ADDSecure.Net™ Audit
Service Description

We attest to your diligence™

    ADDSecure.Net™ Audit
  Total Audit Plans
  SNAPShot™ Security Review
  Service Description

    Order ADDSecure.Net™ Audit Service
  Frequently Asked Questions
  Top 10 Reasons to Buy an Independent Security Audit
  Top 10 Reasons for a Corporate Executive Not to Bother with a Security Audit

 Description du service ADDSecure.Net Audit


top ADDSecure.Net™ Audit
    

ADDSecure.Net™ Audit consists of several hundred thousand remote tests conducted by our team of dedicated network security professionals. The tests include:

 

  Probing of all tcp/udp/icmp for active services;
  tcp/udp/icmp service-specific attacks;
  Application specific attacks;
  Operating system specific attacks;
  Denial of service attacks;
  Verification of Domain Registration Records;
  Domain Name Service (DNS) security test;
  Fully Qualified Domain Name (forward and reverse) validation;
  A complete Report containing references to the accumulated results and detected vulnerability areas.

    

Comprehensive tests are conducted using powerful Internet auditing tools developed by ADDSecure.Net Inc., as well as commercial probes optimized for the operational environment used by service clients. The tests take several hours and we typically produce a report within 72 hours of test completion.

    

ADDSecure.Net™ Audit -- A one-time vulnerability test of a workstation, Internet network or server (up to 8 (eight) I.P. addresses per machine) for US$5,500. Electronic submission of a scan request using an online Order Form reduces the price to $5,000 -- a 10% discount.


top Total Audit Plans

To maintain the security of a network over the longer run and to assure ongoing "peace of mind", start off with a thorough review of your network using the detailed report from ADDSecure.Net™ Audit service. Follow up with SNAPShot™ Security Review testing at random intervals, or subscribe to predefined service packages performed 2, 4, 6 or 12 times. We provide substantial discounts tailored to client needs.

    

Monthly TAP (Total Audit Plan) -- We will provide a comprehensive ADDSecure.Net™ Audit service and report and 11 subsequent monthly follow-ups using SNAPShot™ Security Reviews with randomly selected tests each time -- a value of  US$23,650 for a fixed rate of  US$15,000.

    

Quarterly TAP (Total Audit Plan) -- We will provide a comprehensive ADDSecure.Net™ Audit service and report and 3 subsequent monthly follow-ups using SNAPShot™ Security Reviews with randomly selected tests each time -- a value of  US$10,450 for a fixed rate of  US$7,500.


top SNAPShot™ Security Review
    

SNAPShot™ Security Review -- A one-time security review of a workstation, Internet network or server (one I.P. address) for US$1,650. If ordered by the client through the Internet -- US$1,500, a 10% saving.


top Service Description

ADDSecure.Net™ Audit is an ADDSecure.Net Inc. security auditing service to probe integrity of Web sites and network servers. The service is being offered world-wide to corporations, government agencies and financial institutions that must maintain sensitive data on their Web sites. ADDSecure.Net Inc. also actively encourages Internet service providers, web developers, accounting, insurance brokerage and computer security firms to participate in reselling this new service.

ADDSecure.Net™ Audit encompasses a range of Internet network and server audit and testing services. The program is powerful enough to satisfy the strenuous demands of leading government organizations, banks and private corporations, yet it can meet the budget requirements of even small firms. The most basic audit service consists of a series of remote tests conducted by our team of dedicated network security  professionals. The tests result in an in-depth and easy to read confidential report detailing security vulnerabilities uncovered within the network. Comprehensive tests are conducted using powerful Internet auditing tools developed by ADDSecure.Net Inc., as well as with commercial probes optimized for the operational environment used by service clients.

US Federal Deposit Insurance Corporation's (FDIC) guidance FIL-68-99 of July 7, 1999 "Risk Assessment Tools and Practices for Information System Security" recommends regular use of vulnerability assessment tools and penetration analyses as an integral component of an institution's information security program. The analysis should be independent and may be conducted by a trusted third party, qualified internal audit team, or a combination of both. If using internal testers, the independence of the testers from system administrators should be considered.

As well, Electronic Payments Association's (NACHA) March 2001 rules have created a new Automated Clearing House (ACH) transaction code for identifying debit transactions authorized over the Internet. Under the rules, all financial institutions and businesses that offer an ACH debit as a payment method must conduct an annual security audit. ADDSecure.Net™ Audit addresses the key requirements of both financial industry documents.

We are not that concerned with the brand name of equipment your organization uses to secure your network or server, as long as it does a proper job -- and probably neither should you.  We help you to assure security of your network as much as possible, by leveraging already installed equipment and by using inhouse technical and security personnel. An independent audit can help you protect the integrity of your network and, in the process, save money by decreasing unnecessary or ineffective Internet security measures.

This simple but powerful audit service has been developed in response to requests from numerous ADDSecure.Net Inc. clients. With the increased vulnerability of global computer networks and the raising competitive pressure to provide services through the Internet, public agencies and private corporations need to ensure that the integrity of their data and that of their own customers is well preserved.

Many executives do not fully realize how much data within their area of responsibility are accessible by penetrating the corporate Web. Well-publicized cases of altering government homepages (i.e., see http:// www.ADDSecure.Net/breach.htm) prove that no one is immune from hackers located far away or within the organization. Just as with financial audits (where auditor's independence is required by the US Securities and Exchange Commission, Generally Accepted Auditing Standards -- GAAS, and by Section 5751.32 of the Canadian Institute of the Chartered Accountants Handbook), you cannot rely entirely on the tests done by the vendors of security solutions, and you do need to see results of security audits conducted by independent professionals.

Some of our clients have already found the hard way that hiring real hackers to check corporate defences might be imprudent at the best. What they are looking for is an independent and ethical audit team that has the persistence and adroitness of hackers but that also possesses the professionalism and undisputed integrity of industry security leaders. ADDSecure.Net™ Audit service has been built around this growing demand and provides our world-wide clients with badly needed security audit solutions.

To order ADDSecure.Net™ Audit service or for more information, please fill a form or email us: addsecure (at) ADDSecure.net.

top
(ADDSecure.Net™ Audit is a trademark of ADDSecure.Net Inc.)
ADDSecure.Net Audit ADDSecure.Net Audit