Security Audit
Security audit is an analysis of a IT system, comprising all aspects of its work (see: network audit) emphasizing security. Security tests, including tests of network security resistance to dangers, may constitute a part of an audit.
The aim of a security audit is to specify the current level of the company’s IT system security and to create basis for development and maintaining an established, properly high level of information security, telecommunications network and productive computer systems.
Audit - step by step:
- recognizing information resources, estimating their value,
- an analysis of a current security level,
- indicating possible security policy deviations from the guidelines defined in the security policy,
- listing recommendations for what to do after an audit
- preparing audit documents.
Selected security tests:
- testing LAN and WLAN networks’ susceptibility to sniffing,
- testing resistance to penetration from the inside or outside of a network,
- testing vulnerability to sociotechnical attacks
- testing authentication and authorization data distribution systems.


