Snapshot of skills and competence of CERT-In empanelled Information Security Auditing Organisation

  1. Name, Location of the empanelled Information Security Auditing Organisation : Indusface Consulting Pvt Ltd, Baroda

  2. Carrying out Information Security Audits since : July 2004

  3. Technical manpower deployed for information security audits :
    CISSPs : 8
    BS7799 / ISO27001 LAs : 12
    CISAs : 1
    DISAs / ISAs : 0
    Total Nos. of Technical Personnel : 40

  4. Outsourcing of External Information Security Auditors / Experts : No

  5. Information Security Audit Tools used (owned, in possession) :
    Freeware : 40
    Commercial : 2
    Proprietary: 0
    Total Nos. of Audit Tools : 42
    (Click here for details of the audit tools)

  6. Information Security Audit Methodology : ISO27001, COBIT, OWASP, OSSTMM, PCI

  7. Information Security Audits carried out since empanelment till now :
    Govt. : 250
    PSU : 35
    Private : 15
    Total Nos. of Information Security Audits done : 300

  8. Business domain of auditee organisations : Finance, Healthcare, Government, Software / ITES, Manufacturing, Power (Energy-utilities), Banking

  9. Typical applications in use by auditee organisations : Banking, Web 2.0, Billing, PKI, Oracle ERP, VAT, Document Management System, Content Management System, e-Tender

  10. Typical bandwidth (maximum) of any auditee organisations :
    Internal Bandwidth (LAN / Intranet) : 1 Gbps
    External Bandwidth (WAN / Internet) : 6 Mbps

  11. Networked Infrastructure details of an organizations audited with most complex network :
    No. of Computer Systems : 1500
    No. of servers : 90
    No. of switches : 30
    No. of routers : 4
    No. of firewalls : 4
    No. of IDS' : 2

  12. Ability to carry out vulnerability assessment and penetration test : Yes


Key : NA = Not Available (data not provided by the CERT-In empanelled Information Security Auditing Organisation).