Audit of Infrastructure
1. 1 Audit of infrastructure

The audits of infrastructure make it possible to validate and correct the various implementations of the network so that are assured:
- The availability of the systems, which is defined as their capacity in being used constantly according to the performances envisaged.
- The integrity, which provides the insurance which the exchanged data cannot be modified by a third or which a valid identity on the network cannot be usurped in order to reach sensitive informations fraudulently.
- The confidentiality, which ensures that internal information and communications cannot be intercepted by a third.
- Nonthe repudiation, which constantly charges an operation to a user, in order to always be able to identify the source of an action.
The process of safety must be integrated in a dynamic way:

- The control of risk makes it possible to enumerate the vulnerabilities present, associated with degrees with gravity.
- Then the analysis of the risks consists in evaluating the criticality of a threat according to its probability and its impact.
- In order to work out a coherent security policy, SYSDREAM will emit all the recommendations necessary to the security of the infrastructure.
- An implementation of protected architecture could then be organized.
Our audits consist of the installation of this process on your infrastructure. SYSDREAM then provides you a total return of the real safety of your infrastructure as well as methodologies to fill the existing faults.
They can be realized according to several specific methodologies:
- An intrusive test: it is by putting to us in situation of real attack that we define the potential of destruction of an intruder on your computing systems.
- One to that the technique: A complete process, allowing to analyze the level of risk of your infrastructure, by taking of account organisational and technical aspects, and by respecting your policy of data-processing management.
- One audit of vulnerability: An automated analysis carried out in a cyclic way under control of a consultant, in order to seek between two audits (intrusive standard or system) of the vulnerabilities lately appeared on your network. We can carry out these tests into external and in-house of your company.