
|
|
![]() Specific Security AssessmentsWith hackers and criminals continuing their assault on the financial and personal data stored by commercial businesses and organizations, you need to be sure that your IT security is as tight as possible. And with federal and state regulations for protecting data increasing, the penalties for poor security are getting tougher. So it pays to ensure that your IT security controls are adequate. C5i can help you verify that your IT controls are sufficiently protecting your data and systems. C5i testers and auditors can evaluate specific areas of your IT security program and identify any areas of weaknesses - before they're exploited by hackers or discovered by auditors. As part of C5i's Individual Security Tests prorgam, consultants can perform a general risk assessment or specific assessments that focus on one particular area of need, such as:
Network Security AssessmentsTo help organizations proactively manage risk in the context of their overall goals of protecting their information assets and reputation, C5i maintains a world-class Security Health Center focused on the development and delivery of Network Security Assessment services. These services focus on identifying vulnerabilities throughout the organizations network, including servers, workstations, network devices, and software applications. C5i Network Security Assessments include two main types of evaluations, ranging from broad-view to more narrowly focused assessments of your network security:
All of C5i's Network Security Assessments can be performed as either a full-scale vulnerability assessment or a simple ethical hack/penetration test. C5i offers three basic types of Network Security Assessments: Application Security AssessmentC5i's Application Security Assessment can occur at any point in your application's life-cycle, and includes application design analysis, code review, and application security testing and analysis. Wireless Security AssessmentC5i's Wireless Security Assessment includes the evaluation of your wireless network architecture, access point configuration (war-driving), and encryption technologies. It can also include an optional review of your wireless security policies to ensure that your company understands the security implications and weaknesses of wireless networks and technology. Physical Security AssessmentC5i can help minimize your risks by assessing your infrastructure vulnerabilities and recommending solutions that will ensure the security and continuity of your business. C5i's Physical Security Assessment team will critically examine your facilities, systems, and high-value assets; give you a detailed risk assessment based on your business requirements; and provide recommendations for enhancing security and managing your risks. Physical security assessments include evaluations of security requirements, including policies and procedures, personnel response, mechanical and electronic security measures, access control, use of video surveillance systems, alarm systems and other measures necessary to ensure detection, assessment, response, delay, and neutralization of potential adversaries. The physical security assessment then evaluates the actual physical controls in place, comparing them to your requirements and policies as well as industry best practices. Vulnerabilities and associated risks are identified, and countermeasures are recommended. C5i can also assist property owners, property managers, and architectural and engineering firms in defining physical security requirements and specifying physical security solutions. Call today for more information about how C5i can provide a customized implementation plan to address physical security needs. A Proactive Approach (the best defense is a good offense) Security Architecture EvaluationsThe Security Architecture Review process focuses on reviewing the infrastructure and application security architecture, as well as testing and verifying application, network, and security system configurations. C5i's security consultants will examine the design and architecture of the infrastructure in order to determine how it handles sensitive data and compare it to internal policies and enterprise architecture standards as well as best practices. The review usually includes the security posture of front-end web servers, application software, application servers, supporting database servers, and interfaces to other back-end systems. It focuses on the architecture, design, and configuration of mission-critical IT components, such as firewalls and perimeter defense, servers, VPNs and PBXs, network devices, intrusion detection systems, and audit/alerting mechanisms. It evaluates the balance between security and functional needs. Security Program EvaluationsThe C5i security consultants will conduct an in-depth review of your information security program in order to assess the organizational, personnel, process and technical dimensions of your company's security posture. C5i uses a structured process for reviewing information security programs, which focuses on reviewing existing data security policies, procedures, standards and guidelines; interviewing knowledgeable staff; and directly observing critical program areas. |