-controls=\"panel_5a99eb623038\" role=\"button\" aria-role=\"button\"><span><strong>2. Definitions<\/strong><\/button><div\n                    id=\"panel_5a99eb623038\"\n                    class=\"collapse  expand-fixed\"\n                    \n                    data-parent=\"#accordion_26655e1ad65b\"\n                ><div class=\"card-body\">\n<p>The following capitalized terms will have the definitions set forth below. All other capitalized terms that are not defined herein shall have the meanings accorded to them in the MSA (as defined below).&nbsp;<\/p>\n\n<ol start=\"1\">\n<li><strong>Application Penetration Testing (PenTest\/PT):<\/strong> A simulated cyberattack to evaluate the security of an application.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"2\">\n<li><strong>Application VAPT:<\/strong> A comprehensive security assessment process that combines vulnerability assessment and penetration testing to proactively identify and address security weaknesses in applications before malicious actors can exploit them.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"3\">\n<li><strong>CIS Benchmarks:<\/strong> Configuration baselines and best practices for securely configuring a wide range of IT systems, software, and networks.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"4\">\n<li><strong>Cloud Security Assessment: <\/strong>Reviewing security configurations, access controls, and compliance for 1 Cloud Account and 10 Services.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"5\">\n<li><strong>Customer: <\/strong>An individual, company, or other legal entity that contracts with VIPRE and agrees to purchase Vulnerability and\/or Penetration Testing services.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"6\">\n<li><strong>Final Penetration Test Report:<\/strong> A report that contains the results of the penetration test and assessment phases.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"7\">\n<li><strong>ISO 27001: <\/strong>The standard provides a framework to help organizations manage and protect their information assets, ensuring confidentiality, integrity, and availability, and ultimately minimizing information security risks.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"8\">\n<li><strong>MSA: <\/strong>The VIPRE Master Services Agreement that this SOW is subject to, which is available at <a href=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/about-vipre\/legal\/<\/a>.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"9\">\n<li><strong>Network Penetration Testing (PenTest\/PT):<\/strong> A simulated cyberattack to evaluate the security of a system.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"10\">\n<li><strong>Network VAPT:<\/strong> A comprehensive security assessment process that combines vulnerability assessment and penetration testing to proactively identify and address security weaknesses in networks before malicious actors can exploit them.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"11\">\n<li><strong>NIST 800-115:<\/strong> A guide that provides security testing and assessment methodologies.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"12\">\n<li><strong>OSSTMM:<\/strong> Open Source Security Testing Methodology Manual, a security testing framework.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"13\">\n<li><strong>OWASP Top 10:<\/strong> A standard awareness document for developers and security professionals outlining the most critical web security risks.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"14\">\n<li><strong>PTES:<\/strong> Penetration Testing Execution Standard, a framework for conducting penetration tests.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"15\">\n<li><strong>Questionnaire: <\/strong>Provided to Customer, which will need to be filled in to provide information on systems to be tested.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"16\">\n<li><strong>Revalidation<\/strong>: VIPRE will perform one revalidation test to confirm that vulnerabilities are resolved for vulnerabilities listed in the Final Penetration Test Report. <strong>Customer must submit the request for Revalidation to VIPRE in writing within 90 days from the date that VIPRE provides the Final Penetration Test Report to Customer.<\/strong>&nbsp;&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"17\">\n<li><strong>SOW<\/strong>: This Statement of Work.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"18\">\n<li><strong>VM \u2013 Virtual Machine: <\/strong>A software container that can run its own operating system and execute applications like a physical server&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"19\">\n<li><strong>Vulnerability Assessment: <\/strong>A systematic review of security weaknesses in an information system.&nbsp;<\/li>\n<\/ol>\n      <\/div>  <\/div><\/div><div class=\"card\">  <button class=\"card-header accordion__block__btn expand-fixed\" id=\"panel_d4d752275de3_header\"\n        data-toggle=\"collapse\"\n        data-target=\"#panel_d4d752275de3\"\n        aria-expanded=\"false\"\n        aria-controls=\"panel_d4d752275de3\" role=\"button\" aria-role=\"button\"><span><strong>3. Package Overview\u00a0<\/strong><\/button><div\n                    id=\"panel_d4d752275de3\"\n                    class=\"collapse  expand-fixed\"\n                    \n                    data-parent=\"#accordion_26655e1ad65b\"\n                ><div class=\"card-body\">\n<p>VIPRE offers a range of Vulnerability and Penetration Testing service packages, as detailed in this SOW. All services will be delivered remotely. To assist you in selecting the package that best meets your needs, Table 1 provides a comprehensive overview of the scope of work for each option, including the specific features and the number of testable resources or assets.<\/p>\n\n<div class=\"wp-block-e25m-div bs-div bs-div-91103da672f431009115c2b4dd3e89284290a37b bs-div---default\"><div class=\"bs-div__inner\">\n<p><br><\/p>\n<\/div><\/div>\n\n<p><strong>Table 1: Packages&nbsp;<\/strong><\/p>\n<div class='media-elements bs-media-element---default enable'>    <div class='bs-common-image'>\n                            <figure class='figure justify-content-start d-flex'>\n                            <picture>\n                            <source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-1a.png\" media=\"(max-width:575px)\"><source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-1a.png\" media=\"(max-width:1280px)\">\n                            <img src='https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/06\/statement-of-work-pen-testing-figure-1a.png' class='img-fluid' alt='' title=''  \/>\n                            <\/picture>\n                                \n                            <\/figure>\n                        <\/div><\/div>\n<p><br><\/p>\n\n<p><strong>Package 1: Vulnerability Assessment<\/strong>&nbsp;<\/p>\n\n<ul>\n<li>Vulnerability