A key part of the Secure360 service is the Security Posture Assessment (SPA), designed for the SMB market. The SPA helps to identify and focus on the areas of concern:
- What are the technical risks?
- What is the business costs associated with these risks?
- What security policies should be in place?
- Where is the organization exposed?
- Which computers are vulnerable and how?
- What is required to lock down network devices?
- What solutions are right for our needs?
- How should these solutions be implemented?
The SPA assessment helps develop key security policies, addresses known vulnerabilities, and develops plans to fortify your infrastructure with a Cisco Self-Defending Network, such as the one depicted below.
The table below summarizes our Express, Professional, and Premium Security Posture Assessment offerings:
Task |
Express |
Pro |
Premium |
Technical risk assessment |
Included |
Included |
Included |
Business risk assessment |
|
|
Included |
Security policy development |
4 areas |
8 areas |
12 areas |
Cisco device configuration guidelines |
|
Routers |
Routers, Switches, Firewalls |
Automated port scan of desktops and summary report |
Optional |
Up to 100 addresses |
Up to 250 addresses |
Automated vulnerability scan of servers and detailed report |
Up to 5 addresses |
Up to 10 addresses |
Up to 25 addresses |
In-depth, QualysGuard scan of internal computers |
|
Optional |
Optional |
Cisco compliance audits (SOX, HIPAA, ISO 17799, etc.) |
(Includes 1 PSIRT audit) |
Optional
(Includes 1 PSIRT audit) |
Optional
(Includes 1 PSIRT audit) |
Application vulnerability scan |
|
Optional |
Optional |
Solution recommendations |
Included |
Included |
Included |
Security solution budgeting and planning |
Included |
Included |
Included |
Review of findings and recommendations |
Remote conference |
Onsite |
Onsite |
1 Express incl.: Anti-virus, passwords, physical network access, VPN
2 Pro incl.: Express policies, acceptable use, e-mail, network access ctrl, wireless
3 Premium incl.: Pro policies, plus up to four policy areas from a select list
4 Each server to be scanned must have a publicly accessible IP address
5 Please inquire about supported Cisco devices, OS releases & audits offered
6 A network diagram is provided if your organization does not already have one
7 Devices included in the scope are described in the table above
The Deliverables
At the end of the SPA, Network Architects will deliver the following client-specific reports:
- A high-level network diagram
- A high-level risk assessment summary report
- A model for assessing your network infrastructure
- Key security policy documents customized to your needs
- Cisco device configuration guidelines
- Reports summarizing scan results
- Cisco Self-Defending Network solution recommendations and plans
|