Compliance Services

The gap and maturity assessment is a fast track analysis to establish an understanding on organizations’ information security capabilities. The purpose of this activity is to evaluate the current capabilities of organizations against relevant areas of best practices, so that gaps can be identified. This exercise is designed to give Senior management a better indication of where the organization stands in terms of the relevant standard, and what effort is required to be compliant.

Internal Audit

Internal auditing is an independent, objective assurance and consulting activity designed to evaluate compliance, and improve an organization’s governance, risk management and management controls. This service involves onsite independent assessment and fact finding and a report which provides insight and recommendations based on analyses and assessments of data and business processes. I(TS)2 provides Internal Audit for following standards:

  • ISO 27001- Information Security Management System
  • ISO 22301 – Business Continuity
  • ISO 20000 – Service delivery Management

Standards Establishment, Implementation & Certification

This service involves facilitatingour clients to establish, implement, manage, maintain following management systems:

                • ISO 27001- Information Security Management System
                • ISO 22301 – Business Continuity
                • ISO 20000 – Service delivery Management
                • We ensure that all the requirements for certification are well met and facilitate organization to achieve desired management system certification

Physical Security Review

The objective of this service is to assess and evaluate an organization’s physical security controls, identify any shortcomings, and to provide recommendation via a report. Typically it comprises of review of physical Access Control;Vehicle Access Control;Security Guards Control; Environmental Controls;Life Safety Controls;Equipment Controls; and other Concerns.

Cyber Security Risk Assessment and Management

This Service comprises of establishing a tailored risk methodology for to assess, evaluate, modify and mitigate the cyber security risk for an organization.During risk assessment critical organizational services are identified, and related information security threats and vulnerabilities are determined and eventually risk is evaluated. A mitigation plan is established to address the information security risks which are not acceptable. At the end of engagement a comprehensive report will be created to summarize all risks, their values, mitigation plans, risk owners and due dates.

Cyber Security Policies & Procedures

I(TS)2 helps organizations help develop policies and procedures that sets out a framework of governance and accountability for information security management commitment across an organization.
Procedures describe how each policy will be put into action in the organization, and gives a detailed step-by-step how to fulfill a specific task or activity.

Information security Organization

This service involves facilitatingour clients to establish, implement, manage, maintain following management systems:

  • Establishing Cyber Security structure and hierarchy in an organization
  • Establishing Cyber Security roles and responsibilities and explicit assignment for the employees (RASI)
  • Identifying key roles and responsibilities for main roles in security program such as CIO, Security Manager, Security Unit, end users.

Vulnerability Assessment

The objective of a vulnerability assessment service is to identify and assess all possibly present vulnerabilities in the IT network or infrastructure and report it to the customer. The end result is a report which produced prioritizing list of vulnerabilities& suggests remediation.

External Penetration Testing

External penetration testingis an offensive security analysis of an IT infrastructure’s defensesagainst attacks from the Internet. External penetration testing involves mimicking the actions of an external hacker, with the purpose of simulating a cyber-attack or gaining access to confidential information through the Internet. This type of testing checks for vulnerabilities in the IT infrastructure’s external perimeter that may lead to a breach of confidentiality, integrity and accessibility of data

Physical Security Review

Internal penetration testing is an analysis of IT infrastructure security within a corporate network. Internal penetration testing involves simulation of actions of a malicious employee. This type of testing checks for vulnerabilities in the internal network that may lead to a breach of confidentiality, integrity and accessibility of data.

Web Application Penetration Testing

Web application penetration testing is to ensure the security of the most critical information by identifying known and unidentified vulnerabilities within the web application layer. The security assessments are performed on any web-based application, including all industry-leading application platforms. Our methodology is aligned with leading practices such as OWASP, WASC.

Mobile Application Penetration Testing

The objective of a mobile application penetration testing is to identify and assess all possibly present vulnerabilities in the mobile application and report it to the customer. Mobile Application testing includes:

                • Client side testing
                • Network side testing
                • Server side testing
                • Our team is fully capable of performing assessment on android, iOS, and windows platforms.

Wireless Penetration Testing

Wireless Penetration testing is to test the effectiveness of the Wireless security Controland also to analyses the Weakness and Critical wireless network vulnerabilities.

Secure Code review

Secure code review is a specialized task involving manual and/or automated review of an application’s source code in an attempt to identify security-related weaknesses (flaws) in the code.

Security Analysis of Industrial Systems (APCS, SCADA)

The purpose of the security analysis of industrial systems is to provide an objective and independent assessment of the current level of protection of an industrial system. The scope of this process includes verification of the network demarcation, security of applications, the ability to upgrade the operator’s access rights, security of operating systems, the safety of controllers and other system components.

DDoS Simulation Testing

DDoS Testing gives enterprises the unique opportunity to carry out comprehensive, simulated attacks. Designed to emulate real-life DDoS attack scenarios, the fully customizable and controllable tests expose system vulnerabilities and allow enterprises to put their security strategies to the test.

Threat Hunting & Compromise Assessment

A Threat Hunting &Comprise assessment is an advanced threat detection service tailor made for organization suspected a data breach. The service identified and detects the contemporary cyber threats that already exists in your organization. I(TS)2 team of consultants will investigate your infrastructure to pinpoint accuracy and precisely detect who, what, where, when and how you have been attacked, and simultaneously provide corrective actions.

Social Engineering

Social engineering testing is use to test and manipulate the organization employees into allowing unauthorized access to confidential information. This provides perception into how effective the organization’s policies and procedures are at countering social engineering threats, how well the employees follow to established policies and procedures, and the level of security awareness that exists among employees.

Red Teaming

The Red Teaming Test simulates a situation where our team of qualified consultants and target your organization’s vulnerable assets.By simulating real life attackers. The results produce perceptions into how potential vulnerabilities can affect your business and how they can be effectively treated. This exercise also tests the maturity of your current incident response processes.

Forensic Investigations

The Forensic investigation service examines digital media in a forensically sound manner with the aim of identifying, preserving, recovering, analyzing and presenting facts and opinions about the digital information incident.

SOC Assessment

SOC assessment is a review of components associated with any typical security operations center. The service comprises of:

                • Hardware Specifications Validations
                • SIEM Configuration review
                • SIEM Log Volume Capacity Study
                • SIEM Use-Case relevancy check
                • Data-Sources integration review
                • Incident handling process review
                • Escalation Process review
                • SOC staff augmentation

Secure Architecture Review

The Secure architecture Review is areview of your current Network architecture from a security perspective. The study is based on International acclaimed standards and best practices. The core of the engagement involves understanding your business requirements, architectural design review, verifying your network design flows, and assessing your current security technologies in place. The end result is a detailed report which identifies weaknesses and the measure to be taken to address them. Also, a technology roadmap is provided to the customer as a part of the report

Secure Configuration Review

A configuration review provides a comprehensive and detailed security audit of network components such as switches , servers and routers, to ensure that weaknesses in their configuration are identified and remediated, reducing the risk of a security incident