Assessment \u2013 50 IPs&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Package 2: Penetration Testing<\/strong>&nbsp;<\/p>\n\n<ul>\n<li>Vulnerability Assessment \u2013 50 IPs&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Network Pentest \u2013 50 IPs&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Cloud Configuration Review \u2013 1 Account (up to 10 Services)&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Package 3: Penetration Testing 360<\/strong>&nbsp;<\/p>\n\n<ul>\n<li>Vulnerability Assessment \u2013 50 IPs&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Network Pentest \u2013 50 IPs&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Cloud Configuration Review \u2013 2 Account (up to 10 Services)&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Black-Box Web Application Pentest \u2013 up to 5 public domains&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Grey-Box Web Application Pentest \u2013 1 Application up to 3 User roles &amp; 20 API Endpoints&nbsp;<\/li>\n<\/ul>\n      <\/div>  <\/div><\/div><div class=\"card\">  <button class=\"card-header accordion__block__btn expand-fixed\" id=\"panel_6072b40c209e_header\"\n        data-toggle=\"collapse\"\n        data-target=\"#panel_6072b40c209e\"\n        aria-expanded=\"false\"\n        aria-controls=\"panel_6072b40c209e\" role=\"button\" aria-role=\"button\"><span><strong>4. Package 1: VIPRE Vulnerability Assessment<\/strong><\/button><div\n                    id=\"panel_6072b40c209e\"\n                    class=\"collapse  expand-fixed\"\n                    \n                    data-parent=\"#accordion_26655e1ad65b\"\n                ><div class=\"card-body\">\n<h5 class=\"wp-block-heading\" id=\"h-\"><\/h5>\n\n<p>VIPRE will provide Vulnerability Assessment services as described in this SOW. This SOW and your use of the Vulnerability Assessment services are subject to the terms of the MSA. In the event of a conflict between this SOW and the MSA, the terms of this SOW will control.&nbsp;<\/p>\n\n<p><strong>The scope of work for the VIPRE Vulnerability Assessment will include the phases listed within this section.&nbsp;<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will conduct an assessment that will focus on evaluating the security configurations, rules, and effectiveness of 50 IPs in Customer&#8217;s network environment. The scope includes:&nbsp;<\/p>\n\n<ul>\n<li><strong>Domain:<\/strong>\u202fProtecting web applications from threats like SQL injection, cross-site scripting (XSS), and other web-based attacks.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Network IPs:<\/strong>\u202fDetecting and preventing network-level threats such as unauthorized access, and DDoS attacks, weak protocol usage.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Approach &amp; Methodology<\/strong>&nbsp;<\/p>\n\n<p>VIPRE\u2019s assessment will follow industry-standard methodologies and practices, including\u202f<strong>OWASP, NIST 800-115, &amp; PTES<\/strong>, ensuring a thorough and structured approach. The methodology includes the following phases.&nbsp;<\/p>\n\n<p><strong>Phase 1: Planning and Preparation&nbsp;<\/strong>&nbsp;<\/p>\n\n<p>The assessment will begin with an onboarding call to review key logistics including timelines, communication channels, and technical scoping. During this session, VIPRE will share a detailed questionnaire designed to gather critical information about your network environment.&nbsp;<\/p>\n\n<p>The questionnaire, along with any relevant documentation (e.g., network diagrams), is essential for initiating the assessment. Your IT team\u2019s input will be necessary to ensure completeness and accuracy.&nbsp;<\/p>\n\n<p>Key Areas Covered in the Questionnaire&nbsp;<\/p>\n\n<p>a) Network Infrastructure Information&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>L2 and L3 Network Details&nbsp;<\/li>\n\n\n\n<li>Facility Diagrams&nbsp;<\/li>\n\n\n\n<li>Wireless Access Points&nbsp;<\/li>\n\n\n\n<li>Asset Inventory&nbsp;<\/li>\n<\/ul>\n\n<p>b) Network and Security Devices&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>Firewall&nbsp;<\/li>\n\n\n\n<li>IDS\/IPS&nbsp;<\/li>\n\n\n\n<li>SIEM&nbsp;<\/li>\n\n\n\n<li>Antivirus&nbsp;<\/li>\n\n\n\n<li>Secure Configuration Benchmarks&nbsp;<\/li>\n<\/ul>\n\n<p>c) Network Services&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>Active Directory \/ LDAP&nbsp;<\/li>\n\n\n\n<li>DNS &amp; DHCP&nbsp;<\/li>\n\n\n\n<li>Email Services&nbsp;<\/li>\n\n\n\n<li>Network Monitoring Tools&nbsp;<\/li>\n\n\n\n<li>Internet-Facing Servers \/ Applications&nbsp;<\/li>\n<\/ul>\n\n<p>d) Security Policies and Practices&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>IT Security Governance&nbsp;<\/li>\n\n\n\n<li>Data Protection (at rest &amp; in transit)&nbsp;<\/li>\n\n\n\n<li>Backup &amp; Disaster Recovery&nbsp;<\/li>\n\n\n\n<li>EINDPUNTBEVEILIGING&nbsp;<\/li>\n\n\n\n<li>Vulnerability Management&nbsp;<\/li>\n\n\n\n<li>Incident Response&nbsp;<\/li>\n\n\n\n<li>Access Control&nbsp;<\/li>\n\n\n\n<li>Security Awareness&nbsp;<\/li>\n<\/ul>\n\n<p>Successful execution of this assessment is contingent upon fulfilling the requirements outlined in the \u201cYour Requirements\u201d section of the SOW. This includes timely submission of the questionnaire and granting necessary access and approvals to enable effective and efficient testing aligned with SLA expectations.&nbsp;<\/p>\n\n<p><strong>Phase 2: Vulnerability Scanning &amp; Analysis<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will conduct a comprehensive vulnerability assessment of the agreed-upon IPs. This assessment will include:&nbsp;<\/p>\n\n<ul>\n<li>Automated scanning of IPs for known vulnerabilities utilizing industry-standard tools to identify known vulnerabilities.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Manual validation of identified vulnerabilities.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Phase 3: Attack Surface &amp; Exploitation Testing<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will conduct the testing outlined below on the date and time agreed upon with Customer during the phase 1 planning and preparation.&nbsp;<\/p>\n\n<ul>\n<li>Testing for misconfigurations, weak authentication, and outdated software.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Safe exploitation of vulnerabilities to evaluate security gaps.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Phase 4: Risk Evaluation, Reporting &amp; Remediation Plan<\/strong>&nbsp;<\/p>\n\n<p>Within 10 business days of completing the vulnerability assessment (Phases 2 &amp; 3), VIPRE will deliver a report detailing the findings and a strategic remediation plan. This phase includes:&nbsp;<\/p>\n\n<ul>\n<li><strong>Risk Evaluation &amp; Impact Analysis:<\/strong> A realistic assessment of your organization&#8217;s security effectiveness based on the assessment results, including the potential impact of discovered vulnerabilities and the prioritization of risks according to their likelihood and severity.