|
System
System Security Assessment
As your IT infrastructure has changed and grown to meet the needs of your organization,
chances are the responsibilities for security management of each system platform have been
distributed to personnel who may not be full time security professionals. In addition, your
organization is probably dependent on a variety of sophisticated, add-on "middleware"
components such as comprehensive office solutions from LotusTM or Microsoft®, data base
servers, file and print servers, and application servers. These components typically require
security management actions that are independent of the operating system platforms on which
they operate.
SSG's System Security Assessment can help you identify vulnerabilities on your key,
internal operating system platforms, such as UNIX®, Windows/NTTM, etc.) and most core
"middleware" components (such as Microsoft ExchangeTM, Lotus Notes®, DB2, CICS, MQ Series,
Sybase, DCE, Netware, CORBA, TivoliTM, etc. Both technology and management controls are
reviewed.
The technology review assesses each component's mechanisms for identification and
authentication, access control, confidentiality, integrity, non-repudiation, audit and
alert in the context of your organization's documented policies, standards and processes.
The management review consists of interviews with administrators and management and reviews
of documented security policies, standards and processes related to the components included
in the scope of the review.
|
This provides you with insight into how your organization is prepared to handle the
security responsibilities of your infrastructure over time against potential threats from
insiders or outsiders who get through your external security controls.
Range of Services
- review of the configuration files for each operating system and middleware component
within the scope of the project to determine how each effectively allows authorized
users access based on your security policy and prevents and detects unauthorized
access attempts at all times
- comprehensive review of the security management controls for the included components
covering:
- policy
- organization
- personnel
- asset classification and control
- physical security
- access control
- network and computer management
- business continuity
- system development and maintenance
- compliance
- report describing the strengths and weaknesses found in all of the above activities
with recommendations for short and long term improvements
|