The strictest security solutions implemented would not be effective without appropriate procedures. Many cases of penetration are ‘successfully’ conducted due to wrong operating procedures. In order to create an effective security shield for online systems and for processes as a whole, strong security tools should be backed by well-defined operation and maintenance procedures.

During the e-Sure process, and especially this stage, Comsec will verify that no breaches are created by the ‘human factor’, working with problematic procedures from a security point of view, and indicate if there are procedures missing. In case of a lack of appropriate procedures, Comsec could provide and develop the required procedures as an option against additional costs. The penetration tests, described hereafter, include penetration attempts that will use procedural breaches.

The audit of procedural security aspects is a new element as opposed to the Application Level Security Audit.