CTG Security Assessments. Image of several people in a business meeting.

CTG security assessments are focused, flexible, and modular, supported by proven methodologies, best practices, and tailored to comply with current regulations and standards. Our services and solutions identify and eliminate your organization's system vulnerabilities while enhancing logical and physical security controls and processes.

Security Program Assessments Does your security program comply with necessary legal and regulatory requirements? Does it support your overall risk management program? Using ISO 27001 as a framework, CTG security experts work with your organization's stakeholders to evaluate whether your security program supports your business processes and goals.

Application Security Assessments CTG experts help detect security flaws within your organization's applications. We can help you identify security vulnerabilities that even newer technologies--such as web application vulnerability scanners--fail to detect.

Technical Vulnerability Assessment CTG specialists have worked in a wide range of environments and have performed vulnerability assessments on networks, web applications, servers, databases, VoIP, firewalls, network infrastructure, wireless, and PBX, for hundreds of organizations.

Penetration Testing Our approach encompasses a highly technical, detailed, and real-life simulated test of your security defensive posture, controls, and processes. Our experts use proven methodologies, commercial and open source toolsets, and the specialized skills required to write custom tools and exploits for attack vectors unique to specific environments. Our testing includes:

  • Internet-based penetration
  • Internal network penetration
  • Social engineering
  • Wireless network penetration
  • Application penetration
  • Facility penetration

Regulatory and Compliance Assessments CTG professionals help you manage compliance with multiple regulatory requirements, including:

  • Physical security
  • ISO 27001 certification readiness
  • PCI DSS Report on Compliance (ROC) and Attestation of Compliance (AOC)
  • HIPAA and ARRA HITECH readiness
  • FTC Red Flags Rule readiness
  • PCI DSS readiness

Comprehensive assessments adapted to fit your needs, combined with our complete suite of security assessment services and highly experienced consultants, will help you validate and improve your security management.