Skip to main content

techsiagus.com

Security Audits & Assessments

Infrastructure audit and assessment against company security policy and compliance requirements, typically using frameworks such as ISO 27001 or NIST.

Typical engagement15 days for assessment plus one week for reporting.

The problem

What usually brings people to this.

  • Cyber security incidents and anomalies
  • Security configuration issues
  • Poor compliance status
What we do

Audit against your security policy and your compliance obligations

We audit the IT estate against your own security policy and against the compliance framework you are held to. The result is the paperwork an auditor recognises — non-conformities, a corrective action plan, opportunities for improvement and a management review report — backed by technical evidence rather than a questionnaire.

  • 01

    Network infrastructure audit

    Audit and assessment of network infrastructure and its controls.

  • 02

    Server infrastructure audit

    Audit and assessment across server infrastructure.

  • 03

    Endpoint security audit

    Audit and assessment of endpoint security coverage and configuration.

  • 04

    Cloud security audit

    Security audit and assessment of cloud infrastructure.

Methodology

How the engagement runs.

A defined sequence, so you know what is happening at any point and what comes out of each stage.

  1. 01

    Define audit objectives and scope

    Fix the boundaries and the pass criteria up front.

    • Set objectives
    • Identify scope
    • Set criteria
  2. 02

    Review documentation

    Establish what the organisation says it does.

    • Collect security policies
    • Systems documentation
    • Compliance documentation
  3. 03

    Assess current security controls

    Establish what the organisation actually does.

    • Network security
    • Endpoint security
    • Application security
  4. 04

    Conduct vulnerability assessment

    Technical verification of the control set.

    • Vulnerability scanning
    • Penetration testing (optional)
  5. 05

    Evaluate compliance with standards

    Measure the gap against the framework.

    • Gap analysis
    • Access control review
  6. 06

    Documentation and reporting

    Produce findings that can be actioned and audited.

    • Detailed findings report
    • Risk ratings
    • Remediation plans
Typical duration 15 days for assessment and one week for reporting.
Deliverables

What you receive.

  • 01List of non-conformities (NCs)
  • 02Corrective action plan (CAP)
  • 03Observations and opportunities for improvement (OFIs)
  • 04Compliance status
  • 05Management review report
Outcome

What changes afterwards.

  • Improved compliance posture
  • Improved security posture
  • Strategic alignment with the business
  • Improved user experience

Technologies and frameworks in scope

  • ISO 27001
  • NIST

Talk to us about security audits & assessments.

Describe the estate and the constraint you are working within. We will tell you what the engagement would actually involve.

Questions

Before you get in touch.

Is this the same as a penetration test?

No — a penetration test simulates exploitation of a defined scope. This audits the estate against your own security policy and your compliance framework, producing the paperwork an auditor recognises.

What does the output actually include?

A list of non-conformities, a corrective action plan, observations and opportunities for improvement, a compliance status, and a management review report — backed by technical evidence.

Which frameworks do you audit against?

ISO 27001 and NIST, typically — or your own security policy directly.

How long does an audit take?

15 days for assessment plus one week for reporting.