The audit scheme recommended by us is developed on the basis of fifteen issues that are mutually interconnected:
-
Appointing an audit team
-
Collecting information on organization structure of a company, network infrastructure and topology, media in use, active and passive devices, resources, physical and logical protection systems, threats and hazards, etc.
-
Company orientation towards security assurance
-
Preliminary analysis of the collected information
-
Network traffic analysis
-
Network security testing
-
Analysis of network resources protection systems and hazard notification
-
Verification of network administration and access control methods
-
Cryptographic security (protection?) analysis
-
HR analysis (It personnel knowledge/expertise, IT staff number)
-
Physical security analysis
-
Analysis of internet resources access policy
-
Anti-virus control analysis
-
Analysis of data recovery and company efficiency restore
-
Audit report
The following standards and procedures are observed while preparing and performing the audit:
-
PN-ISO 10011-1 Directives for quality system auditing. Auditing;
-
ISO/IEC 17799 Information technologies. Rules of conduct for information security management;
-
PN-I-13335-1 IT technique. Guidelines for IT system management. Concepts and models of security of IT systems;
-
PrPN-I-13335-2 IT technique. Guidelines for IT system management. Management and planning aspects;
-
PrPN-I-1335-3 IT technique. Guidelines for IT system management. Security techniques;
-
ISO/IEC 15408-1 Information technologies. Security techniques – Evaluation criteria of information security. Introduction and general model;
-
ISO/IEC 15408-2 Information technologies. Security techniques – Evaluation criteria of information security. Functional security requirements;
-
ISO/IEC 15408-3 Information technologies. Security techniques – Evaluation criteria of information security. Requirements of security assurance;
-
PN-I-02000 IT technique. Protection of IT systems. Terminology;
IT Baseline Protection Manual - handbook published by Bundesamt für Sicherheit in der Informationstechnik.

