|
SOLUTIONS & SERVICES
Would you like further info? Feel free to Contact Us
|
Security Solutions - CORPORATE SECURITY AUDIT SERVICES
In order to make the auditing a successful one, it is crucial for us to have the full cooperation of the organization being assessed. The organization grants access to its facilities, provides network access, outlines detailed information about the network, etc. All parties understand that the goal is to study security and identify improvements to secure the systems.
The following methodology outline is put forward as the effective means in conducting security assessment.
| |
 |
Requirement Study and Situation Analysis |
| |
 |
Document Review |
| |
 |
Risk Identification |
| |
 |
Vulnerability Scan |
| |
 |
Data Analysis |
| |
 |
Report & Briefing |
After the assessment, our team will generate a audit report based on following information:
| |
 |
Introduction/background information |
| |
 |
Executive and Management summary |
| |
 |
Assessment scope and objectives |
| |
 |
Assumptions and limitations |
| |
 |
Methods and assessment tools used |
| |
 |
Current environment or system description with network diagrams |
| |
 |
Security requirements |
| |
 |
Summary of findings and recommendations |
| |
 |
The general control review result |
| |
 |
The vulnerability test results |
| |
 |
Risk assessment results including identified assets, threats, vulnerabilities, impact and likelihood assessment, and the risk results analysis |
| |
 |
Recommended safeguards |
IT security risk assessments like many risk assessments in IT, are not actually quantitative and do not represent risk in any actuarially-sound manner. Measuring risk quantitatively can have a significant impact on prioritizing risks and getting investment approval (Doug Hubbard Hurdling Risk, CIO Magazine 1998).
|
 |