Snapshot of skills and competence of CERT-In empanelled
Information Security Auditing Organisation
- Name & location of the empanelled Information Security Auditing Organisation : Kochar & Associates (CA), Mumbai
- Carrying out Information Security Audits since : February 2006
- Technical manpower deployed for information security audits :
CISSPs : 0
BS7799 / ISO17799 / ISO27001 LAs : 2
CISAs / CISMs: 4
DISAs / ISAs : 3
Total
Nos. of Technical Personnel : 9
- Outsourcing of information security auditing work to external Information Security Auditors / Experts : No
- Information Security Audit Tools being used (available, installed and licensed) :
Freeware : 6
Commercial : 2
Proprietary: 0
Total Nos. of Information Security Audit Tools : 8
(Click here for details of the information security audit tools)
- Information Security Audit Methodology : CoBIT, ISO27001
- Information Security Audits carried out so far :
Govt. : 0
PSU : 4
Private : 20
Total Nos. of Security Audits : 24
- Business domains of auditee organisations : Banking, Share Broking, Collateral Security Management
- Typical applications in use by auditee organisations : CTCL (NSE), ITORS (BSE), CBS (Finacle)
- Bandwidth available with an auditee organisation having most
complex network :
Internal
Bandwidth (LAN / Intranet) : 100 Mbps
External Bandwidth (WAN / Internet) :
2 Mbps
- LAN infrastructure details of an auditee organisation having most complex network :
No. of Computers : 300
No. of Servers : 18
No. of Switches : 6
No. of Routers : 5
No. of Firewalls : 2
No. of IDS' : 0
- Ability to carry out vulnerability assessment and penetration test : Yes
Key : NA = Not Available (data not provided by the CERT-In
empanelled Information Security Auditing Organisation).