Snapshot of skills and competence of CERT-In Empanelled Information Security Auditing Organisation

  1. Name, Location of the Empanelled Information Security Auditing Organisation : Astral Consulting Ltd., Coimbatore

  2. Carrying out Information Security Audits since : 2003

  3. Technical manpower deployed for information security audits :
    CISSPs : 0
    BS7799 / ISO27001 LAs : 1
    CISAs / CISMs: 6
    DISAs / ISAs : 3
    Total Nos. of Technical Personnel : 16

  4. Outsourcing of External Information Security Auditors / Experts : No

  5. Information Security Audit Tools used (owned, in possession) :
    Freeware : 7
    Commercial : 4
    Proprietary: 0
    Total Nos. of Audit Tools : 11
    (Click here for details of the information security audit tools)

  6. Information Security Audit Methodology : OSSTM, OWASP, ISO/IEC 27001, CoBIT, ITIL

  7. Information Security Audits carried out since empanelment till now :
    Govt. : 2
    PSU : 3
    Private : 5
    Total Nos. of Security Audits : 10

  8. Business domain of auditee organisations : Telecom, Airport, Banking, Financial, Manufacturing, Automotive, Textiles, Sugar, Insurance, BPO

  9. Typical applications in use by auditee organisations : ERP Solutions, Home grown applications

  10. Typical bandwidth (maximum) of any auditee organisations :
    Internal Bandwidth (LAN / Intranet) : 100 Mbps
    External Bandwidth (WAN / Internet) : 5 Mbps

  11. LAN Infrastructure details of an organizations audited with most complex network :
    No. of Servers : 620
    No. of Computers : 15000
    No. of Routers : 45
    No. of Switches : 2200
    No. of Firewalls : 2
    No. of IDS' : 1

  12. Ability to carry out vulnerability assessment and penetration test : Yes

Key : NA = Not Available (data not provided by the CERT-In empanelled Information Security Auditing Organisation).