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Detailed Reporting:<\/strong> A report outlining all identified vulnerabilities, their corresponding risk ratings, and the evidence supporting these findings.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Mitigation and Security Enhancement Recommendations:<\/strong> Actionable and prioritized recommendations for mitigating the identified vulnerabilities and enhancing your overall security posture.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>\u200b<\/strong><strong>\u200b<\/strong><strong>Vulnerability Assessment Deliverables<\/strong><strong>\u200b<\/strong><strong><\/strong>&nbsp;<\/p>\n\n<p>Upon completion of the assessment, VIPRE will provide You with the following deliverables:&nbsp;<\/p>\n\n<ul>\n<li><strong>Vulnerability Assessment Report:<\/strong>\u202fwith findings, severity levels, and recommendations.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Remediation Guidance:<\/strong>\u202ffor addressing identified vulnerabilities.&nbsp;<\/li>\n<\/ul>\n      <\/div>  <\/div><\/div><div class=\"card\">  <button class=\"card-header accordion__block__btn expand-fixed\" id=\"panel_4c617d5565c7_header\"\n        data-toggle=\"collapse\"\n        data-target=\"#panel_4c617d5565c7\"\n        aria-expanded=\"false\"\n        aria-controls=\"panel_4c617d5565c7\" role=\"button\" aria-role=\"button\"><span><strong>5. Package 2: VIPRE Penetration Testing<\/strong><\/button><div\n                    id=\"panel_4c617d5565c7\"\n                    class=\"collapse  expand-fixed\"\n                    \n                    data-parent=\"#accordion_26655e1ad65b\"\n                ><div class=\"card-body\">\n<h5 class=\"wp-block-heading\" id=\"h-\"><\/h5>\n\n<p>VIPRE will provide Penetration Testing services as described in this SOW. This SOW and your use of the Penetration Testing services are subject to the terms of the MSA. In the event of a conflict between this SOW and the MSA, the terms of this SOW will control.&nbsp;<\/p>\n\n<p><strong>The scope of work for the VIPRE <\/strong><strong>Penetration Testing<\/strong> <strong>will include the phases listed within this section.&nbsp;<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will conduct a comprehensive Network Penetration Testing, Vulnerability Assessment, and Cloud Security Assessment for your environment. VIPRE\u2019s objective is to identify vulnerabilities, assess security controls, and provide actionable remediation strategies to strengthen the security posture of your infrastructure. The scope includes:&nbsp;<\/p>\n\n<ul>\n<li><strong>Vulnerability Assessment:<\/strong> Identifying weaknesses and misconfigurations in the network infrastructure across 50 IP addresses.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Network Penetration Testing:<\/strong> Simulating real-world attacks to evaluate the resilience of security controls across 50 IP addresses.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Cloud Security Assessment: <\/strong>Reviewing security configurations, access controls, and compliance for 1 Cloud Account and up to 10 Services.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Approach &amp; Methodology<\/strong>&nbsp;<\/p>\n\n<p>VIPRE\u2019s assessment will follow industry-standard practices and frameworks, including NIST 800-115, PTES, OWASP, and CIS Benchmarks, ensuring a structured and effective evaluation. The methodology includes the following phases.&nbsp;<\/p>\n\n<p><strong>Phase 1: Planning and Preparation<\/strong>&nbsp;<\/p>\n\n<p>The assessment will begin with an onboarding call to review key logistics including timelines, communication channels, and technical scoping. During this session, VIPRE will share a detailed questionnaire designed to gather critical information about your network environment.&nbsp;<\/p>\n\n<p>The questionnaire, along with any relevant documentation (e.g., network diagrams), is essential for initiating the assessment. Your IT team\u2019s input will be necessary to ensure completeness and accuracy.&nbsp;<\/p>\n\n<p>Key Areas Covered in the Questionnaire&nbsp;<\/p>\n\n<p>a) Network Infrastructure Information&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>L2 and L3 Network Details&nbsp;<\/li>\n\n\n\n<li>Facility Diagrams&nbsp;<\/li>\n\n\n\n<li>Wireless Access Points&nbsp;<\/li>\n\n\n\n<li>Asset Inventory&nbsp;<\/li>\n<\/ul>\n\n<p>b) Network and Security Devices&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>Firewall&nbsp;<\/li>\n\n\n\n<li>IDS\/IPS&nbsp;<\/li>\n\n\n\n<li>SIEM&nbsp;<\/li>\n\n\n\n<li>Antivirus&nbsp;<\/li>\n\n\n\n<li>Secure Configuration Benchmarks&nbsp;<\/li>\n<\/ul>\n\n<p>c) Network Services&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>Active Directory \/ LDAP&nbsp;<\/li>\n\n\n\n<li>DNS &amp; DHCP&nbsp;<\/li>\n\n\n\n<li>Email Services&nbsp;<\/li>\n\n\n\n<li>Network Monitoring Tools&nbsp;<\/li>\n\n\n\n<li>Internet-Facing Servers \/ Applications&nbsp;<\/li>\n<\/ul>\n\n<p>d) Security Policies and Practices&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>IT Security Governance&nbsp;<\/li>\n\n\n\n<li>Data Protection (at rest &amp; in transit)&nbsp;<\/li>\n\n\n\n<li>Backup &amp; Disaster Recovery&nbsp;<\/li>\n\n\n\n<li>EINDPUNTBEVEILIGING&nbsp;<\/li>\n\n\n\n<li>Vulnerability Management&nbsp;<\/li>\n\n\n\n<li>Incident Response&nbsp;<\/li>\n\n\n\n<li>Access Control&nbsp;<\/li>\n\n\n\n<li>Security Awareness&nbsp;<\/li>\n<\/ul>\n\n<p>Successful execution of this assessment is contingent upon fulfilling the requirements outlined in the \u201cYour Requirements\u201d section of the SOW. This includes timely submission of the questionnaire and granting necessary access and approvals to enable effective and efficient testing aligned with SLA expectations.&nbsp;<\/p>\n\n<p><strong>Phase 2: Vulnerability Scanning &amp; Analysis<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will conduct the vulnerability testing outlined below on the date and time agreed upon with the customer.&nbsp;<\/p>\n\n<ul>\n<li>Automated scanning of IPs for known vulnerabilities using industry-leading tools.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Manual validation of identified vulnerabilities to reduce false positives.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Cloud misconfiguration scanning and security benchmarking against best practices.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Phase 3: Network Penetration Testing<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will conduct the Network Penetration testing outlined below on the date and time agreed upon with the customer.&nbsp;<\/p>\n\n<ul>\n<li><strong>External Testing: <\/strong>Evaluating internet-facing IPs for security flaws and potential exploitation.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Internal Testing (if applicable): <\/strong>Assessing security from within the network to identify lateral movement opportunities.