An in-depth IT system audit or IT system security review can be performed on an individual system or database to identify risks and points of exposure.
IT system audits focus on security controls over physical and logical security of the server, including change control, administration of server accounts, system logging and monitoring, incident handling, system backup and disaster recovery.
The system or application will be reviewed against vendor recommendation and industry best practices, in addition to recommendations by our IT audit specialists.
Our Security Review is designed to assess the key aspects of your IT security related infrastructure, processes and technical management capabilities, and balance these against the cyber threats that are most relevant to your business.
Our aim is to help you understand your current situation, and come up with pragmatic strategy and set of improvements that directly relate to your current risk of a serious cyber security breach.
An IT system audit or security review can be performed on a variety of systems and services:
- Windows & Active Directory Security Assessment
Active Directory plays a critical role in the IT infrastructure, and ensures the harmony and security of different network resources in a global, interconnected environment.
Our approach balances the use of Microsoft-branded solutions, open-source technology, and third-party tools.
At ADVANCED ICT Consultants & Auditors LLP, we pride ourselves on our broad range of expertise, which combines deep Microsoft experience with a broad understanding of other technologies and environments, such as networking, Linux, and Citrix.
Our engineers are particularly strong at tackling problems in heterogeneous environments that combine different technologies and require different IT skill sets. So if your organization is experiencing finger-pointing between different IT groups, we can help by identifying and resolving the root cause of your Windows or Active Directory issues.
- UNIX Security Assessment
Our team of experienced consultants will review your AIX, Linux, Solaris environments end to end covering both Desktops and Servers.
We conduct detailed, platform-specific and/or “flavor”-specific review of the configuration of UNIX/Linux servers to verify that these systems are configured to maximize security and minimize exposure to cyber-attacks.
Our certified engineers or consultants review system configuration files and settings, running processes, and installed packages to identify opportunities to improve security, in line with best-practices.
Systems are inspected for evidence of rootkits and malware.
Recommendations are provided for enhancing security.
Review Highlights
- Credentialed review of UNIX/Linux systems
- Network-based testing
- Automated scoring of configuration files and settings
- Manual review of tool results and configurations
- Review of installed packages and running processes
- Rootkit/malware searches
- Comparison against best-practices
- Classification of severity of findings
- Remediation recommendations
- Database Security Assessment
- Oracle
- Microsoft SQL Server
- MySQL
- IBM DB2
- REDIS
- PostgreSQL
- Maria DB
- Apache Cassandra
- ElasticSearch
- Informix
- Mongo DB
- Network
- Firewalls
- Network Intrusion Detections Systems (NIDS)
- Demilitarized Zones - DMZ Zones
- Load Balancers
- Proxies
- Gateways
- Virtual Private Networks (VPNs)
- Host Intrusion Detections Systems (HIDS)
- Application Performance Monitoring (APM)
- End User Monitoring (EUM)
- Synthentic Monitoring
- Application Servers
- Webservers