IT audit
A sound assessment of your resources
An information security audit gives an objective measure of how effective an organisation's efforts and controls really are. It confirms that the principal risks are identified, monitored and controlled.
What we deliver
Assessment of existing assets, procedures, policies and how they interact
Whether the IT infrastructure meets business needs and serves every process in the company
Whether all IT risks are adequately managed
Cost efficiency of the IT equipment
Execution
- Assessment of how effective the deployed information security controls are
- Assessment of communications and network security
- Assessment of service providers
- Assessment of applications in use and their licence compliance
- Assessment of database security
- Assessment of servers and the services they provide
- Analysis of endpoint and workstation security mechanisms
- Vulnerability scanning of internet-facing systems and applications
Reporting and recommendations
The audit concludes with a complete report covering every finding. The final report identifies weaknesses and the risks arising from them, with a detailed account of the conclusions for each system. Alongside it we set out recommendations for improving security and optimising the information environment.
Security levels are also assessed through penetration testing — either as part of the report or as part of a regular review programme under ISO 27001, PCI-DSS or GDPR.