| Risk management services
Developed initially as the necessary backup
for creation of a general security system, later they became necessary
instruments for a constant assessment in time of the levels of general
security of the company network.
That is because they are services that, combined with the professional
capabilities of Audemars, are a fundamental tool for restructuring
or implementing all aspects of network security.
Thanks to these services it is possible to obtain every sort of
information about the weak points in the company's security system
and develop the methods to strengthen them.
Threat Analysis
This service is performed on a maximum of
one or two machines and indicates the number of risks to which the
system is exposed. This type of analysis is performed free of charge
when a project of network security is requested of Audemars.
Vulnerability Analysis
At this level, in addition to the previous
test, the service identifies the level of vulnerability associated
with every risk detected. A document written by technical personnel
will summarize the results of the test and provide a detailed interpretation
of the levels of vulnerability found.
Countermeasures Selection
This is the most complete level of evaluation
obtainable with the series of Risk Management services.It departs
from the results of the two previous services to supply guidelines
and technical recommendations as to the countermeasures necessary
to overcome the vulnerability detected on the network.
Social Engineering
The highest level of vulnerability in the
network is that of the company personnel. The service of Social
Engineering has the precise purpose of understanding, through simulations
of attacks of this type, the level of instruction of the personnel
with regard to company security.
Business Continuity Plan
As its name suggests, this means drawing
up a definite, specific security plan. Its purpose is to enable
the company to continue the operations necessary for maintenance
and growth of its business under any type of critical conditions,
from a simple attack to damage of its information structure. A project
of this kind includes, in addition to all the previous services,
also a restructuring and expansion of all the internal procedures,
an evaluation of the company systems (such as its fire prevention
system, alarm system, wiring system) and a period of regularization
to comply with legal and technical standards.
Value Analysis
This service makes it possible to assign
the percentage of turnover generated by a specific device and, analyzing
the data deriving from the previous services, is able to provide
a cost/value analysis relative to the countermeasures to be implemented.
In practice, with this service it is possible to determine the percentage
of the turnover connected to a given server, and calculate the potential
economic damage due to damage to the server and the cost of implementing
the necessary countermeasure.
Services from outside the network
All these services, except Threat Analysis
and the Business Continuity Plan, can also be performed from outside
the network. They are based on the simulation of the behavior of
a hacker and are mainly directed towards the machines exposed to
Internet such as firewall, web server and mail server.
|