HOST SECURITY AUDIT
> OBJECTIVES
Control the security configuration of a technical asset
> METHODOLOGY
The host security audit service is done by analysing the security related configuration of an asset. This differs of the Security assessment and penetration testing by the fact that the auditor has a direct and complete access to the host to be analysed.
The security analysis of a system or an application can be divided in the following categories :
- Baseline security : analysis of the security context of the host
- Data repository security : how secured are stored the data
- Data exchange security : how are secured the communication to/from the host
- Operating system security : specific security configuration of the OS
- Authentication security : how does people interacting with the assets are authenticated
- Logging capabilities : does the system allows a logging that could be used to trace an incident
> BENEFITS
This is the most complete possible view of the security of an asset.
|