Security Assessment Services

Identify Threats Before They Attack

To better service the compliance and audit needs of our customers, Lighthouse Computer Services has established a strategic partnership with Compass IT Compliance, LLC. The members of Compass IT Compliance, LLC are highly experienced and certified, and the company’s managing partners were formerly senior consultants within the Lighthouse IT Compliance Group.

Let Compass IT Compliance help you protect your enterprise against intruders.

Compass IT Compliance, LLC offers four specific Security Assessment services designed to help you identify security vulnerabilities before they happen, and plan remedial actions to correct these exposures. Their Security Assessment services help identify threats to your network security infrastructure and processes, including data vulnerabilities, hardware and software vulnerabilities, transmission vulnerabilities, configuration errors, and leakage of sensitive information:

• The Vulnerability Assessment looks at security 
  from the inside, determining specific services 
  and ports that are available on your hosts, and 
  documenting all known attacks to which they 
  may be exposed. 
 

• The Penetration Test looks at your security 
  from the outside, running exploitation tools 
  against hosts within your environment in order 
  to identify possible risks that may be exploited 
  using common hacker methods.

• The Configuration Audit looks at your system 
  component configurations and will determine if 
  they are aligned with industry best practices and
  regulatory requirements such as: PCI, GLBA, 
  HIPPA, DISA STIGS, NIST, CIS, Microsoft, Red 
  Hat, Solaris, etc.

• The Data Loss Prevention Assessment looks 
  for the presence of sensitive information 
  throughout your network and infrastructure such 
  as: Credit Card Information, Social Security 
  Numbers, Health Care Information, Financial 
  Information, Classified Information, etc.

Look to Compass to help you gain a foothold against the constant threat of IT intrusion. For more information, or to schedule a consultation, please contact Compass IT Compliance, LLC.

 

Vulnerability Assessment
A Vulnerability Assessment identifies technical vulnerabilities in computers and networks, as well as weaknesses in policies and practices related to the operation of these systems. The Vulnerability Assessment identifies what services your hosts are offering, and whether or not the policies and procedures associated with them are in line with industry and company standards for security.

Penetration Testing
As a simulation of a real-world outside attack, Penetration Testing identifies exploitable risks prior to costly damage being inflicted by security incidents. Compass' Penetration Testing services will:

• Attempt to gain control of the host system.

• Document the steps taken, showing if any attack
  was successful.

• If an attack was successful, pivot on that 
  system and attempt to attack other host 
  systems on the customer network. 

• Attempt to gain control of any production system 
  or extract sensitive data from the environment.

• Provide guidance on how to remediate the 
  issues identified. Document all findings in a 
  final report.


 
Configuration Audit
Regulatory Compliance Requirements can sometimes be cryptic and hard to apply to a robust infrastructure. This service will ensure systems are configured to standard or best practices and in accordance with regulatory requirements.

Data Loss Prevention (DLP) Assessment
While working with sensitive Personal Identifiable Information (PII), it is easy to misplace or mishandle this data and be susceptible to hefty regulatory fines and debilitating business results. Compass' DLP service will ensure that your organization’s PII is only present where it needs to be and is not leaking or misplaced.


 

 A Compass Vulnerability Assessment Includes: 

•  Identification of applications and services  
   on host devices, DHCP, TFTP, DNS, etc.

•  Review of communication protocols active 
   on the system.

•  Review of industry sources for notices of  
   known vulnerabilities on host-based 
   operating systems.

•  Review of configuration and network 
   diagrams of all network related devices that 
   are exposed on the perimeter of the network.

•  Identification of unneeded services on 
   network device (DHCP, TFTP, DNS, small 
   servers, etc).

•  Review of CERT notices for known 
   vulnerabilities of network equipment.

•  Recommendations for securing networking  
   devices.

•  Documentation of all findings, impact  
   analyses, and recommendations in a final  
   report.

 Vulnerability Assessment Services

External Vulnerability and Penetration Testing

For a complete and consistent approach, Compass IT Compliance, LLC utilizes industry best practices and methodologies for penetration testing, such as the Open Source Security Testing Methodology Manual (OSSTMM) and National Institute for Standards and Technology (NIST). There are four major phases to the Internet vulnerability and penetration tests:

• Reconnaissance and Information Gathering

• Enumeration

• Vulnerability Scanning

• Attack and Penetrate (Optional)


Internal Vulnerability Assessment 

Compass designs its Internal Vulnerability Assessment to find existing vulnerabilities in internal hosts, such as servers, workstations, printers, routers, switches and other network devices and infrastructure components. In addition, Compass will attempt to determine the root causes of the vulnerabilities identified.


Password Cracking/Recovery

The objective of this review is to ensure the target systems have appropriate password requirements in place and that users are creating strong passwords that are not easily enumerated. Online password cracking is possible for certain protocols, such as Telnet, Windows, SSH and HTTP.

Internet Infrastructure Security
Assessment
 

Compass will perform a hands-on assessment of the configuration of your Internet architecture, including:

• Firewall

• Architecture and Design

• DMZ Host Vulnerability Assessment

• Managed Security Services – Service Level 
  Testing


Social Engineering
 

Compass will also evaluate human weakness, including:

• Phishing

• Dumpster Diving

• Pre-Text Calling

• Baiting (Physical & Logical)


Wireless Security Assessment

Compass will evaluate the configuration of your 802.11x wireless network implementation, including:

• Rogue Access Point Detection

• Ad-hoc Wireless Device Detection

• Wireless Architecture Review

• Wireless Encryption Key Cracking

For more information, or to schedule a consultation, please visit Compass IT Compliance, LLC, or call Compass at 888-246-7594.

Customer Login Employee Login