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Attack Surface Analysis:<\/strong> Testing for misconfigurations, weak authentication, and exposed services.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Exploitation (Non-Destructive):<\/strong> Attempting controlled exploitation of vulnerabilities to assess impact.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Privilege Escalation Testing:<\/strong> Identifying weaknesses that could allow attackers to gain elevated access.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Phase 4: Cloud Security Assessment<\/strong>&nbsp;<\/p>\n\n<p>The Cloud Security Assessment evaluates security configurations across 1 (one) account and a total of 10 cloud services. This assessment helps identify vulnerabilities, misconfigurations, and potential risks to enhance overall security and compliance. This phase will be completed within 10 business days.&nbsp;<\/p>\n\n<p><strong>Key Areas of Assessment:<\/strong>&nbsp;<\/p>\n\n<ul>\n<li><strong>Identity and Access Management (IAM) &amp; Role-Based Access Control (RBAC):<\/strong> Review policies, roles, controls, MFA enforcement and identified of excessive permissions and unauthorized access&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Encryption and Key Management:<\/strong> Assessment of encryption for data at rest and in transit. Validation of key management policies and secure credential storage.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Network Security &amp; Firewall Configurations:<\/strong> Analysis of VPC architecture, subnet segmentation, and firewall rules. Identification of publicly exposed assets and misconfigurations.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Logging, Monitoring, and Compliance:<\/strong> Review of logging configurations, audit logs, and monitoring tools. Identification of compliance gaps based on industry standards. Evaluation of automated threat detection mechanisms.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Data Storage and Access Control Security:<\/strong> Analysis of cloud storage security configurations. Identification of public exposure risks and access misconfigurations. Review of backup, disaster recovery, and data retention policies.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Compliance &amp; Best Practices Review:<\/strong> Aligning security controls with industry standards such as ISO 27001, NIST, and CIS Benchmarks.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Phase 5: Risk Evaluation &amp; Impact Analysis<\/strong>&nbsp;<\/p>\n\n<p>Within 10 business days of completing phase 4, VIPRE will provide a realistic assessment of an organization&#8217;s security effectiveness based on test results<strong>.<\/strong>&nbsp;<\/p>\n\n<ul>\n<li>Assessing the criticality and exploitability of discovered vulnerabilities. Providing risk-based prioritization of findings.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Phase 6: Reporting &amp; Remediation Plan<\/strong>&nbsp;<\/p>\n\n<p>Within 10 business days of completing phase 5, VIPRE will deliver a report to you outlining risks and remediation steps.&nbsp;<\/p>\n\n<ul>\n<li>Technical report with findings, severity levels, and recommendations.&nbsp;&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Executive Summary for management, outlining key risks and mitigation strategies.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Penetration Testing Deliverables<\/strong>&nbsp;<\/p>\n\n<p>Upon completion of the assessment, VIPRE will provide you with the following deliverables:&nbsp;&nbsp;<\/p>\n\n<ul>\n<li><strong>Final Penetration Testing Report<\/strong> which is comprised of the following&nbsp;\n<ul>\n<li><strong>Vulnerability Assessment Report<\/strong> \u2013 A written report outlining identified vulnerabilities, risk ratings, and suggestions for remediation.&nbsp;&nbsp;<\/li>\n\n\n\n<li><strong>Network Penetration Testing Report<\/strong> \u2013 A written report detailing the results of the simulated attacks, including security control analysis, system weaknesses, and exploitation methods.&nbsp;<\/li>\n\n\n\n<li><strong>Cloud Security Assessment Report <\/strong>\u2013 A written report covering misconfigurations, access control weaknesses, and compliance gaps.&nbsp;&nbsp;<\/li>\n\n\n\n<li><strong>Executive Summary for management<\/strong> \u2013 With risk insights and remediation priorities.&nbsp;<\/li>\n\n\n\n<li><strong>Remediation Guidance<\/strong> \u2013 Clear written recommendations for fixing or mitigating the vulnerabilities found.&nbsp;<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Revalidation Report<\/strong> \u2013 A report containing the results of the Revalidation Test to confirm that reported vulnerabilities are resolved. <strong>You must request the single Revalidation test in writing within 90 days from the date that VIPRE delivers the Final Penetration Testing Report to You.&nbsp;<\/strong><\/li>\n<\/ul>\n      <\/div>  <\/div><\/div><div class=\"card\">  <button class=\"card-header accordion__block__btn expand-fixed\" id=\"panel_93e0e5942d87_header\"\n        data-toggle=\"collapse\"\n        data-target=\"#panel_93e0e5942d87\"\n        aria-expanded=\"false\"\n        aria-controls=\"panel_93e0e5942d87\" role=\"button\" aria-role=\"button\"><span>6. Package 3: VIPRE Penetration Testing 360<\/button><div\n                    id=\"panel_93e0e5942d87\"\n                    class=\"collapse  expand-fixed\"\n                    \n                    data-parent=\"#accordion_26655e1ad65b\"\n                ><div class=\"card-body\">\n<h5 class=\"wp-block-heading\" id=\"h-\"><\/h5>\n\n<p>VIPRE will provide Penetration Testing services as described in this SOW. This SOW and your use of the Penetration Testing services are subject to the terms of the MSA. In the event of a conflict between this SOW and the MSA, the terms of this SOW will control.&nbsp;<\/p>\n\n<p><strong>The scope of work for the VIPRE <\/strong><strong>Penetration Testing<\/strong> <strong>will include the phases listed within this section.&nbsp;<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will conduct a comprehensive Web Application Penetration Testing, Network Penetration Testing, Vulnerability Assessment, and Cloud Security Assessment for your environment. VIPRE\u2019s objective is to identify vulnerabilities, assess security controls, and provide actionable remediation strategies to strengthen the security posture of your infrastructure. The scope includes:&nbsp;<\/p>\n\n<ul>\n<li><strong>Vulnerability Assessment:<\/strong> Identifying weaknesses and misconfigurations in the network infrastructure across 50 IP addresses.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Network Penetration Testing:<\/strong> Simulating real-world attacks to evaluate the resilience of security controls across 50 IP addresses.