| PSSM # |
Title |
|
|
|
Firewalls, VPNs, Traffic Management, IDS and IPS |
|
1.1 |
|
Firewall, VPN, TM, IDS & IPS Deployment |
|
1.2 |
|
Firewall, VPN, TM, IDS & IPS Adjustment
|
|
1.3 |
|
Firewall, VPN, TM, IDS & IPS Configuration Review
|
|
1.4 |
|
Firewall, VPN, TM, IDS & IPS Performance Review
|
|
|
|
|
|
|
|
Anti-Virus Solutions |
|
2.1 |
|
Anti-Virus Solution Deployment |
|
2.2 |
|
Anti-Virus Solution Adjustment |
|
2.3 |
|
Anti-Virus Solution Configuration Review |
|
2.4 |
|
Anti-Virus Solution Performance Review |
|
|
|
|
|
|
|
Content Security Solutions |
|
3.1 |
|
Content Security Solution Deployment |
|
3.2 |
|
Content Security Solution Adjustment |
|
3.3 |
|
Content Security Solution Configuration Review |
|
3.4 |
|
Content Security Solution Performance Review |
|
|
|
|
|
|
|
Authentication Solutions |
|
4.1 |
|
Authentication Solution Deployment |
|
4.2 |
|
Authentication Solution Adjustment |
|
4.3 |
|
Authentication Solution Configuration Review |
|
4.4 |
|
Authentication Solution Performance Review |
|
|
|
|
|
|
|
Security Strategy |
|
5.1 |
|
Security Strategy Workshop |
|
5.2 |
|
Security Strategic Plan Development |
|
5.3 |
|
Security Strategic Plan Review |
|
|
|
|
|
|
|
Security Policy & Procedure |
|
6.0 |
|
Custom Policy and/or Procedure Requirement |
|
6.1 |
|
Security Policy and/or Procedure Devlopment |
|
6.2 |
|
Security Policy and/or Procedure Education |
|
6.3 |
|
Security Policy and/or Procedure Review |
|
6.4 |
|
AS/NZS ISO/IEC 27001, 27002, 27003 Alignment Gap Analysis |
|
|
6.4.5 |
Information Security Ownership |
|
|
6.4.6 |
Third Party Access Control & Data Exchange |
|
|
6.4.7 |
Third Party Service Contract Review |
|
|
6.4.8 |
Asset Identification & Classification |
|
|
6.4.9 |
Asset Classification Rules |
|
|
6.4.10 |
Employee Security |
|
|
6.4.11 |
Physical Environment Security |
|
|
6.4.12 |
Physical Equipment Security |
|
|
6.4.13 |
Secure Change Control |
|
|
6.4.14 |
Security Incident Identification |
|
|
6.4.15 |
Security Incident Management |
|
|
6.4.16 |
Data Handling & Disposal |
|
|
6.4.17 |
User Access Review |
|
|
6.4.18 |
Endpoint Access Control |
|
|
6.4.19 |
Sensitive System Identification & Control |
|
|
|
|
|
|
|
Network Services Security |
|
7.1 |
|
Network Services Identification |
|
7.2 |
|
Network Services Volume Vulnerability Identification |
|
7.3 |
|
Network Services Zero-Day Vulnerability Identification |
|
|
|
|
|
|
|
Application Security |
|
8.1 |
|
Website CGI Assessment (Non-Authenticated Users) |
|
8.2 |
|
Website CGI Assessment (Authenticated Users) |
|
8.3 |
|
Website CGI Architecture |
|
8.4 |
|
Application Architecture |
|
8.5 |
|
Application Assessment (Non-Authenticated Users) |
|
8.6 |
|
Application Assessment (Authenticated Users) |
|
|
|
|
|
|
|
Wireless Security |
|
9.1 |
|
Active WiFi (802.11) Access Point Identification and Assessment |
|
9.2 |
|
Active Bluetooth Device Identification and Assessment |
|
|
|
|
|
|
|
Network Security |
|
10.1 |
|
Network Architecture Security Design |
|
10.2 |
|
Network Architecture Security Review |
|
10.3 |
|
Network Traffic Review |
|
10.4 |
|
Network Access/Admission Control Deployment |
|
10.5 |
|
Network Access/Admission Control Review |
|
|
|
|
|
|
|
Desktop & Server Security |
|
11.1 |
|
Desktop SOE Security Review |
|
11.2 |
|
Server General and/or SOE Security Review |
|
|
|
|
|
|
|
Data Leakage Prevention/Protection |
|
12.1 |
|
Data Leakage Protection Review |
|
12.2 |
|
Data Leakage Protection Deployment |
|
12.3 |
|
Data Encryption Deployment |
|
12.4 |
|
Data Encryption Adjustment |
|
12.5 |
|
Data Encryption Configuration Review |
|
12.6 |
|
Data Encryption Performance Review |