Critical Asset Security Assessment CONSULTANTS EXPERTS PROFESSIONALS

Protecting the information assets that are most important to you is a fundamental principle of effective cyber security. But how do you know which are your most important information assets, and how do you protect them sufficiently, given the threats they face? This is where effective Information Risk Assessment comes in.
Internal vulnerability assessment, manual validation and penetration testing of mission-critical assets including applications, servers, routers, and switches for validation of layered-security and defense in depth. Testing is performed inside the network perimeter, behind firewalls, for unfiltered results. The assessment tests susceptibility to attack propagation should perimeter defenses be breached. Scope includes internal-only systems, as well as Internet-facing (DMZ) critical assets but in this case analyzed from within the network.

Performing cybersecurity risk assessments is a key part of any organization’s information security management program. Everyone knows that there’s some level of risk involved when it comes to a company’s critical and secure data, information assets, and facilities. But how do you quantify and prepare for this cyber security risk? The purpose of an IT security risk assessment is to determine what security risks are posed to your company’s critical assets and to know how much funding and effort should be used in the protection of them.

Our professionals will help you implement effective information risk assessment, for example by:

  • Helping you identify the information assets that are most important to you
  • Evaluating your current approach to risk assessment and making recommendations for improvement
  • Conducting information risk assessments on your behalf, and developing an action plan to plug gaps identified
  • Undertaking an in-depth assessment of your most mission-critical information asset/s, and identifying the additional levels of security you'll need to apply in order to protect them.

Specific Areas of focus in our Assessment

  • Scanning to create a baseline of vulnerabilities and security risks
  • Best-of-breed open source and commercial vulnerability harvesting tools
  • Manual testing to find additional vulnerabilities not found by scanning tools
  • Penetration testing through custom-designed and pre-existing exploits to test real severity
  • Classification of severity of findings
  • Remediation recommendations
  • Benchmark analysis of results vs industry

Assessment Targets

Networks, systems, applications, services, ports, protocols from within firewalls boundaries – unfiltered analysis:

  • Web sites and web applications and Intranet Sites
  • Web applications (non-credentialed testing)
  • Firewalls, routers and load balancers
  • Internal routers
  • 100,000+ known vulnerabilities, unique vulnerabilities from custom designs, configurations and software
ADVANCED ICT » Consultants and Auditors LLP.