Technology Risk Assessments

For organizations that a specific technical security assessment, SAS 70 Solutions provides the following services.  Technology risk assessments may be configured to include the following:

  • Overall network/security architecture assessment
  • Virtualization and cloud computing assessments
  • Application architecture reviews
  • Network vulnerability assessments
  • Application vulnerability assessments
  • Penetration testing (network and application)
  • Code review
  • Firewall and network configuration reviews
  • Platform (standard and virtual) configuration (standard build) reviews

Approaches and deliverables will vary. In general, industry standards for information security and configuration management (such as ISO 27002, NIST, CIS, etc.) are leveraged as standards of good practice.