Why You Need to Audit


By Nahum Goldmann
ADDSecure.Net Inc.
addsecure (at) ADDSecure.Net
http://www.ADDSecure.Net/

Most Canadian government organizations and private corporations have established Web sites which distribute important information to their clients and general public. Soon their Internet and intranet servers will deliver administrative services and electronic commerce.

Is your Web secure? This is the top concern of your clients when using corporate intranet and Internet services. Most executives and professionals have personal responsibility for the security of the sensitive content stored on their Web sites. They are fully expected to assure the integrity of the proprietary corporate information or protection of personal data entrusted to the government.

Is your organization fully prepared for a politically insensitive slogan that might be placed on your Web homepage or for a lawsuit induced by a disgruntled employee who penetrated your agency's protected bank of sensitive data? The security of Web-based services is likely to be audited, as is the case for all other collections of corporate information. In cases of security breach, executives will require to prove that they exercised due diligence in securing Web-based corporate data.

Unfortunately, Internet sites of every government agency and of the leading private corporations are targeted for penetration. Whether browsing or managing Internet and Intranet web sites, no minimal guarantee of availability, integrity, accountability, or confidentiality is likely to exist. Your web site may have already been penetrated without detection, or become the next target. Numerous well publicized cases of homepage altering prove that no one is fully immune from hackers located far away or within the organization.

  • The DOD reports that 80% of its sites were penetrated. The same had happened to the CIA, NASA and the UK government.
  • Virtually all the world leading corporations have experienced malicious attacks. Studies conducted by CSI, FBI and NCSA show that half of Web sites surveyed were attacked and penetrated through the Internet.
  • 20% of companies that are using firewalls, anti-virus and encryption solutions still experience Internet related security breaches.
  • Companies engaged in iCommerce are 57 per cent more likely to suffer an information security breach than those that do not do business online, according to The 1999 Information Security Industry Survey published in the July '99 issue of the Information Security magazine.

New services of ADDSecure.Net Inc. can fully address your Web security concerns. ADDSecure.Net Inc. (formerly CSCI Computer Security Canada Inc.) is an independent and impartial company that provides highly efficient and reasonably priced security audit services for Internet/Extranet servers and workstations. ADD in our name stands for Audit and Due Diligence.

Operating world-wide, ADDSecure.Net Inc. assists governments and industry in protecting their corporate image, intellectual assets, privacy of personal and proprietary data entrusted to them by their clients and employees, and investments in electronic commerce solutions. Our ADDSecure.Net™ and appSQA™ services to audit Web and code security are offered to corporations, government agencies and financial institutions that must maintain sensitive data on their servers and networks.



ADDSecure.Net Audit