Hi,
Mga boss! Gud am! Mangutana lang unta ko sa nuha kng naa mu mga kaila nga mga IT Firm nga pwed maka conduct ug assessment sa amoa Infra with scope below. Salamat kaau daan sa nuha mga inputs mga masters.!
1. Network and Security Architecture
a. Segregation of critical & non-critical assets
b. VLANs
c. DMZ's
d. Ingress/Egress points
e. Firewall
f. IPS/IDS
g. DDoS
h. Wi-Fi Security
i. Network Admission Control (NAC)
2. Web Security
a. Proxy
b. URL Filtering
c. Anti-Virus
3. Email Security
a. Anti-Virus
b. Anti-Spam
c. E-mail Policy for blocking suspicious file extensions/types
4. Application Security
a. Secure coding guidelines
b. Application Security Assessment (One sample application)
c. WAF
5. Secure Configuration
a. Hardening Standards (OS, Network, Middleware, Database, Products)
b. Build Secure Infrastructure
6. Patch Management
a. Patch Management Policy (including Testing & Deployment procedure)
b. Patching Cycle
7. Endpoint Security
a. End-Point Policy
b. EDR
c. HIPS
d. Client Firewall
8. Monitoring
a. Security Operations Center (SOC)
b. SIEM, Log Review
c. NADS
d. Anti-APT
e. Social Media
f. Threat Intelligence
g. Analytics, Dashboards & Reports
9. Assessments & Audits
a. Architecture Review
b. Threat Modelling
c. VA, PT
d. Process Audits