Security audits involve a set of periodic, pro-active compliance and
assurance activities that help assess the security of the IT
infrastructure of your organization. They encompass security architecture,
policy and vulnerability assessment
SECURITY ARCHITECTURE
AUDIT SERVICE An audit of this nature is typically carried out at the
enterprise IT organization level and its objective is to assess the IT
infrastructure in the context of security and availability. The elements
covered in this service are · Network devices like firewalls,
Intrusion detection systems, VPN etc DELIVERABLES ·
Analysis of gaps in existing IT network infrastructure
VULNERABILITY ASSESSMENT SERVICES This assessment service
determines the nature of security vulnerabilities which exist on the
network as well as hosts, and methods of mitigation. The vulnerability
assessment covers network equipment like routers, switches, firewalls etc.
and Operating systems like Windows NT, Solaris and Linux. This activity is
usually performed by executing tool-based scans on network and hosts
within the client's internal network. Keystone also provides an
External Penetration testing Service. The objective is to assess the
security posture of Critical Internet facing equipment. This activity is
usually performed by executing tool-based scans on network and hosts that
are visible on the Internet. Deliverables ·
Vulnerabilities on each network device and host · Recommendations to
identify the right safeguards plus findings and specific recommendations
for each system |