Skip to content

Home Expertise / Audits & assessments

AUD / AUD-02

Infrastructure security audit

An examination of server, network, access and infrastructure-service architecture and configurations to identify weaknesses and protection gaps.

WHEN IT HELPS

A focused response
to a defined need.

CIO or infrastructure manager; hosting changes, rapid growth or poorly documented infrastructure.

AT A GLANCE

Family
Audits & assessments

Engagement
Assessment

Reference
AUD-02

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Review diagrams and flows
  • sample configuration checks
  • assess administrative rights, patching, logs and backups

Deliverables

  • Evidence-based technical report
  • trust-zone diagram
  • prioritised remediation plan

Acceptance evidence

Findings identify the asset, evidence, impact, recommendation and test limitation; operations teams review the conclusions.

DELIVERY

How the work is structured.

Approach

Scope assets and criteria; gather evidence and interviews; validate gaps; present priorities and limitations.

Prerequisites & responsibilities

Customer: inventory, read access, documents and business contacts. Provider: assessment and debrief. Production changes are not included by default.

Scope factors

Sites, assets, technologies and interviews; assessment depth; inventory quality; access constraints; required reporting. One-off project with optional follow-up.

Questions to clarify

How many sites and servers? Which environments are critical? Are read-only access and configurations available?

IMPORTANT BOUNDARIES

Sampling must be disclosed; remediation, intrusive testing and continuous availability are not included by default.

Sampling and observation date are explicit. No assessment certifies the absence of flaws; remediation, penetration testing and recurring follow-up are separate scopes.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A multisite company uses one administrator account everywhere. Project: assess directories, hypervisors and networks. Target outcome: map excessive access and define a remediation workstream separating administration, users and backups.

Scenario 02

A software company runs inconsistent Linux production configurations. Project: compare a sample with the agreed baseline. Target outcome: a reference image and documented exceptions; unsupported systems require a migration decision.

Technology and reference context

ANSSI guidance, CIS Benchmarks subject to usage rights, and read-only collection tools.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.