What is a Security Vulnerability Assessment and Configuration Audit?
Security configuration audits, also known as vulnerability assessments, provide an in depth and comprehensive review of system security to identify weak settings and policies within network and security devices, servers, operating systems, databases and infrastructure software.
A security configuration audit and vulnerability assessment exercise measures the security settings and policies within a network and exposes insecure configurations. The output from the security configuration audit is an audit report. This report details the safe and unsafe settings and communicates clearly the risk level and potential impact associated with each unsafe finding or vulnerability, along with clear and concise recommended solutions.
Overview of our service
Our Security Vulnerability and Configuration Audit service is divided into two phases:
Phase 1 – Security configuration capture
For each system within the scope of the audit, we provide a custom built executable file and a set of supporting instructions. When the file is executed on the target system, it will collect and package key security configuration information. Once the file has been run, it is securely uploaded to our Test Team for analysis.
Phase 2 – Security configuration analysis and reporting
Once the security configuration information has been uploaded to our secure site, the Test Team will analyse the information collected for each system and will mark each security configuration setting as either “Safe” or “Unsafe”.
For each unsafe finding, we determine the ease of exploitation and the security impact of the finding along with a risk rating. The report will provide a list of security configuration settings for each platform, categorised as safe or unsafe. The test report will also provide one or more solutions to mitigate the risks identified.
Key service attributes
- In depth audit of security configurations for:
- Network devices
- Security devices
- Servers
- Operating systems
- Databases
- Infrastructure software
- Secure method of collecting and analysing vulnerability information
- Combined automated analysis and manual verification of configuration settings
- Wide variety of platforms supported
- Access to reports via ClientConnect portal
- Removal of false positive findings
- Clear recommendations and fixes
- Cost effective and in depth vulnerability assessment
What you receive
The results of the tests are presented logically and clearly and are provided through an online secure portal (also downloadable as a PDF). The test report includes the following details:

- Executive summary
- Detailed vulnerabilities
- Security impact
- Risk rating
- Solution
- Severity levels – explained
- List of checks and state
The reports provide a view of the vulnerabilities found and risk level, helping you prioritise the areas of greatest risk. Clear guidance and concise solutions are included to help you quickly eliminate all vulnerabilities found.
..
...
.
.
.
What to do next
Contact us on 0844 488 0963, email us at info@securityalliance.co.uk or complete our Enquiry Form to discuss requirements, get an online demonstration, request a sample report or arrange a meeting.