Configuration audit
Keep your devices and servers compliant.
What is a configuration audit?
Configuration audits assess the settings of your systems, applications and infrastructure to make sure they follow security best practices and your organizational standards.
These audits typically cover operating systems, middleware, firewalls and applications.
Objectives
Our configuration audits highlight the following configuration gaps:
General configuration and updates
User and access control
System log review
Application and software security
Backup and recovery systems
Review of advanced security settings
The HELX approach
We identify configuration errors, potential vulnerabilities and deviations from security standards such as CIS, NIST, STIG and ANSSI.
Our audits help prevent attacks by fixing misconfigurations before they get exploited. Regular audits keep you compliant and strengthen the overall security of your IT environment.
Methodology
Configuration audits are performed in white box mode, with full access to the systems and their settings. Our methodology builds on proven standards such as the CIS Benchmarks, ANSSI, STIG and NIST.
- 01
Configuration collection
We collect the key settings and configuration files, either through direct server access or an automated script, for in-depth analysis.
- 02
Configuration settings review
Review of system, application and infrastructure settings to spot inadequate or insecure parameters. Detection of errors that could expose the environment to threats.
- 03
Standards compliance check
Comparison of the configurations against security baselines (CIS Benchmarks, STIG, ANSSI, etc.) to confirm an optimal setup that meets security and performance requirements.
- 04
Risk identification
Analysis of weak or poorly secured configurations, such as unrestricted access, weak passwords or insecure services, that could expose the system to exploitation.
A bit of technical detail
Our configuration audit methodology is built on well-known, proven standards such as the CIS Benchmarks, STIG, ANSSI and NIST. We audit the following systems in particular:
- Unix / Linux systems: Ubuntu, Debian, CentOS, RedHat, AIX, etc.
- Windows systems: workstations, servers, Active Directory
- Databases: MySQL, MSSQL, PostgreSQL, etc.
- Web servers: Nginx, Apache, IIS, etc.
- Firewalls: Cisco, Fortinet, Stormshield, etc.
- Web browsers: Firefox, Chrome, Microsoft Edge
Frequently asked questions
How much does a configuration audit cost?
Plan on about two days per system family (Windows servers, Linux, workstations) plus half a day per audited device, at a daily rate of €850 excl. VAT. The online quote simulator calculates the exact amount based on your estate.
Which baselines do you use?
The CIS Benchmarks and the ANSSI hardening guides, adapted to your context: we separate what is truly critical in your environment from what is only theoretical.
What access do you need?
Read-only access (or an export of the configurations) is enough: the audit is completely non-intrusive, and no changes are made to your systems.
How is this different from a penetration test?
A pentest proves what an attacker can do; a configuration audit measures the gap to the state of the art, including flaws that are not exploitable yet but will become so. The two complement each other. For internal systems, the configuration audit is often the best starting point.
Tell us about your project.
Let us talk through your needs and expectations and build the right service for you.
