|
bIT360's security auditing and consulting services are suitable for any organization that needs
independent validation of its data security infrastructure and practices. Our certified consultants
also have experience in auditing and validating regulatory compliance requirements. These services
are focused on small to mid-size growing organizations that do not have in-house security functions.
It is our commitment to identify the vulnerabilities in your IT capabilities, prepare a remedy plan
for you, and implement and manage it for you. If your organization is already exposed to some
vulnerability, we can always assist you on short notice and in emergency needs.
Security audits are performed in many phases which can be mixed and matched to meet any organization's
specific security audit needs. The following general areas are evaluated during audit phases:
Domain Controllers
Physical access to computing equipment and facilities
Firewall configuration and policies
Router configuration and policies
Wireless access methods, practices, and policies
VPN and dial-up security policies
WAN Links
Server Operating Systems and user policies
Workstation operating systems and data policies
Patch management practices
Backup strategies and business continuance plans
Tape management practices
Laptop usage and network access policies
Virus protection management practices
Spyware/Malware avoidance management policies
Intrusion detection mechanisms and strategies
Password and other first or second level security policies
Directory access policies
Network authentication policies
Vendor access policies
Equipment disposal policies
Web usage policies
E-mail usage policies
Change management policies
The security audit services do not include review of application or website security policies and practices. However, these services could be provided as a separate consulting service on an individually needed basis. All identified vulnerabilities are detailed in our findings and matched against the current industry best practices.
As an option, we also offer to create a remediation plan for each of the identified vulnerabilities. In addition, we offer vendor negotiation, project management, and implementation services. Services to perform periodic follow-up reviews, identify any new threats as well as compliance with the recommended policies are also offered as an option.
Lastly, we offer another service to review our client's Internet usage to ensure that their HR policies are being followed completely. The service also identifies exposure to potential legal liability issues if the policies are not followed by the employees completely. This service can passively review all web and non-web protocol usage by a user and categorize it by destination as business related, loss of productivity, legal liability, etc.
You can now have a high caliber IT security department at your disposal whenever and wherever you need it, without the overhead of actually having one.
|