What usually brings people to this.
- Cyber security incidents and anomalies
- Security configuration issues
- Poor compliance status
Audit against your security policy and your compliance obligations
We audit the IT estate against your own security policy and against the compliance framework you are held to. The result is the paperwork an auditor recognises — non-conformities, a corrective action plan, opportunities for improvement and a management review report — backed by technical evidence rather than a questionnaire.
-
01
Network infrastructure audit
Audit and assessment of network infrastructure and its controls.
-
02
Server infrastructure audit
Audit and assessment across server infrastructure.
-
03
Endpoint security audit
Audit and assessment of endpoint security coverage and configuration.
-
04
Cloud security audit
Security audit and assessment of cloud infrastructure.
How the engagement runs.
A defined sequence, so you know what is happening at any point and what comes out of each stage.
-
01
Define audit objectives and scope
Fix the boundaries and the pass criteria up front.
- Set objectives
- Identify scope
- Set criteria
-
02
Review documentation
Establish what the organisation says it does.
- Collect security policies
- Systems documentation
- Compliance documentation
-
03
Assess current security controls
Establish what the organisation actually does.
- Network security
- Endpoint security
- Application security
-
04
Conduct vulnerability assessment
Technical verification of the control set.
- Vulnerability scanning
- Penetration testing (optional)
-
05
Evaluate compliance with standards
Measure the gap against the framework.
- Gap analysis
- Access control review
-
06
Documentation and reporting
Produce findings that can be actioned and audited.
- Detailed findings report
- Risk ratings
- Remediation plans
What you receive.
- 01List of non-conformities (NCs)
- 02Corrective action plan (CAP)
- 03Observations and opportunities for improvement (OFIs)
- 04Compliance status
- 05Management review report
What changes afterwards.
- Improved compliance posture
- Improved security posture
- Strategic alignment with the business
- Improved user experience
Technologies and frameworks in scope
- ISO 27001
- NIST
Before you get in touch.
Is this the same as a penetration test?
No — a penetration test simulates exploitation of a defined scope. This audits the estate against your own security policy and your compliance framework, producing the paperwork an auditor recognises.
What does the output actually include?
A list of non-conformities, a corrective action plan, observations and opportunities for improvement, a compliance status, and a management review report — backed by technical evidence.
Which frameworks do you audit against?
ISO 27001 and NIST, typically — or your own security policy directly.
How long does an audit take?
15 days for assessment plus one week for reporting.