|
Network Security Assessments

Solution Strategy Our network security assessment strategy rests on basic requirements for system and network security. There are certain characteristics that the network should possess: Security Policy. Networks should have an associated defined security policy that specifies information security requirements (e.g., confidentiality, integrity, availability, auditing, access control, etc.) as well as what users may and may not do on the network (e.g., what constitutes unauthorized and illegal activities). Network Management. Networks should be able to control access to and detect modifications of critical components. Networks must maintain control over their configuration (e.g., hardware, software, security, etc.) and connectivity. Identification and Authentication. Networks should provide and manage identification and authentication functions. Resources Management. Networks should provide and manage confidentiality, integrity, access control, and availability of network resources. Account Management. Networks should provide and manage security-related features of network accounts (e.g., user). Our primary focus for the network security assessment is identifying network vulnerabilities that an active hostile human threat might exploit. Although our assessment identifies both technical and non-technical weaknesses (e.g. procedural deficiencies), our assessment is focused on an in-depth analysis of technical vulnerabilities. Our solution includes --
Identifying and reporting network security weaknesses, Providing the client information about the weakness, Helping validate that the weakness is a vulnerability the client wants to fix, Assisting in identifying measures to eliminate or mitigate the vulnerability, and Validating that the vulnerability is eliminated or mitigated.
Solution Overview Depending on the client's needs, a network security assessment may be a snapshot of a network at a point in time or it may be a continuous process. We can provide a single assessment over a set time (e.g. a few weeks). We also provide a continuous service over months or years that includes intrusion detection, monitoring, continuous assessments of network components (e.g., on a regular schedule), and periodic site assessments (e.g., quarterly or annually). A complete assessment using all processes helps the client establish the "security baseline" for the network. Continuous assessment helps the client maintain and improve this "security baseline."
Contact More Power Computers today to learn more about our Network Security Assessment solutions.
|