|
|
About us
 | RUauthorised Ltd is a leading specialist provider of IT Security Consultancy Services and Solutions for Security, Compliance, Continuity and Identity Management.
From the development of policy, strategy and awareness through to the delivery of complete, end-to-end solutions that encompass testing, training, security recruitment and managed services, RUauthorised consultants assist organisations to understand and manage the risk in their IT and business operations. RUauthorised has partnered with a number leading security technology suppliers using best of breed solutions to promote quality and cost effective solutions that can integrate in a seamless manner. Through partners we are able to offer cost effective managed security service solutions allowing the customer to concentrate on core business and benefit from enhanced levels of security. See partners. |
Services
Security Management
Your organisation faces some significant security challenges today, where protecting vital business data can be an expensive and a challenging proposition. To succeed requires a pro-active mind as well as action. Think about data as being an asset just as your car, home and contents. Some of these however are more valuable than others. That is where the security challenge comes into play. How do we determine where to place the highest levels of security? This is where threat and risk management appear. How many people in organisations develop bespoke applications and then try and apply the requisite security after the work has been done? All these types of experiences are being felt at a cost in many organisations. It`s a daunting prospect I know!
Organisations have now to comply with various regulatory bodies like HIPPA, SOX, Basell II, Turnbull etc whilst maintaining control of budgets, yet many of the IT Security solutions available in the market if deployed correctly will bring about greater control, enhanced security and actually reduce your expense, through less down time, increased productivity, regulatory compliance and increased effectiveness and efficiency.
Technical Security
IT security technical assurance
Efficient security is now a requirement for today`s businesses. For some, the drivers will be regulatory requirements such as Basel II, Sarbanes-Oxley or Turnbull. For others, the need to demonstrate assurance to industry standards like IS/ BS7799 may be the goal.
Whatever the driver, and however good your intentions, commitment alone is no longer sufficient. Management, auditors and business partners now demand tangible evidence of the security controls you've implemented and how they'll reduce risk.
How can RUauthorised help?
RUauthorised has drawn on its broad experience of client engagements in both public and private sectors and uses tried and tested methodologies for establishing assurance in the security of an IT infrastructure.
Examples:-
A major change to your IT infrastructure
Implementing a new business application
Preparing for an internal or external audit
Project or corporate risk assessments
Changes in working practices
Are you moving to a new office location?
Involved in a merger or acquisition?
Is your technical infrastructure correct?
Can you accurately identify where your IT security vulnerabilities lie?
Do you have rouge servers, redundant firewalls or poorly located intrusion detection systems?
Do you know where you should be focusing your security testing effort?
Security management
Policy, procedures and Standards
Management and Assurance
IS/BS 7799 Compliance
Risk Assessment
Legal and Regulatory Compliance
Audit
|
Technical security
Secure Network Design
Application Security
Wireless Security
Voice & VOIP Security
ACF2, Top Secret, RACF
OS400 and Unix Security
Firewall / Virus Security
VPN
|
Identity & Access Management
Strategy & Architecture
Identity Management Provisioning
Access Management: Web SSO
Enterprise SSO, Federated Identity
Web Security
Strong Authentication (Dual Factor)
Deployment architectures/products
IBM Tim/Tam, Sun SIM, CA eTrust
Security Management Solutions,
RSA Cleartrust + FIM, Authentication
Manager, Signon Manager, HP Select
Access, Select Identity, IBM XML A35/A40,
MS MIIS, ORACLE OIM - Xellerate, CoreID, Novell IDM etc
Application Security Integration, J2EE,
Portals, Middleware
Physical access control (Tokens, CCTV
Biometrics Palm readers, Fingerprint)
|
Attack & Penetration
Automated Testing
Network Mapping/Discovery,
TCP Port Scan,
FTP Source Port Scan,
UDP Port Scan,
Query of Informational Services Present,
DNS/RIPE Transfers
OS Finger printing
Vulnerability Scanning
Customised vulnerability scan using freeware,
commercial and bespoke products,
Customised web scanning
Remote Access Testing (RAS Testing)
ISDN enumeration, vulnerability scanning
and credential guessing, analogue
enumeration
Manual Testing
Verification of all of the above results
Using manual testing and banner grabs,
public/private vulnerability database
Searches of discovered applications / OS`s
Input Validation
SQL and HTML injection tests,
Script injection attacks (XSS),
General input field modification / Validation, hidden form field validation /
Modification
Directory transversal using ASCII,HEX
1,2,3 & 4 byte UNICODE encodings
Encryption
Encryption strength and scope,
Client side certification authentication
If applicable, Client side validation
Session Tracking
SMTP Specific testing
FTP Specific testing
Manually drafted report addressing
Issues with solutions
|
|
|