Cyber Security Assessment Service is an automated security assessment that provides insights into an organizations security vulnerabilities. It collects relevant data from Endpoint, Office 365, Network Devices, Active Directory & Azure AD
• Provide an analysis of customer’s cybersecurity maturity status.
• Assessment of cybersecurity-related policies and procedures.
• Help to create a cybersecurity roadmap to better protect customer’s IT assets.
• Final report with analysis of current cybersecurity status.
• Recommendations based on facts.
• Cybersecurity improvement with an action plan.
• Cybersecurity maturity is based on CIS controls framework and Microsoft security SOM Model
The CIS Controls Topics | Advised Products are mentioned below:
- Inventory and Control of Hardware Assets | Microsoft Endpoint Manager, Network discovery solution
- Inventory and Control of Software Assets | Software Asset Management [SAM] tooling;
Microsoft Endpoint Manager; Microsoft Cloud App Security; Defender for Endpoint
- Continuous Vulnerability Management | Microsoft Endpoint
Manager, Windows Server Update Services (WSUS), Azure Security Center, Azure Sentinel, Azure AD Identity Protection
- Controlled Use of Administrative Privileges | Azure AD Privileged Identity
Management (PIM), Privileged Access Management (PAM), Azure AD Multi-Factor
Authentication (MFA), Azure AD Conditional Access
- Secure Configuration for Hardware and Software on Mobiles Devices, Laptops, Workstations and Servers | Microsoft Endpoint Manager; Defender for Endpoint; Azure
Security Center; Microsoft Cloud App Security
- Email and Web Browser Protections | Exchange Online Protection; Microsoft Defender for Office 365.
- Malware Defenses | Microsoft Cloud App Security, Defender for Endpoints
- Data Recovery Capabilities | Azure Back-up and Site Recovery
- Secure Configuration for Network Devices, such as Firewalls, Routers and Switches | Network Device Management Solution
- Boundary Defense | Azure DDoS Protection
- Data Protection | Azure Information Protection Scanner; Data Loss Prevention; Microsoft 365 Advanced Data Governance; Microsoft Information Protection; Azure SQL Data Discovery & Classification
- Controlled Access Based on the Need to know | Azure AD, PortalTalk 365
- Account Monitoring and Control (OP, Azure, Microsoft 365) | Azure AD Multi-Factor Authentication (MFA), Azure AD Conditional Access, Azure Identity Protection, Azure AD Password Protection
- Application Software Security | Microsoft Endpoint Manager
- Incident Response and Management | Microsoft 365 Advanced Compliance: Advanced eDiscovery
- Penetration Tests and Red Team Exercises | Microsoft Endpoint Manager; Defender for Endpoint; Azure Security Center
AD.1. IT Governance | Azure AD Identity Governance; Microsoft Compliance Manager
AD.2. Data Governance | Azure Information Protection Scanner , Data Loss Prevention, Azure Information Protection P2, Azure AD Identity Governance
AD.3. Risk Management | Microsoft Compliance Manager
.