| Security Assessment |
|
A Security Assessment can be carried out at various levels. An enterprise-wide security assessment aims to determine control weaknesses or gaps across people, processes and technology. We offer the following services as part of the Security Assessment service suite.
|
| Penetration Testing |
|
Our penetration testing exercise walks through a series of tasks cultivated especially for identification and simulated exploitation of vulnerabilities. We have worked on web applications, VPNs, firewalls, mail servers, and the entire network perimeter.
|
| Penetration Testing 2.0 (SE) |
|
Going much beyond the usual network and web application hacking, attackers have started investing their time, money and effort in an easier and higher yield target. This target is the abuse of trust a human places on their environment. Attackers have started exploiting the trust we place in each other and the systems we use.
|
| Cloud/Virtualization Assessment |
|
Server Virtualization is defined as the capability to run multiple operating system images on a single hardware server at the same time. To grow in the fast paced environment, organizations have been implementing server virtualization being cost effective and high return on investment. Securing virtual machines is equally important as securing the physical servers. Hence the guest operating system that runs in the virtual machine is subject to the same security risks as a physical system. Therefore, it is critical that you employ the same security measures in virtual machines that you would for physical servers.
|
| Wireless Auditing |
|
NII offers comprehensive WLAN Auditing and Consultancy services to help assess the security posture of your WLAN and to configure it to the maximum security level possible.
|
| Network Performance Audit |
|
Regardless of recent improvements in network performance and capacity, it is essential for network administrators to periodically assess the reliability of network technology and its ability to meet business needs. Consequently, network performance assessments can help organizations determine whether the programs, hosts, and applications that are installed on the corporate network function properly.
|
| Security Audit |
|
Our security audit services cover all aspects of security including people, processes, and technologies. We have expertise in auditing a wide range of operating systems, firewalls, intrusion detection systems, databases, web servers, messaging servers, network components and industry specific technologies.
|
| Application Security Audits |
|
We offer exhaustive security audits for all kinds of applications : stand-alone, network-based and web-based. Our Application Security Audit covers
high-level design audit
black-box testing
source code audit
development and delivery audit
operating environment audit
Previous experience in this segment includes application security assessments for CRM and ERP software of large manufacturing and financial firms, e-commerce applications for some of the largest online stores, and client-based encryption software among others.Our skills in this area are demonstrated by the bugs we find in mission critical software from vendors such as Microsoft, Oracle, Macromedia and Nortel. Read our list of advisories here.
|
| Network Architecture Review |
|
Our Network Architecture Reviews will help you identify configuration and topology issues through analysis of the design and configuration of the network.
|
| Risk Assessment |
|
Our Risk Assessment exercises lists out the key information assets within the organization and determines the risk to those assets based on existing vulnerabilities and probable threats. Risk Assessment is essential in determining the security posture of your organization.
|
| Tiger Team Attack |
|
An organization may have the best of security in terms of physical security and security technologies deployed as well as the security policies, procedures and controls adopted and adhered to. In spite of the high spend on IT and Physical security, there may still exist numerous vulnerabilities that may have been overlooked and incidents of security breaches and failures that might still occur, especially through people
|