ETS Comprehensive Security Audit 1. Assess current business operations Examine existing hardware and software infrastructure such as PCs, servers, routers, wireless, operating system, firewalls, antivirus, etc. Assess current security policies such as passwords, user accounts, etc. Review current procedures such as data backup and restore Inspect physical environment, office entrance/exit, locks and location Deliverable: Written assessment detailing your entire infrastructure with technology recommendations for improvement (customizable). 2. Identify vulnerabilities and associated risks Here are a few considerations: Is your anti-virus up-to-date with the latest virus definitions? Do you travel with your laptop? Do you use a firewall utility? Is it configured properly? Are you using a wireless connection? Is security enabled? Does your Windows operating system have all the security service packs & hot fixes applied? Do you have a current data backup system in place? Is your network firewall configured properly and doing its job? How do you know? What user access controls are implemented on your network? Is your server virus protection implemented and current? Are password policies enforced throughout your organization? Deliverable: Meticulous report designed to inform you of your vulnerabilities and your current level of risk. 3. Improve security and reduce the risks Here are some examples: Install and regulate the appropriate security measures through PC and network configuration. Initiate policies such as user access controls and strong passwords. Implement a security maintenance program - keeping your protection up-to-date. Create a disaster recovery plan and conduct periodic testing. Keep current documentation as to what safeguards are in place. Provide user awareness by periodically training users on proper security practices. Deliverable: A comprehensive report outlining the three parts to implementing a successful security plan: Part 1. Immediate plan of action needed to install appropriate security measures. Part 2. Periodic maintenance program designed to continually protect. Part 3. Ongoing security awareness training for all employees. At ETS we believe an effective security plan is a customized, all encompassing security plan. Contact the ETS professionals today for your custom security audit! (back to top) |