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Cloud Security Assessment: <\/strong>Reviewing security configurations, access controls, and compliance for up to 2 Cloud Accounts and up to 10 Services.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Black-Box Web Application Penetration Testing<\/strong>: Simulating real-world attacks across 5 public domains.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Grey-Box Web Application Penetration Testing<\/strong>: Simulating real-world attacks across one application, up to 3 user roles, and 20 API endpoints.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Approach &amp; Methodology<\/strong>&nbsp;<\/p>\n\n<p>VIPRE\u2019s assessment will follow industry-standard practices and frameworks, including NIST 800-115, PTES, OWASP, and CIS Benchmarks, ensuring a structured and effective evaluation. The methodology includes the following phases.&nbsp;<\/p>\n\n<p><strong>Phase 1: Planning and Preparation<\/strong>&nbsp;<\/p>\n\n<p>The assessment will begin with an onboarding call to review key logistics including timelines, communication channels, and technical scoping. During this session, VIPRE will share a detailed questionnaire designed to gather critical information about your network environment.&nbsp;<\/p>\n\n<p>The questionnaire, along with any relevant documentation (e.g., network diagrams), is essential for initiating the assessment. Your IT team\u2019s input will be necessary to ensure completeness and accuracy.&nbsp;<\/p>\n\n<p>Key Areas Covered in the Questionnaire&nbsp;<\/p>\n\n<p>a) Network Infrastructure Information&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>L2 and L3 Network Details&nbsp;<\/li>\n\n\n\n<li>Facility Diagrams&nbsp;<\/li>\n\n\n\n<li>Wireless Access Points&nbsp;<\/li>\n\n\n\n<li>Asset Inventory&nbsp;<\/li>\n<\/ul>\n\n<p>b) Network and Security Devices&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>Firewall&nbsp;<\/li>\n\n\n\n<li>IDS\/IPS&nbsp;<\/li>\n\n\n\n<li>SIEM&nbsp;<\/li>\n\n\n\n<li>Antivirus&nbsp;<\/li>\n\n\n\n<li>Secure Configuration Benchmarks&nbsp;<\/li>\n<\/ul>\n\n<p>c) Network Services&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>Active Directory \/ LDAP&nbsp;<\/li>\n\n\n\n<li>DNS &amp; DHCP&nbsp;<\/li>\n\n\n\n<li>Email Services&nbsp;<\/li>\n\n\n\n<li>Network Monitoring Tools&nbsp;<\/li>\n\n\n\n<li>Internet-Facing Servers \/ Applications&nbsp;<\/li>\n<\/ul>\n\n<p>d) Security Policies and Practices&nbsp;<\/p>\n\n<ul class=\"pl-5\">\n<li>IT Security Governance&nbsp;<\/li>\n\n\n\n<li>Data Protection (at rest &amp; in transit)&nbsp;<\/li>\n\n\n\n<li>Backup &amp; Disaster Recovery&nbsp;<\/li>\n\n\n\n<li>EINDPUNTBEVEILIGING&nbsp;<\/li>\n\n\n\n<li>Vulnerability Management&nbsp;<\/li>\n\n\n\n<li>Incident Response&nbsp;<\/li>\n\n\n\n<li>Access Control&nbsp;<\/li>\n\n\n\n<li>Security Awareness&nbsp;<\/li>\n<\/ul>\n\n<p>Successful execution of this assessment is contingent upon fulfilling the requirements outlined in the \u201cYour Requirements\u201d section of the SOW. This includes timely submission of the questionnaire and granting necessary access and approvals to enable effective and efficient testing aligned with SLA expectations.<\/p>\n\n<p><strong>Phase 2: Application Penetration Testing<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will conduct the Application Penetration testing outlined below on the date and time agreed upon with the customer. This phase comprises the VAPT activities performed against your assets selected for penetration testing. The scope includes:&nbsp;<\/p>\n\n<ul>\n<li><strong>Black-Box Web Application Penetration Testing<\/strong>: Simulating real-world attacks across 5 public domains.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Grey-Box Web Application Penetration Testing<\/strong>: Simulating real-world attacks across one application, up to 3 user roles, and 20 API endpoints&nbsp;<\/li>\n<\/ul>\n\n<p>The applications Penetration Test may include the areas mentioned in Table 2.&nbsp;<\/p>\n\n<p><strong>Table 2: Applications Penetration Testing may include the following prominent areas<\/strong>&nbsp;<\/p>\n<div class='media-elements bs-media-element---default enable'>    <div class='bs-common-image'>\n                            <figure class='figure justify-content-start d-flex'>\n                            <picture>\n                            <source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-2a.png\" media=\"(max-width:575px)\"><source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-2a.png\" media=\"(max-width:1280px)\">\n                            <img src='https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-2a.png' class='img-fluid' alt='' title=''  \/>\n                            <\/picture>\n                                \n                            <\/figure>\n                        <\/div><\/div>\n<p><br><\/p>\n\n<p><strong>Phase 3: Network Penetration Testing<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will conduct the Network Penetration testing outlined below on the date and time agreed upon with Customer. This phase comprises the VAPT activities performed against Customer\u2019s network assets selected for penetration testing. The scope includes:&nbsp;<\/p>\n\n<ul>\n<li><strong>External Testing: <\/strong>Evaluating internet-facing IPs for security flaws and potential exploitation.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Internal Testing (if applicable): <\/strong>Assessing security from within the network to identify lateral movement opportunities.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Attack Surface Analysis:<\/strong> Testing for misconfigurations, weak authentication, and exposed services.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Exploitation (Non-Destructive):<\/strong> Attempting controlled exploitation of vulnerabilities to assess impact.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Privilege Escalation Testing:<\/strong> Identifying weaknesses that could allow attackers to gain elevated access.&nbsp;<\/li>\n<\/ul>\n\n<p>You will assist the VIPRE security analyst in performing this activity.&nbsp; A scanner VM shall be deployed for a limited time in your network to perform VAPT of internal network and software applications hosted on the intra-net. You will be required to whitelist the IP address assigned to the scanner from the Firewall and any failover or load balancer. The network penetration test may include the following (Table 3) potential areas.