Snapshot of skills and competence of CERT-In empanelled Information Security Auditing Organisation

  1. Name, Location of the empanelled Information Security Auditing Organisation : Network Intelligence India Pvt. Ltd., Mumbai

  2. Carrying out Information Security Audits since : October 2001

  3. Technical manpower deployed for information security audits :
    CISSPs : 3
    BS7799 / ISO27001 LAs : 12
    CISAs : 3
    DISAs / ISAs : 0
    Total Nos. of Technical Personnel : 18

  4. Outsourcing of External Information Security Auditors / Experts : Yes

  5. Information Security Audit Tools used (owned, in possession) :
    Freeware : 38
    Commercial : 0
    Proprietary: 10
    Total Nos. of Audit Tools : 48
    (Click here for details of the audit tools)

  6. Information Security Audit Methodology : ISO 27001 (BS 7799), ISO 20000 (BS 15000), CoBIT, OSSTMM, OWASP, BS 25999

  7. Information Security Audits carried out since empanelment till now :
    Govt. : 3
    PSU : 3
    Private : 78
    Total Nos. of Security Audits : 84

  8. Business domain of auditee organisations : Banking, Financial Institutions, Telecom, IT/ITES, Government, Manufacturing

  9. Typical applications in use by auditee organisations : SAP, IIS, Microsoft Exchange, Lotus Domino, Web applications (ASP, JSP, PHP)

  10. Typical bandwidth (maximum) of any auditee organisations :
    Internal Bandwidth (LAN / Intranet) : 100 Mbps
    External Bandwidth (WAN / Internet) : 5 Mbps

  11. Networked Infrastructure details of an organizations audited with most complex network :
    No. of Computer Systems : 3000
    No. of servers : 200
    No. of switches : 60
    No. of routers : 20
    No. of firewalls : 10
    No. of IDS' : 1

  12. Ability to carry out vulnerability assessment and penetration test : Yes

Key : NA = Not Available (data not provided by the CERT-In empanelled Information Security Auditing Organisation).