Customers: Baltika, brewery
Contractors: Digital Security (Digital Security guard) Product: Projects of external audit of IT and security (in tch PCI DSS and SUIB)Project date: 2011/09
|
Digital Security and Baltika completed in the fall of 2011 the complex project on regular audit of security of three key information systems of the company. Search and elimination of the found vulnerabilities allowed to save the high level of information security on Baltika.
Information systems Lotus Notes, Citrix also VMware underwent the profound technical analysis of security therefore in the software of vender vulnerabilities, including unknown at the time of audit were revealed (0-day vulnerabilities). Objective assessment and detailed technical recommendations allowed IT department of Baltika and vendors to eliminate quickly found vulnerabilities and to save the current level of security of the company at traditionally high level.
Medvedovsky Ilya, the expert in IT - security and the chief executive of Didzhital Sekyyuriti LLC: "At assessment of security of the key information systems of the companies which are regularly booking audit and maintaining security of the systems up to standard it is extremely important to pay attention to the analysis and search not only standard vulnerabilities, but also new, unknown at the moment to the producer. Execution of these conditions allows Baltika as the companies with the high level of corporate culture including in information security field to support a level and it is reliable to preserve the key systems against the possible hacker attacks".
Tambovtsev Ilya, head of development department of information systems and infrastructure of JSC Baltika Brewery: "The purpose of the implemented project – increase in information security and providing the continuous company performance in mode 24х7 excluding failures and idle times, real and indirect financial loss. Involvement of the external expert on behalf of Digital Security allowed us to receive independent assessment of security of information systems of the company. We received specific recommendations about elimination of vulnerabilities as in the separate systems – at the level of their interaction, and at the level of the general architecture".
Information systems of Baltika company are a big complex of the specialized on a scope, different in the scale of application, integrated among themselves systems of different vendors. Vulnerabilities in some systems threaten security of others, and so on a chain.
Audit of security is a chastyobyazatelny process of operation and continuous improvement of an information system of any company.