Cybersecurity Services
- IT General Controls Audits
- IT Infrastructure Audit
- IT Risk Assessment
- Network Security Audit
- Application Security Audit
- Network Vulnerability Testing & Assessment
- Disaster Recovery and Business Continuity Planning
- Penetration Testing
Information Technology (IT) Audit
In today’s information-driven business environment, organizations must continually evaluate their ability to protect information assets. This includes not only security protocols and development processes but also continued availability of information to authorized parties. The purpose of an IT audit is to determine how effectively an organization is maintaining these protocols and to provide direction on how to improve. Effective IT audit services help organizations not only improve internal controls and security but also achieve their IT goals and objectives.
CACS’ IT Audit services help organizations understand their key technology risks and how well they are mitigating and controlling those risks. Our professionals provide insight into the threats inherent in today’s highly complex technologies. Computer Audit Control and Security (CACS) Associates Limited offers a wide range of services of IT audit outsourcing and co-sourcing. The CACS methodology, which is both COSO- and COBIT®-based, facilitates an overall IT internal audit management team (either CACSS-led, client-led, or in combination) with the execution of individual projects by subject-matter experts in each IT audit area.
Our IT Audit team have a deep understanding of industry best practice. They also bring with them a multitude of recognized credentials, as well as a wealth of experience. They will produce a comprehensive IT audit report that includes a complete review of your:
- Servers and Desktops
- Networking and Security
- Applications and licensing
- Hosting and Internet Access
- Backup and Disaster Recovery
- Telephony
- IT Team and stakeholders
- Technology Suppliers and Costs
A thorough gap-analysis will highlight any areas of concern and ways to consolidate, rationalize and make cost savings, while also uncovering ways to improve performance, productivity and efficiency across your business will be uncovered.
Our services delivery mode consists of:
Co-sourcing: We provide you with IT auditors and/or subject matter experts to supplement your in-house team. These experts will assist you in composing an annual IT audit plan that can help you close gaps regarding in-house resources. The model strengthens collaboration with your internal auditors and enables the transfer of valuable knowledge to your company. This enhances the value of the internal audit while your organization keeps overall control.
Audit Advisory: These engagements are ad hoc in nature and may be requested in addition to the performance of an internal audit plan or other service (e.g. IT risk assessments, process improvement engagements, training etc.).
Outsourcing: Together with our colleagues from the internal audit risk and compliance team, we complete your internal audit mandate providing the full lifecycle of internal audit activities; including risk assessment and prioritization, development of audit plans, stakeholder management, delivery of internal audits and reporting and issue resolution tracking.
IT General Controls (ITGC) Audit
IT general controls (ITGC) are the basic controls that can be applied to IT systems such as applications, operating systems, databases, and supporting IT infrastructure.
The objectives of ITGCs are to ensure the integrity of the data and processes that the systems support. The most common ITGCs are as follow:
- Logical access controls over applications, data and supporting infrastructure
- Program change management controls
- Backup and recovery controls
- Computer operation controls
- Data center physical security controls
- System development life cycle controls
Detailed Approach to IT General Controls
We assist organizations in designing ITGC frameworks and providing operating effectiveness assurance through co-sourcing and outsourcing of ITGC audits.
CACS Associates’ dedicated IT audit professionals have experience working with a wide variety of industries of all sizes. We partner with you to provide a comprehensive ITGC coverage to manage and mitigate ITGC risks within your IT environment. Our ITGC services will be tailored to the organizations risk appetite and compliance requirements. Our staff also delivers the utmost integrity, objectivity, confidentiality, and independence required by the auditing standards.
IT Risk Assessment Services
Prior to performing an audit of your IT infrastructure, it is critical to first identify and categorize risk. A properly performed risk assessment is a critical component in understanding the complexities and requirements of the risk assessment process, prior to identifying and testing controls to mitigate the related risks. Risk assessments should be comprised of an information gathering process to identify threats and vulnerabilities the organization is facing, determining the probability and impact of those threats, identifying existing mitigating controls, designing audit procedures to test the effectiveness of those mitigating controls. Throughout this process, a combination of collaborative discussion and reviews will occur with the business functions and supporting services being audited.
CACS Associates Consultants can assist your organization in identifying IT risks by performing a thorough and detailed risk assessment that will ensure that your organization has implemented the appropriate safeguards to protect the most valuable IT assets within your organization.
Our to IT Risk Assessment
We begin our assessment by working closely with you to understand your business functions and take an inventory of the technologies used to support those functions. We will work with and interview key individuals within the business and information technology services to understand information policies, procedures, and practices through the following:
- Hold information gathering sessions;
- Identify threats and vulnerabilities;
- Determine the probability and likelihood of threats occurring;
- Evaluate the effectiveness of controls;
- Determine overall residual risk
Our ultimate goal is to assess your organization’s risk appetite in relation to your business functions and supporting technologies through identifying gaps and providing detailed recommendations to effectively close those gaps to mitigate potential risks to the business.
