Security Baselining
Baselining is a formalized process of determining a corporation's external security Internet profile and internal security posture.
Internal baselines are established using local physical access to the corporate network and the results of a series of audit tools analysis. Internal security issues are identified and assigned a risk rating based on severity.
External baselining audits Internet-facing assets, routers, firewalls, VPNs and establishes a target profile. Once a profile is completed, penetration testing of the external assets then takes place by:
- Footprinting;
- Scanning; and
- Enumeration of vulnerabilities.
If the client wishes information on risks from social engineering, then additional services in this area are available.
