Snapshot of skills and competence of CERT-In empanelled Information Security Auditing Organisation
- Name, Location of the empanelled Information Security Auditing Organisation : KPMG, Gurgaon
- Carrying out Information Security Audits since : September 1996
- Technical manpower deployed for Information security audits :
CISSPs : 17
BS7799 / ISO27001 LAs : 17
CISAs : 50
DISAs / ISAs : 0
Total Nos. of Technical Personnel : 200
- Outsourcing of External Information Security Auditors / Experts : No
- Information Security Audit Tools used (owned, in possession) :
Freeware : 19
Commercial : 12
Proprietary: 7
Total Nos. of Information Security Audit Tools : 38
(Click here for details of the audit tools)
- Information Security Audit Methodology : Beyond Standard, COBIT, ISO27001
- Information Security Audits carried out since empanelment till now :
Govt. : 10
PSU : 50
Private : 230
Total Nos. of Security Audits : 290
- Business domain of auditee organisations : Financial Services, InfoTech, Communication, Entertainment, Infrastructure, Government, Marketing
- Typical applications in use by auditee organisations : ERP, Email, Client-Server, Web based, Workflow, Collaboration
- Typical bandwidth (maximum) of any auditee organisations :
Internal Bandwidth (LAN / Intranet) : 1 Gbps
External Bandwidth (WAN / Internet) : 100 Mbps
- Networked Infrastructure details of an organizations audited with most complex network :
No. of Computer Systems : 20000
No. of servers : 400
No. of switches : 150
No. of routers : 80
No. of firewalls : 30
No. of IDS' : 45
- Ability to carry out vulnerability assessment and penetration test : Yes
Key : NA = Not Available (data not provided by the CERT-In empanelled Information Security Auditing Organisation).