Snapshot of skills and competence of CERT-In Empanelled Security Auditor

  1. Name, Location of the Empanelled Security Auditing organisation: Network Solutions, Delhi

  2. Carrying out Information Security Audits since : NA

  3. Technical manpower deployed for security audits :
    CISSPs : 1
    BS7799 / ISO27001 LAs : 3
    CISAs : 0
    DISAs / ISAs : 2
    Total Nos. of Technical Personnel : 6

  4. Outsourcing of External IT Security Auditors / Experts : No

  5. Security Audit Tools used (owned, in possession) :
    Freeware : 15
    Commercial : 0
    Proprietary: 1
    Total Nos. of Audit Tools : 16
    (Click here for details of the audit tools)

  6. Security Audit Methodology : COBIT, ISACA, SAN, BS7799

  7. Security Audits carried out since empanelment till now :
    Govt. : NA
    PSU : NA
    Private : NA
    Total Nos. of Security Audits : NA

  8. Business domain of auditee organisations :
    sw dev, banking, BPO, Infras. Mgmt

  9. Typical applications in use by auditee organisations :
    web, messaging, BPO, banking, Oracle, Lotus Notes, MS Exch.

  10. Typical bandwidth (maximum) of any auditee organisations :
    Internal Bandwidth (LAN / Intranet) : NA bps
    External Bandwidth (WAN / Internet) : NA bps

  11. Networked Infrastructure details of an organizations audited with most complex network :
    No. of servers : 50
    No. of Computer Systems : 2000
    No. of routers : 0
    No. of switches : 10
    No. of firewalls : 2
    No. of IDS' : 2

  12. Ability to carry out vulnerability assessment and penetration test : Yes


Key : NA = Not Available (data not provided by the CERT-In empanelled Information Security Auditing Organisation).