&nbsp;<\/p>\n\n<p><strong>Table 3: Network penetration test may include the following areas<\/strong>&nbsp;<\/p>\n<div class='media-elements bs-media-element---default enable'>    <div class='bs-common-image'>\n                            <figure class='figure justify-content-start d-flex'>\n                            <picture>\n                            <source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-3a.png\" media=\"(max-width:575px)\"><source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-3a.png\" media=\"(max-width:1280px)\">\n                            <img src='https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-3a.png' class='img-fluid' alt='' title=''  \/>\n                            <\/picture>\n                                \n                            <\/figure>\n                        <\/div><\/div>\n<p><br><\/p>\n\n<p><strong>Phase 4: Cloud Security Assessment<\/strong>&nbsp;<\/p>\n\n<p>The Cloud Security Assessment evaluates security configurations across 2 accounts and a total of 10 cloud services. This assessment helps identify vulnerabilities, misconfigurations, and potential risks to enhance overall security and compliance. This phase will be completed within 10 business days.&nbsp;<\/p>\n\n<p><strong>Key Areas of Assessment:<\/strong>&nbsp;<\/p>\n\n<ul>\n<li><strong>Identity and Access Management (IAM) &amp; Role-Based Access Control (RBAC):<\/strong> Review policies, roles, controls, MFA enforcement and identified of excessive permissions and unauthorized access&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Encryption and Key Management:<\/strong> Assessment of encryption for data at rest and in transit. Validation of key management policies and secure credential storage.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Network Security &amp; Firewall Configurations<\/strong>: Analysis of VPC architecture, subnet segmentation, and firewall rules. Identification of publicly exposed assets and misconfigurations.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Logging, Monitoring, and Compliance:<\/strong> Review of logging configurations, audit logs, and monitoring tools. Identification of compliance gaps based on industry standards. Evaluation of automated threat detection mechanisms.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Data Storage and Access Control Security:<\/strong> Analysis of cloud storage security configurations. Identification of public exposure risks and access misconfigurations. Review of backup, disaster recovery, and data retention policies.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Compliance &amp; Best Practices Review:<\/strong> Aligning security controls with industry standards such as ISO 27001, NIST, and CIS Benchmarks.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Phase 5: Reporting, Clean-Up and Destroy Artifacts<\/strong>&nbsp;<\/p>\n\n<p>This phase comprises the reporting activity and cleanup of the environment and destroying any artifacts created for the purpose of VAPT activity. This phase to be completed within 10 business days of completing the testing and assessment phases. This phase comprises these steps:&nbsp;<\/p>\n\n<ul>\n<li><strong>Analyze raw data<\/strong>: VIPRE will review and evaluate the raw data gathered from interviews, observations, samples, and\/or tools.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Develop recommendations:<\/strong> VIPRE will draft recommendations for mitigation.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>QA draft reports with team:<\/strong> The draft report is reviewed for technical completeness and SOW validation by VIPRE.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li><strong>Final Penetration Testing Report delivered:<\/strong> The report is delivered to you along with final out brief meeting if requested by you.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Penetration Testing 360 Deliverables<\/strong>&nbsp;<\/p>\n\n<p>VIPRE will provide the following deliverables to you:&nbsp;<\/p>\n\n<ul>\n<li><strong>Final Penetration Testing Report<\/strong> \u2013 which is comprised of the following&nbsp;\n<ul>\n<li><strong>Vulnerability Assessment Report<\/strong> \u2013 A written report outlining identified vulnerabilities, risk ratings, and suggestions for remediation.&nbsp;<\/li>\n\n\n\n<li><strong>Network Penetration Testing Report<\/strong> \u2013 A written report detailing the results of the simulated attacks, including security control analysis, system weaknesses, and exploitation methods.&nbsp;<\/li>\n\n\n\n<li><strong>Application Penetration Testing Report<\/strong> \u2013 A written report detailing the results of the simulated attacks, including security control analysis, system weaknesses, and exploitation methods.&nbsp;<\/li>\n\n\n\n<li><strong>Cloud Security Assessment Report <\/strong>\u2013 A written report covering misconfigurations, access control weaknesses, and compliance gaps.&nbsp;<\/li>\n\n\n\n<li><strong>Executive Summary for management<\/strong> \u2013 with risk insights and remediation priorities.&nbsp;<\/li>\n\n\n\n<li><strong>Remediation Guidance<\/strong> \u2013 Clear written recommendations for fixing or mitigating the vulnerabilities found.&nbsp;<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Revalidation Report<\/strong> \u2013 A report containing the results of the Revalidation Test to confirm that reported vulnerabilities are resolved. <strong>You must request the single Revalidation test in writing within 90 days from the date VIPRE delivers the Final Penetration Testing Report to you.<\/strong>&nbsp;<\/li>\n<\/ul>\n      <\/div>  <\/div><\/div><div class=\"card\">  <button class=\"card-header accordion__block__btn expand-fixed\" id=\"panel_a3f88e0b2333_header\"\n        data-toggle=\"collapse\"\n        data-target=\"#panel_a3f88e0b2333\"\n        aria-expanded=\"false\"\n        aria-controls=\"panel_a3f88e0b2333\" role=\"button\" aria-role=\"button\"><span><strong>7. Your Requirements<\/strong><\/button><div\n                    id=\"panel_a3f88e0b2333\"\n                    class=\"collapse  expand-fixed\"\n                    \n                    data-parent=\"#accordion_26655e1ad65b\"\n                ><div class=\"card-body\">\n<p>The following requirements are essential for the successful delivery of the selected Vulnerability and Penetration Testing services package and are supplemental to the terms stated in the MSA. The specific requirements outlined below will vary depending on whether Package 1 (Vulnerability Assessment), Package 2 (Penetration Testing), or Package 3 (Penetration Testing 360) is purchased. Failure to meet the applicable requirements may impair the delivery of services under this SOW and may adversely affect the application of any SLA and established timelines&nbsp;<\/p>\n\n<ol start=\"1\">\n<li>You must provide accurate details in the customer Questionnaire, and in a timely manner, including but not limited to:\n<ul>\n<li>List of target systems, networks, and applications to be tested.&nbsp;<\/li>\n\n\n\n<li>IP ranges, domains, URLs, or internal assets in scope.&nbsp;<\/li>\n\n\n\n<li>Exclusions (systems or environments that should not be tested) <\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n<ol start=\"2\">\n<li>You must provide the following, depending on the testing type (e.g., Black-box, Gray-box):&nbsp;\n<ul>\n<li>Network and application credentials (for authenticated testing).