NETWORK SECURITY AUDIT
As technology needs continue to increase, so do potential vulnerabilities for critical business systems. Network security assessments and audits help identify unknown vulnerabilities that have gone undetected or underestimated and provide advice and guidance to secure your organization.
A network security assessment is an audit of your organization’s IT infrastructure that reviews your network’s security measures. Its goal is to identify vulnerabilities to determine if your organization is secure in the event of an attack or data breach.
There are two basic types of network security assessments: penetration tests and vulnerability assessments. Penetration tests, or pen tests, are methods of legitimate hacking used to simulate attacks on your organization to help you identify vulnerabilities before they are exploited by hackers. In contrast, vulnerability assessments use tools to detect vulnerabilities in your organization rather than exploit them.
Security assessment help your organization evaluate security risk and meet compliance with regulatory requirements. They can include an in-depth assessment of systems such as infrastructure analysis, server and system analysis, network analysis, application scanning, information security analysis, company policies and third-party security analysis.
Network security risk assessments can be complex and time-consuming, especially when it comes to third parties. CACS Associates Ltd gives you a comprehensive view of how secure your third parties are (or aren’t), identifying any security gaps while also providing remediation plans to mitigate any gaps. We’ll also help assess your third parties’ compliance with the latest security standards and regulations.
Features of our penetration testing services
- Testing includes web and mobile applications, APIs, infrastructure and IoT
- Testing across the spectrum of black-box and white-box methods
- Automated tools with hands-on analysis by qualified engineers produce a detailed, risk-based report with actionable recommendations for mitigation
Benefits of our penetration testing services
- Receive snapshot of security posture and an opportunity to identify potential breach points
- Drive compliance with regulation or security certifications
- Increase business continuity
- Test cyber-defense capabilities
- Protect customers from financial damage
MOBILE APPLICATIONS SECURITY AUDIT
Emulating the approach used by hackers, our expert IT Auditors will perform a controlled real-life evaluation of your mobile software application. Our experts identify security vulnerabilities related to your mobile application, interfaces to servers, databases, firewalls, internal servers, and network infrastructure configuration. Our report identifies specific vulnerabilities and provides detailed instructions to mitigate or eliminate each risk
Disaster Recovery/Business Continuity Planning
CACS Associates’ Risk Advisory professionals understand that business continuity provides a framework for building organizational resilience and the capability for an effective response through managing processes to identify the following potential risks, threats, and vulnerabilities that could affect continued operations:
- Advances in technology
- Cyber threat considerations
- Utilizing insurance as a risk transfer tool
- Strategies for manufacturing
- Supply chain processing
- Risk management concepts
- Legal and regulatory concerns
We are committed to the continued understanding of risks that have the potential to impact business operations. Specifically, what sets us apart is our commitment to continue professional education and the fact that management of our Risk Advisory Practice has obtained the Certified Business Continuity Lead Auditor (CBCLA) certification, which is one of only 64 certified professionals globally.
Our Approach
Created and maintained by Disaster Recovery Institute International, The Professional Practices for Business Continuity Management is a body of knowledge designed to assist in the development, implementation, and maintenance of business continuity programs. These professional practices, along with the NFPA 1600 Standard on Disaster/Emergency Management and Business Continuity/Continuity of Operations Programs and our industry experience will serve as a baseline to assess the existing Plan in helping to identify gaps and deficiencies, while providing recommendations as necessary.
Our approach and core areas of focus for the assessment will include but not be limited to the following:
- Assess Management’s Buy-In and Ongoing Support of the Plan
- Assess the Risk Assessment Approach and Frequency
- Assess the Business Impact Analysis (BIA)
- Assess the Business Continuity Strategies based upon the Risk Assessment and BIA
- Assess the Incident Response Plan and its Effectiveness
- Assess the Plan and the Implementation Procedures
- Assess the Awareness and Training Programs
- Assess Ongoing Testing and Maintenance of the Plan
- Assess Crisis Communication Procedures
- Assess Coordination Efforts and Procedures with External Agencies
We will perform our assessment with the assistance of management to ensure resources and information remains readily available.
WEB SITE SECURITY TESTING AND WEB APPLICATION SECURITY AUDIT
By emulating the approach used by hackers, CACS website security testing and web application security audit performs a controlled real-life evaluation of your web applications, websites, and web servers. Our experts evaluate your systems for over 35,000 types of vulnerabilities including SQL injection, authentication, encryption, buffer overflow, cross site scripting, web server configuration issues, and many others. Our website security testing and web application security audit report identifies specific vulnerabilities and provides detailed instructions to mitigate or eliminate each risk.
As an output of the engagement, we will issue you a website security testing and website security audit report that provides specific recommendations and detailed steps you can take to address any identified security vulnerabilities. After delivery of our reports, we provide three months of free support to answer any questions you may have. This ensures your security vulnerabilities are properly mitigated or eliminated