"The Current State Analysis -project performed by Nixu gave us concrete results on the security state of our organization and identified critical areas in the need of development", Anonymous Customer.

Security Management Audits

We deliver comprehensive Security Audit Services which are based on highly developed methods and an expert auditor team. Our auditors are skilful, experienced, security management professionals and also proficient IT-professionals. We provide both small-scale, focused projects and large enterprise-class security audits.

We also provide Security Management Consulting services that enable effective security development at all organization business levels.

Our modular audit process enables effective work flow and provides development tools for our customers

Modular Methodology

Our audit process provides methods for information security auditing, risk assessment, control selection, gap analysis, benchmarking and security development. Security auditing reveals security weaknesses and strengths in the customer's business environment through risk assessment and analysis where the risk is calculated from weakness realization probability and business impact. Furthermore, the security posture of the customer is benchmarked against similar business cases in the same industry. Finally, applicable and effective security controls are proposed to mitigate the risks.

The standardized, modular structure of our audit process enables our customers to benefit from an effective audit service, where modules are chosen based on the customer business environment and architecture. Our process for audit work includes meetings, workshops and interviews, which are used for collecting all information required for a comprehensive end result.

Security Audit Services

Some of our audit services to help you assess your infrastructure security:

Current State Analysis

To effectively manage organization security, the state, level and adequacy of security measures must be comprehensively known. This enables to focus enhancement resources to the most critical areas. Our Current State Analysis provides detailed insight to understanding the organization security state. The development plan provides a cost-effective improvement roadmap and benchmarking provides a measure to industry related companies.

Compliance Audits

Companies face mandatory security demands to be able to conduct their core business. Regulatory demands such as SOX and Emergency Power Acts, and business demands such as PCI DSS, must be fulfilled. Furthermore, customers demand adequate security practices from their vendors and partners. We can effectively assess the compliance of your business using the most recognized security standards and provide effective compliance development gap analysis and roadmap.

Risk Analysis and Assessment

We deliver quality risk assessment and analysis services, which provide our customers with effective methods for comprehensively analyzing the most serious risks in their organization. Our Risk Analysis and Assessment methods are based on ISO27001 and COBIT standards and provide detailed analysis of threats, risk exposure, benchmark results and plan for managing the observed information risks.

Security Policy and Process Audits

Security policy defines the company-wide security requirements of the top management and vital stakeholders. To be effective company security policy must be implemented and materialized through uniforming operational level day-to-day practices, processes and procedures. We can audit the service development and day-to-day practices to ensure that service architecture is developed and maintained securely and effectively.

Service Operation and Maintenance Audits

A company's heterogeneous infrastructure contains various critical services and systems which must be consistently developed, maintained and secured. Compromise could mean serious business impact through customer and profit loss. We provide effective audit services to help you assess the service maintenance and operation procedures, which ensure the service and system service level and comprehensive protection.

Please Contact our Sales department for further information.

We deliver

Advanced audit methods based on international security standards such as ISO27001, COBIT and PCI DSS

Comprehensive audit results provided by our experienced, expertise consultants

Modular methodology which provides effective project models and matches the process to the customer business

Development plan and roadmap as a deliverable to enable customer security development and ROI justification

Terminology

PCI DSS
Payment Card Industry Data Security Standard
COBIT
ISACA's Control Objectives for Information and related Technology
ISO27001
Information Security Management System (ISMS) specification (former BS7799-2)
SOX
Sarbanes-Oxley Act, administered by the Securities and Exchange Commission (SEC)
PKI
Public Key Infrastructure
AAA
Authentication, authorization, and accounting
IDS
Intrusion Detection (and prevention) System
RAS
Remote Access Service
ROI
Return Of Investment
ITIL
IT Infrastructure Library
Nixu CIRT
Nixu's specialized Incident Response and Forensics Team

Related reading

Are you confident that your critical services and operations are secured effectively? When was the last time you conducted an independent audit?

Could the bottleneck of your infrastructure security be non-uniform and ineffective security processes being used to control your infrastructure?

Contact

Please Contact our Sales department for further information.