&nbsp;<\/li>\n\n\n\n<li>VPN access to internal systems (if applicable).&nbsp;<\/li>\n\n\n\n<li>API keys and documentation (if testing APIs).&nbsp;<\/li>\n\n\n\n<li>Test accounts with different privilege levels (e.g., user, admin).&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n<ol start=\"3\">\n<li>You must request the single Revalidation test in writing to VIPRE within 90-days of the delivery of the Final Penetration Testing Report and once you have addressed the reported vulnerabilities.&nbsp;&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"4\">\n<li>You must perform the following to avoid service disruptions and ensure legal compliance:&nbsp;\n<ul>\n<li>Approve testing hours and windows (especially for production environments)&nbsp;<\/li>\n\n\n\n<li>Provide points of contact for communication during testing&nbsp;<\/li>\n\n\n\n<li>Approve or restrict attack techniques&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n<ol start=\"5\">\n<li>You must Whitelist relevant scanner and tools in firewalls, IDS\/IPS to avoid blocking&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"6\">\n<li>You must provide network architecture diagrams, if required.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"7\">\n<li>You are responsible for procuring and\/or managing the hardware and network required for security assessment services.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"8\">\n<li>You are required to maintain an active and functional internet connection at all times. You are responsible for internet access service and telecommunication systems.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"9\">\n<li>Network VAPT and\/or Web Application VAPT Service will be delivered only for one time.&nbsp; At the end of the service, Customer can purchase these services on a periodic or continuous basis.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"10\">\n<li>You should plan to interact with the VIPRE PenTest team for around 1 week prior to the required scheduling PenTest activity.&nbsp;<\/li>\n<\/ol>\n\n<ol start=\"11\">\n<li>You may need to interact with the VIPRE PenTest team for around 1 week prior to the required scheduling of the Revalidation testing.&nbsp;<\/li>\n<\/ol>\n      <\/div>  <\/div><\/div><div class=\"card\">  <button class=\"card-header accordion__block__btn expand-fixed\" id=\"panel_b33d9ae88464_header\"\n        data-toggle=\"collapse\"\n        data-target=\"#panel_b33d9ae88464\"\n        aria-expanded=\"false\"\n        aria-controls=\"panel_b33d9ae88464\" role=\"button\" aria-role=\"button\"><span><strong>8. Responsibilities<\/strong><\/button><div\n                    id=\"panel_b33d9ae88464\"\n                    class=\"collapse  expand-fixed\"\n                    \n                    data-parent=\"#accordion_26655e1ad65b\"\n                ><div class=\"card-body\">\n<p>Roles and Responsibilities for You and the VIPRE team are shown in table 4, below.&nbsp;<\/p>\n\n<p>Additionally, VIPRE will adhere to the following guidelines.&nbsp;<\/p>\n\n<ul>\n<li>VIPRE will attempt to minimize any impact to your production and include special considerations for legacy systems.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>All tests will be non-destructive, non-intrusive, and have minimal impact on performance.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Testing schedules will be planned and communicated to you least 24 hours prior to initial testing.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>Upon request by you, VIPRE will disclose actual tools used in the penetration testing activity and audit functions.&nbsp;<\/li>\n<\/ul>\n\n<ul>\n<li>VIPRE will deliver all deliverables through agreed channels of communication.&nbsp;<\/li>\n<\/ul>\n\n<p><strong>Table 4: Responsibility Matrix<\/strong>&nbsp;<\/p>\n<div class='media-elements bs-media-element---default enable'>    <div class='bs-common-image'>\n                            <figure class='figure justify-content-start d-flex'>\n                            <picture>\n                            <source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-4bc.jpeg\" media=\"(max-width:575px)\"><source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-4bc.jpeg\" media=\"(max-width:1280px)\">\n                            <img src='https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/06\/statement-of-work-pen-testing-figure-4bc1.png' class='img-fluid' alt='' title=''  \/>\n                            <\/picture>\n                                \n                            <\/figure>\n                        <\/div><\/div>\n<p><\/p>\n      <\/div>  <\/div><\/div><div class=\"card\">  <button class=\"card-header accordion__block__btn expand-fixed\" id=\"panel_6fab03c45140_header\"\n        data-toggle=\"collapse\"\n        data-target=\"#panel_6fab03c45140\"\n        aria-expanded=\"false\"\n        aria-controls=\"panel_6fab03c45140\" role=\"button\" aria-role=\"button\"><span><strong>9. Appendix A. Summary of Enterprise Security Assessment Activities &amp; Tools<\/strong><\/button><div\n                    id=\"panel_6fab03c45140\"\n                    class=\"collapse  expand-fixed\"\n                    \n                    data-parent=\"#accordion_26655e1ad65b\"\n                ><div class=\"card-body\">\n<p>VIPRE offensive security teams use the tools listed below (in Table 5) for application and network VAPT (VIPRE may use additional tools not listed below).&nbsp;<\/p>\n\n<p><strong>Table 5: Summary of Application &amp; Network VAPT with Tools<\/strong>&nbsp;<\/p>\n<div class='media-elements bs-media-element---default enable'>    <div class='bs-common-image'>\n                            <figure class='figure justify-content-start d-flex'>\n                            <picture>\n                            <source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-4a.png\" media=\"(max-width:575px)\"><source srcset=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-4a.png\" media=\"(max-width:1280px)\">\n                            <img src='https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2025\/05\/statement-of-work-pen-testing-figure-4a.png' class='img-fluid' alt='' title=''  \/>\n                            <\/picture>\n                                \n                            <\/figure>\n                        <\/div><\/div>      <\/div>  <\/div><\/div>      <\/div>  <\/div><\/div><\/div>\n<\/div>\n<\/div><\/section>","protected":false},"excerpt":{"rendered":"<p>VIPRE Vulnerability and Penetration Testing Services SOW<\/p>","protected":false},"author":45,"featured_media":0,"parent":27171,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"show_custom_date":false,"custom_date":"","featured":false,"featured_image":0,"learn_more_label":"","image_alt_text":"","learn_more_type":"","learn_more_link":[],"show_popup":false,"learn_more_link_file":0,"event_date":false,"event_start_date":"","event_end_date":"","om_disable_all_campaigns":false,"inline_featured_image":false,"footnotes":""},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.4 (Yoast SEO v23.4) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Statement of Work for VIPRE Vulnerability and Penetration Testing Services - VIPRE<\/title>\n<meta name=\"description\" content=\"Statement of Work for VIPRE Vulnerability and Penetration Testing Services\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/\" \/>\n<meta property=\"og:locale\" content=\"nl_NL\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Statement of Work for VIPRE Vulnerability and Penetration Testing Services\" \/>\n<meta property=\"og:description\" content=\"Statement of Work for VIPRE Vulnerability and Penetration Testing Services\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/\" \/>\n<meta property=\"og:site_name\" content=\"VIPRE\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-16T20:43:23+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@VIPRESecurity\" \/>\n<meta name=\"twitter:label1\" content=\"Geschatte leestijd\" \/>\n\t<meta name=\"twitter:data1\" content=\"18 minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/\",\"url\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/\",\"name\":\"Statement of Work for VIPRE Vulnerability and Penetration Testing Services - VIPRE\",\"isPartOf\":{\"@id\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#website\"},\"datePublished\":\"2025-05-02T15:40:53+00:00\",\"dateModified\":\"2025-06-16T20:43:23+00:00\",\"description\":\"Statement of Work for VIPRE Vulnerability and Penetration Testing Services\",\"breadcrumb\":{\"@id\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/#breadcrumb\"},\"inLanguage\":\"nl-NL\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"About Us\",\"item\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/about-vipre\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"List of Legal Agreements\",\"item\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/about-vipre\/legal\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Statement of Work for VIPRE Vulnerability and Penetration Testing Services\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#website\",\"url\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/\",\"name\":\"VIPRE Security Group\",\"description\":\"Antivirus Protection for Home and Business\",\"publisher\":{\"@id\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"nl-NL\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#organization\",\"name\":\"VIPRE Security Group\",\"alternateName\":\"VIPRE\",\"url\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"nl-NL\",\"@id\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2022\/08\/VIPRE_HeaderLogo.svg\",\"contentUrl\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2022\/08\/VIPRE_HeaderLogo.svg\",\"width\":213,\"height\":39,\"caption\":\"VIPRE Security Group\"},\"image\":{\"@id\":\"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/VIPRESecurity\",\"https:\/\/www.linkedin.com\/company\/vipresecurity\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Statement of Work for VIPRE Vulnerability and Penetration Testing Services - VIPRE","description":"Statement of Work for VIPRE Vulnerability and Penetration Testing Services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/","og_locale":"nl_NL","og_type":"article","og_title":"Statement of Work for VIPRE Vulnerability and Penetration Testing Services","og_description":"Statement of Work for VIPRE Vulnerability and Penetration Testing Services","og_url":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/","og_site_name":"VIPRE","article_modified_time":"2025-06-16T20:43:23+00:00","twitter_card":"summary_large_image","twitter_site":"@VIPRESecurity","twitter_misc":{"Geschatte leestijd":"18 minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/","url":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/","name":"Statement of Work for VIPRE Vulnerability and Penetration Testing Services - VIPRE","isPartOf":{"@id":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#website"},"datePublished":"2025-05-02T15:40:53+00:00","dateModified":"2025-06-16T20:43:23+00:00","description":"Statement of Work for VIPRE Vulnerability and Penetration Testing Services","breadcrumb":{"@id":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/#breadcrumb"},"inLanguage":"nl-NL","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/about-vipre\/legal\/sow-vipre-vulnerability-and-penetration-testing-services\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/"},{"@type":"ListItem","position":2,"name":"About Us","item":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/about-vipre\/"},{"@type":"ListItem","position":3,"name":"List of Legal Agreements","item":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/about-vipre\/legal\/"},{"@type":"ListItem","position":4,"name":"Statement of Work for VIPRE Vulnerability and Penetration Testing Services"}]},{"@type":"WebSite","@id":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#website","url":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/","name":"VIPRE Security Group","description":"Antivirus Protection for Home and Business","publisher":{"@id":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"nl-NL"},{"@type":"Organization","@id":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#organization","name":"VIPRE Security Group","alternateName":"VIPRE","url":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/","logo":{"@type":"ImageObject","inLanguage":"nl-NL","@id":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#\/schema\/logo\/image\/","url":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2022\/08\/VIPRE_HeaderLogo.svg","contentUrl":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/wp-content\/uploads\/2022\/08\/VIPRE_HeaderLogo.svg","width":213,"height":39,"caption":"VIPRE Security Group"},"image":{"@id":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/VIPRESecurity","https:\/\/www.linkedin.com\/company\/vipresecurity"]}]}},"_links":{"self":[{"href":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/wp-json\/wp\/v2\/pages\/33292"}],"collection":[{"href":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/wp-json\/wp\/v2\/users\/45"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/wp-json\/wp\/v2\/comments?post=33292"}],"version-history":[{"count":5,"href":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/wp-json\/wp\/v2\/pages\/33292\/revisions"}],"predecessor-version":[{"id":33984,"href":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/wp-json\/wp\/v2\/pages\/33292\/revisions\/33984"}],"up":[{"embeddable":true,"href":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/wp-json\/wp\/v2\/pages\/27171"}],"wp:attachment":[{"href":"https:\/\/wordpress-776622-2794197.cloudwaysapps.com\/nl\/wp-json\/wp\/v2\/media?parent=33292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}